Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Iphone Os HIGH 10.0
CVE-2014-4487

Buffer overflow in IOHIDFamily in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows attackers to execute arbitrary …

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Iphone Os HIGH 7.5
CVE-2014-4485

Buffer overflow in the XML parser in Foundation in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attacke…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Iphone Os MEDIUM 6.8
CVE-2014-4483

Buffer overflow in FontParser in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute arbi…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Safari MEDIUM 6.8
CVE-2014-4479

WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remot…

Fix: after 12.1
Fix from $1,600 2015-01-30
Safari MEDIUM 6.8
CVE-2014-4477

WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remot…

Fix: after 12.1
Fix from $1,600 2015-01-30
Safari MEDIUM 6.8
CVE-2014-4476

WebKit, as used in Apple iOS before 8.1.3; Apple Safari before 6.2.3, 7.x before 7.1.3, and 8.x before 8.0.3; and Apple TV before 7.0.3, allows remot…

Fix: after 12.1
Fix from $1,600 2015-01-30
I Access HIGH 7.2
CVE-2014-8920

Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecif…

Patch available
Fix from $1,950 2015-01-28
Vala HIGH 7.5
CVE-2014-8154

The Gst.MapInfo function in Vala 0.26.0 and 0.26.1 uses an incorrect buffer length declaration for the Gstreamer bindings, which allows context-depen…

Patch available
Fix from $1,950 2015-01-27
Reflection Ftp Client MEDIUM 6.8
CVE-2014-5211

Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large P…

Mitigation only
Fix from $1,600 2015-01-27
Exif Pilot HIGH 7.5
CVE-2015-1362EPSS 8%

Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary code via a long string in the m…

No fix yet
Fix from $1,950 2015-01-27
Chrome HIGH 7.5
CVE-2015-1360

Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecif…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-27
Debian Linux MEDIUM 6.8
CVE-2014-8158EPSS 14%

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or poss…

Fix: after 1.900.1
Fix from $1,600 2015-01-26
Vorbis Tools MEDIUM 5.0
CVE-2014-9640

oggenc/oggenc.c in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted raw file.

Mitigation only
Fix from $1,600 2015-01-23
Chrome MEDIUM 5.0
CVE-2014-7946

The RenderTable::simplifiedNormalFlowLayout function in core/rendering/RenderTable.cpp in Blink, as used in Google Chrome before 40.0.2214.91, skips …

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome MEDIUM 5.0
CVE-2014-7947

OpenJPEG before r2944, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome MEDIUM 5.0
CVE-2014-7945

OpenJPEG before r2908, as used in PDFium in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome MEDIUM 5.0
CVE-2014-7944

The sycc422_to_rgb function in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 40.0.2214.91, does not properly handle o…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Ubuntu Linux MEDIUM 5.0
CVE-2014-7943

Skia, as used in Google Chrome before 40.0.2214.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2014-7941

The SelectionOwner::ProcessTarget function in ui/base/x/selection_owner.cc in the UI implementation in Google Chrome before 40.0.2214.91 uses an inco…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-22
Chrome HIGH 7.5
CVE-2014-7938

The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly ha…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Chrome HIGH 7.5
CVE-2014-7937

Multiple off-by-one errors in libavcodec/vorbisdec.c in FFmpeg before 2.4.2, as used in Google Chrome before 40.0.2214.91, allow remote attackers to …

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Adamview HIGH 7.5
CVE-2014-8386EPSS 6%

Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary code via a crafted (1) displa…

Fix: after 4.3
Fix from $1,950 2015-01-20
Solaris HIGH 8.8
CVE-2015-0973

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers t…

Fix: after 10.11.3
Fix from $1,950 2015-01-18
Intelligent Platforms Proficy Hmi\/scada Cimplicity MEDIUM 6.9
CVE-2014-2355

The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted…

Fix: after 8.2
Fix from $1,600 2015-01-17
Sap Kernel MEDIUM 6.5
CVE-2014-9595

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-01-15
Sap Kernel MEDIUM 6.5
CVE-2014-9594

Buffer overflow in the SAP NetWeaver Dispatcher in SAP Kernel 7.00 32-bit and 7.40 64-bit allows remote authenticated users to cause a denial of serv…

Mitigation only
Fix from $1,600 2015-01-15
Fedora MEDIUM 5.0
CVE-2014-8738EPSS 5%

The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (i…

Fix: after 2.24
Fix from $1,600 2015-01-15
Adobe Air HIGH 10.0
CVE-2015-0309EPSS 9%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.42…

Fix: after 15.0.0.356
Fix from $1,950 2015-01-13
Adobe Air HIGH 8.5
CVE-2015-0307EPSS 5%

Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 1…

Fix: after 15.0.0.356
Fix from $1,950 2015-01-13
Adobe Air Sdk HIGH 10.0
CVE-2015-0304EPSS 9%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.42…

Fix: after 15.0.0.356
Fix from $1,950 2015-01-13