Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
P8 Firmware HIGH 7.8
CVE-2015-8088EPSS 6%

Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7-TL10 before MT7-TL10C00B354,…

Mitigation only
Fix from $1,950 2016-01-12
Visilogic Oplc Ide CRITICAL 9.6
CVE-2015-7939EPSS 5%

Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.

Fix: after 9.8.0.00
Fix from $2,300 2016-01-09
Subversion HIGH 8.6
CVE-2015-5259EPSS 19%

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2016-01-08
Dx Library HIGH 7.8
CVE-2016-1131

Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted s…

Fix: after 3.15e
Fix from $1,950 2016-01-08
Android CRITICAL 9.8
CVE-2015-6636

mediaserver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows remote attackers to execute arbitrary code or cause a denial of servi…

Mitigation only
Fix from $2,300 2016-01-06
Wireshark MEDIUM 5.5
CVE-2015-8726EPSS 7%

wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8725EPSS 8%

The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x before 1.12.…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8723EPSS 7%

The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8713

epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings,…

Mitigation only
Fix from $1,600 2016-01-04
PHP CRITICAL 9.8
CVE-2016-1283EPSS 8%

The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'…

Fix: 5.6.32 / 7.0.25+
Fix from $2,300 2016-01-03
I Access MEDIUM 5.5
CVE-2015-7422

Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via unspecified vectors.

Mitigation only
Fix from $1,600 2016-01-02
I Access HIGH 8.8
CVE-2015-2023

Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.

No fix yet
Fix from $1,950 2016-01-02
Uptime Infrastructure Monitor HIGH 7.3
CVE-2015-2895

Buffer overflow in the up.time client in Idera Uptime Infrastructure Monitor 7.4 might allow remote attackers to execute arbitrary code via long comm…

Mitigation only
Fix from $1,950 2015-12-31
Air HIGH 8.8
CVE-2015-8645EPSS 7%

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.…

Fix: after 20.0.0.204
Fix from $1,950 2015-12-28
Air HIGH 8.8
CVE-2015-8636EPSS 21%

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.…

Fix: after 20.0.0.204
Fix from $1,950 2015-12-28
Flash Player HIGH 8.8
CVE-2015-8460

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.…

Fix: after 20.0.0.204
Fix from $1,950 2015-12-28
Air Sdk CRITICAL 10.0
CVE-2015-8459EPSS 6%

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.…

Fix: after 20.0.0.204
Fix from $2,300 2015-12-28
Ffmpeg HIGH 8.3
CVE-2015-8663

The ff_get_buffer function in libavcodec/utils.c in FFmpeg before 2.8.4 preserves width and height values after a failure, which allows remote attack…

Mitigation only
Fix from $1,950 2015-12-24
Ffmpeg HIGH 8.3
CVE-2015-8661

The h264_slice_header_init function in libavcodec/h264_slice.c in FFmpeg before 2.8.3 does not validate the relationship between the number of thread…

Fix: after 2.8.2
Fix from $1,950 2015-12-24
Ffmpeg HIGH 7.3
CVE-2015-8662

The ff_dwt_decode function in libavcodec/jpeg2000dwt.c in FFmpeg before 2.8.4 does not validate the number of decomposition levels before proceeding …

Fix: after 2.8.3
Fix from $1,950 2015-12-24
Bmxnoc0401 HIGH 10.0
CVE-2015-7937EPSS 7%

Stack-based buffer overflow in the GoAhead Web Server on Schneider Electric Modicon M340 PLC BMXNOx and BMXPx devices allows remote attackers to exec…

Mitigation only
Fix from $1,950 2015-12-21
Enterprise Linux Desktop HIGH 7.2
CVE-2015-5277

The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow loc…

Fix: after 2.19
Fix from $1,950 2015-12-17
Firefox HIGH 10.0
CVE-2015-7221

Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause …

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox HIGH 10.0
CVE-2015-7220

Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of…

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox HIGH 10.0
CVE-2015-7203

Buffer overflow in the DirectWriteFontInfo::LoadFontFamilyData function in gfx/thebes/gfxDWriteFontList.cpp in Mozilla Firefox before 43.0 might allo…

Fix: after 42.0
Fix from $1,950 2015-12-16
Firefox HIGH 10.0
CVE-2015-7202EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory…

Fix: after 42.0
Fix from $1,950 2015-12-16
Fedora HIGH 10.0
CVE-2015-7201EPSS 6%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to …

Fix: after 42.0
Fix from $1,950 2015-12-16
Design Review MEDIUM 6.8
CVE-2015-8572

Multiple buffer overflows in Autodesk Design Review (ADR) before 2013 Hotfix 2 allow remote attackers to execute arbitrary code via crafted RLE data …

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 5.0
CVE-2015-8317EPSS 6%

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterm…

Fix: after 2.9.2
Fix from $1,600 2015-12-15
Ubuntu Linux MEDIUM 5.8
CVE-2015-8242

The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a…

Fix: after 2.9.2
Fix from $1,600 2015-12-15