Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Chrome HIGH 7.5
CVE-2015-6771

js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which all…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome CRITICAL 9.8
CVE-2015-6764

The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.…

Fix: 4.2.3+
Fix from $2,300 2015-12-06
Leap HIGH 7.5
CVE-2015-8076

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain s…

Mitigation only
Fix from $1,950 2015-12-03
Perl Compatible Regular Expression Library HIGH 7.5
CVE-2015-8395

PCRE before 8.38 mishandles certain references, which allows remote attackers to cause a denial of service or possibly have unspecified other impact …

Fix: after 8.37
Fix from $1,950 2015-12-02
Perl Compatible Regular Expression Library HIGH 7.5
CVE-2015-8392

PCRE before 8.38 mishandles certain instances of the (?| substring, which allows remote attackers to cause a denial of service (unintended recursion …

Fix: after 8.37
Fix from $1,950 2015-12-02
Linux CRITICAL 9.8
CVE-2015-8391EPSS 6%

The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $2,300 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8389

PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite re…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Linux HIGH 7.5
CVE-2015-8388EPSS 7%

PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote at…

Fix: after 8.37
Fix from $1,950 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8386EPSS 7%

PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a den…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Linux HIGH 7.5
CVE-2015-8385EPSS 6%

PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to…

Fix: after 8.37
Fix from $1,950 2015-12-02
Perl Compatible Regular Expression Library HIGH 7.5
CVE-2015-8384

PCRE before 8.38 mishandles the /(?J)(?'d'(?'d'\g{d}))/ pattern and related patterns with certain recursive back references, which allows remote atta…

Fix: after 8.37
Fix from $1,950 2015-12-02
Fedora CRITICAL 9.8
CVE-2015-8383EPSS 6%

PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or poss…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Perl Compatible Regular Expression Library MEDIUM 6.4
CVE-2015-8382

The match function in pcre_exec.c in PCRE before 8.37 mishandles the /(?:((abcd))|(((?:(?:(?:(?:abc|(?:abcdef))))b)abcdefghi)abc)|((*ACCEPT)))/ patte…

No fix yet
Fix from $1,600 2015-12-02
Perl Compatible Regular Expression Library HIGH 7.5
CVE-2015-8381EPSS 5%

The compile_regex function in pcre_compile.c in PCRE before 8.38 and pcre2_compile.c in PCRE2 before 10.2x mishandles the /(?J:(?|(:(?|(?'R')(\k'R')|…

Fix: after 8.37
Fix from $1,950 2015-12-02
Fedora HIGH 7.5
CVE-2015-8380

The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial …

Fix: after 8.37
Fix from $1,950 2015-12-02
Perl Compatible Regular Expression Library HIGH 7.5
CVE-2015-2327

PCRE before 8.36 mishandles the /(((a\2)|(a*)\g<-1>))*/ pattern and related patterns with certain internal recursive back references, which allows re…

Fix: after 8.35
Fix from $1,950 2015-12-02
Ubuntu Linux MEDIUM 6.8
CVE-2015-8365

The smka_decode_frame function in libavcodec/smacker.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not verify that the d…

Mitigation only
Fix from $1,600 2015-11-26
Ffmpeg MEDIUM 6.8
CVE-2015-8363

The jpeg2000_read_main_headers function in libavcodec/jpeg2000dec.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 does not enfo…

Mitigation only
Fix from $1,600 2015-11-26
Plant Connectivity HIGH 7.8
CVE-2015-8330

The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption and agent crash) via crafted xM…

No fix yet
Fix from $1,950 2015-11-24
Gpu Driver MEDIUM 6.6
CVE-2015-8328

Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87…

Fix: 341.92+
Fix from $1,600 2015-11-24
Espace Firmware HIGH 7.8
CVE-2015-8083

An unspecified module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software before V200R003C00SPC300 does not …

Mitigation only
Fix from $1,950 2015-11-19
Debian Linux MEDIUM 6.8
CVE-2015-7942

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, whi…

Fix: after 10.11.3
Fix from $1,600 2015-11-18
Picasa HIGH 10.0
CVE-2015-8221

Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, wh…

Fix: after 3.9.140
Fix from $1,950 2015-11-17
Dameware Mini Remote Control HIGH 7.5
CVE-2015-8220

Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers t…

Fix: after 12.0
Fix from $1,950 2015-11-17
Opensuse HIGH 9.3
CVE-2015-7805EPSS 13%

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF f…

No fix yet
Fix from $1,950 2015-11-17
Galaxy S6 HIGH 7.5
CVE-2015-7897EPSS 7%

The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge before G925VVRU4B0G9 allows remot…

No fix yet
Fix from $1,950 2015-11-16
Imt25 Magnetic Flow Dtm HIGH 7.7
CVE-2015-3977

Buffer overflow in Schneider Electric IMT25 Magnetic Flow DTM before 1.500.004 for the HART Protocol allows remote authenticated users to execute arb…

Fix: after 1.500.000
Fix from $1,950 2015-11-15
Kerberos 5 HIGH 8.5
CVE-2015-2698

The iakerb_gss_export_sec_context function in lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) 1.14 pre-release 2015-09-14 improperly accesses a…

Patch available
Fix from $1,950 2015-11-13
Excel HIGH 9.3
CVE-2015-6094EPSS 21%

Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2015-11-11
Office HIGH 9.3
CVE-2015-6093EPSS 21%

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word Automation Services on SharePoint Server 2010 SP2 …

Mitigation only
Fix from $1,950 2015-11-11