Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Android HIGH 10.0
CVE-2015-3867

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 10.0
CVE-2015-3823

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Freeswitch HIGH 7.5
CVE-2015-7392

Heap-based buffer overflow in the parse_string function in libs/esl/src/esl_json.c in FreeSWITCH before 1.4.23 and 1.6.x before 1.6.2 allows remote a…

Fix: after 1.4.21
Fix from $1,950 2015-10-05
Trendweb HIGH 7.5
CVE-2015-5653

Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.

Fix: after 9.0.2.27051
Fix from $1,950 2015-10-02
Android HIGH 9.3
CVE-2015-3842

Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execu…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3835

Buffer overflow in the OMXNodeInstance::emptyBuffer function in omx/OMXNodeInstance.cpp in libstagefright in Android before 5.1.1 LMY48I allows attac…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3832

Multiple buffer overflows in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attackers to execute arbitrary code via…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3831

Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android befo…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3828EPSS 85%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3827EPSS 81%

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship bet…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 5.0
CVE-2015-3826EPSS 74%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 10.0
CVE-2015-3824EPSS 90%

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly restrict size additi…

Fix: after 5.1
Fix from $1,950 2015-10-01
Display Driver MEDIUM 6.9
CVE-2015-5950

The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Li…

Fix: after 352.86
Fix from $1,600 2015-09-30
Gnu Screen MEDIUM 5.0
CVE-2015-6806

The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of…

Fix: after 4.3.1
Fix from $1,600 2015-09-28
Opensuse HIGH 10.0
CVE-2015-5957

Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name.

Fix: after 3.1.14
Fix from $1,950 2015-09-28
Debian Linux MEDIUM 6.8
CVE-2015-1781EPSS 5%

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-depen…

Fix: after 2.21
Fix from $1,600 2015-09-28
Qemu HIGH 7.2
CVE-2015-5279

Heap-based buffer overflow in the ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows guest OS users to cause a denial of servic…

Fix: after 2.4.0
Fix from $1,950 2015-09-28
Webaccess MEDIUM 6.9
CVE-2014-9202

Multiple stack-based buffer overflows in an unspecified DLL file in Advantech WebAccess before 8.0_20150816 allow remote attackers to execute arbitra…

Mitigation only
Fix from $1,600 2015-09-28
Firefox HIGH 7.5
CVE-2015-7180

The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 misinterprets the return value of a funct…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7179

The VertexBufferInterface::reserveVertexSpace function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 o…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7178

The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, m…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7176

The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7177

The InitTextures function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7175

The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a deni…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-7174

The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a deni…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-4522

The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a de…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-4521

The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of s…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox HIGH 7.5
CVE-2015-4517

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory co…

Fix: after 40.0.3
Fix from $1,950 2015-09-24
Firefox MEDIUM 6.4
CVE-2015-4512

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface cr…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Firefox MEDIUM 6.8
CVE-2015-4511

Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote att…

Fix: after 40.0.3
Fix from $1,600 2015-09-24