Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Ipolis Device Manager MEDIUM 6.8
CVE-2015-0555EPSS 6%

Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitra…

No fix yet
Fix from $1,600 2015-02-24
Dir 645 Firmware HIGH 10.0
CVE-2015-2052EPSS 5%

Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitra…

Fix: after 1.04b12
Fix from $1,950 2015-02-23
Ubuntu Linux HIGH 7.5
CVE-2015-1315

Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a craf…

Patch available
Fix from $1,950 2015-02-23
Al Mail32 MEDIUM 6.8
CVE-2015-0880

Buffer overflow in CREAR AL-Mail32 before 1.13d allows remote attackers to execute arbitrary code via a long filename of an attachment.

Fix: after 1.13
Fix from $1,600 2015-02-20
Cups MEDIUM 6.8
CVE-2014-9679

Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via…

Fix: after 2.0.1
Fix from $1,600 2015-02-19
Server And Application Monitor MEDIUM 6.8
CVE-2015-1500EPSS 8%

Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to…

Patch available
Fix from $1,600 2015-02-16
Motorola Scanner Sdk MEDIUM 6.8
CVE-2015-1495

Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open metho…

Patch available
Fix from $1,600 2015-02-16
Eki 1200 Gateway Series Firmware HIGH 10.0
CVE-2014-8385

Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 1.62
Fix from $1,950 2015-02-13
Mini Httpd MEDIUM 5.0
CVE-2015-1548

mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol stri…

Fix: after 1.21
Fix from $1,600 2015-02-10
Ubuntu Linux MEDIUM 6.8
CVE-2014-9673

Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial o…

No fix yet
Fix from $1,600 2015-02-08
Debian Linux MEDIUM 5.8
CVE-2014-9672

Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bo…

Fix: after 2.5.3
Fix from $1,600 2015-02-08
Debian Linux MEDIUM 6.8
CVE-2014-9667

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus…

No fix yet
Fix from $1,600 2015-02-08
Fedora HIGH 7.5
CVE-2014-9668

The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, whi…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2014-9665

The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG data, which allows remote at…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Enterprise Linux Desktop MEDIUM 6.8
CVE-2014-9664

FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,600 2015-02-08
Debian Linux HIGH 7.5
CVE-2014-9663EPSS 5%

The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely cal…

Patch available
Fix from $1,950 2015-02-08
Debian Linux HIGH 7.5
CVE-2014-9662

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a deni…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2014-9659EPSS 8%

cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Fedora HIGH 7.5
CVE-2014-9656

The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remot…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
12400 Level Transmitter Device Type Manager MEDIUM 5.0
CVE-2014-9203

Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, …

Mitigation only
Fix from $1,600 2015-02-07
Ubuntu Linux MEDIUM 5.0
CVE-2014-9636EPSS 12%

unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size s…

Patch available
Fix from $1,600 2015-02-06
Fedora HIGH 7.5
CVE-2015-1462

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."

Fix: after 0.98.5
Fix from $1,950 2015-02-03
Fedora HIGH 7.5
CVE-2015-1461

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap o…

Fix: after 0.98.5
Fix from $1,950 2015-02-03
Instant Access Point Firmware HIGH 7.8
CVE-2015-1348

Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of …

Fix: after 4.0.0.6
Fix from $1,950 2015-02-03
Fedora HIGH 7.5
CVE-2014-9328

ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."

Fix: after 0.98.5
Fix from $1,950 2015-02-03
Ruggedcom Firmware HIGH 10.0
CVE-2015-1449

Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware b…

Mitigation only
Fix from $1,950 2015-02-02
Somachine HIGH 7.5
CVE-2014-9200EPSS 6%

Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modb…

Mitigation only
Fix from $1,950 2015-02-01
Acrobat Reader HIGH 9.3
CVE-2014-9161

CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.13 and 11.x through 11.0.10 on…

No fix yet
Fix from $1,950 2015-01-30
Mac Os X MEDIUM 6.8
CVE-2014-8830

Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X HIGH 7.5
CVE-2014-8829

SceneKit in Apple OS X before 10.10.2 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.

Fix: after 10.10.1
Fix from $1,950 2015-01-30