Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Office Compatibility Pack HIGH 7.8
CVE-2016-0022EPSS 17%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Com…

Mitigation only
Fix from $1,950 2016-02-10
Linux MEDIUM 6.2
CVE-2013-4312

The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each …

Fix: after 4.4
Fix from $1,600 2016-02-08
Android CRITICAL 9.8
CVE-2016-0804

The NuPlayer::GenericSource::notifyPreparedAndCleanup function in media/libmediaplayerservice/nuplayer/GenericSource.cpp in mediaserver in Android 5.…

Mitigation only
Fix from $2,300 2016-02-07
Android CRITICAL 9.8
CVE-2016-0803

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbi…

Mitigation only
Fix from $2,300 2016-02-07
Ffmpeg MEDIUM 6.5
CVE-2016-2213

The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bou…

Fix: after 2.8.5
Fix from $1,600 2016-02-03
Safari HIGH 8.8
CVE-2016-1727EPSS 6%

WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a d…

Fix: 2.2 / 2.10.5+
Fix from $1,950 2016-02-01
Safari HIGH 8.8
CVE-2016-1726EPSS 6%

WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 9.2
Fix from $1,950 2016-02-01
Safari HIGH 8.8
CVE-2016-1725EPSS 6%

WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 9.2
Fix from $1,950 2016-02-01
Safari HIGH 8.8
CVE-2016-1724

WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a d…

Fix: 2.2 / 2.10.5+
Fix from $1,950 2016-02-01
Safari HIGH 8.8
CVE-2016-1723EPSS 6%

WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 9.2
Fix from $1,950 2016-02-01
Iphone Os HIGH 7.8
CVE-2016-1722

syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memo…

Fix: 2.2 / 9.1.1+
Fix from $1,950 2016-02-01
Iphone Os HIGH 7.8
CVE-2016-1721

The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (…

Fix: 2.2 / 9.1.1+
Fix from $1,950 2016-02-01
Mac Os X HIGH 7.8
CVE-2016-1720

IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memor…

Fix: 2.2 / 9.1.1+
Fix from $1,950 2016-02-01
Iphone Os HIGH 7.8
CVE-2016-1719

The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of …

Fix: after 10.11.2
Fix from $1,950 2016-02-01
Mac Os X HIGH 7.3
CVE-2016-1718

The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of ser…

Fix: after 10.11.2
Fix from $1,950 2016-02-01
Tvos HIGH 7.8
CVE-2016-1717

The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a deni…

Fix: 2.2 / 9.1.1+
Fix from $1,950 2016-02-01
Mac Os X HIGH 7.8
CVE-2016-1716

AppleGraphicsPowerManagement in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via …

Fix: after 10.11.2
Fix from $1,950 2016-02-01
Firefox CRITICAL 9.8
CVE-2016-1946

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operatio…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1944

The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of servic…

No fix yet
Fix from $2,300 2016-01-31
Linux HIGH 8.8
CVE-2016-1935

Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbi…

Fix: after 43.0.4
Fix from $1,950 2016-01-31
Firefox CRITICAL 10.0
CVE-2016-1931EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox CRITICAL 9.8
CVE-2016-1930EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allow remote attackers to …

Fix: after 43.0.4
Fix from $2,300 2016-01-31
File Lock HIGH 7.5
CVE-2015-8773

Stack-based buffer overflow in McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2016-01-29
Libmatroska MEDIUM 5.3
CVE-2015-8792

The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process h…

Fix: after 1.4.3
Fix from $1,600 2016-01-29
1763 L16awa Series A CRITICAL 9.8
CVE-2016-0868EPSS 6%

Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers…

Mitigation only
Fix from $2,300 2016-01-28
Openjpeg MEDIUM 6.5
CVE-2016-1924

The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via …

Fix: after 2.1.0
Fix from $1,600 2016-01-27
Openjpeg MEDIUM 6.5
CVE-2016-1923

Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-…

Mitigation only
Fix from $1,600 2016-01-27
Promotic MEDIUM 5.0
CVE-2016-0869

Heap-based buffer overflow in MICROSYS PROMOTIC before 8.3.11 allows remote authenticated users to cause a denial of service via a malformed HTML doc…

Fix: after 8.3.10
Fix from $1,600 2016-01-26
Chrome HIGH 7.6
CVE-2016-1619

Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Goo…

Fix: after 47.0.2526.106
Fix from $1,950 2016-01-25
Communication Engine HIGH 7.3
CVE-2015-7909

Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and …

Fix: after 1.0
Fix from $1,950 2016-01-22