Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Ntp HIGH 7.5
CVE-2014-9295EPSS 78%

Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, related to (…

Fix: after 4.2.7
Fix from $1,950 2014-12-20
C Icap MEDIUM 5.0
CVE-2013-7401

The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" c…

No fix yet
Fix from $1,600 2014-12-19
Ettercap MEDIUM 5.0
CVE-2014-9380

The dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a p…

Patch available
Fix from $1,600 2014-12-19
Ettercap HIGH 7.5
CVE-2014-9379

The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a de…

Patch available
Fix from $1,950 2014-12-19
Ettercap HIGH 7.5
CVE-2014-9377

Heap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remote attackers to cause a denial…

Patch available
Fix from $1,950 2014-12-19
Ettercap HIGH 7.5
CVE-2014-6396

The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and pos…

Fix: after 0.8.0
Fix from $1,950 2014-12-19
Ettercap HIGH 7.5
CVE-2014-6395EPSS 13%

Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cau…

Fix: after 0.8.0
Fix from $1,950 2014-12-19
Centrecom Ar415s Firmware HIGH 10.0
CVE-2014-7249EPSS 6%

Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT…

Fix: after 2.9.1-20
Fix from $1,950 2014-12-19
MariaDB MEDIUM 5.0
CVE-2014-8964EPSS 7%

Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via…

Fix: 10.0.18+
Fix from $1,600 2014-12-16
HTTP Server MEDIUM 5.0
CVE-2014-3583EPSS 11%

The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause …

Mitigation only
Fix from $1,600 2014-12-15
Opos Suite HIGH 7.5
CVE-2014-8269

Multiple stack-based buffer overflows in (1) HWOPOSScale.ocx and (2) HWOPOSSCANNER.ocx in Honeywell OPOS Suite before 1.13.4.15 allow remote attacker…

Fix: after 1.13.4.14
Fix from $1,950 2014-12-13
K7av Sentry Device Driver HIGH 7.2
CVE-2014-8956

Stack-based buffer overflow in the K7Sentry.sys kernel mode driver (aka K7AV Sentry Device Driver) before 12.8.0.119, as used in multiple K7 Computin…

Fix: after 12.8.0.118
Fix from $1,950 2014-12-12
K7firewall Packet Driver HIGH 7.2
CVE-2014-7136

Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as used in multiple K7 Computing p…

Fix: after 14.0.1.15
Fix from $1,950 2014-12-12
Sql Anywhere HIGH 7.5
CVE-2014-9264

Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alia…

Mitigation only
Fix from $1,950 2014-12-11
Firefox MEDIUM 6.8
CVE-2014-1593

Stack-based buffer overflow in the mozilla::FileBlockCache::Read function in Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, Thunderbird b…

Fix: after 33.0
Fix from $1,600 2014-12-11
Acrobat Reader HIGH 10.0
CVE-2014-8460EPSS 10%

Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute ar…

Mitigation only
Fix from $1,950 2014-12-10
Acrobat HIGH 10.0
CVE-2014-8457EPSS 13%

Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute ar…

Mitigation only
Fix from $1,950 2014-12-10
X Server MEDIUM 6.5
CVE-2014-8103

X.Org Server (aka xserver and xorg-server) 1.15.0 through 1.16.x before 1.16.3 allows remote authenticated users to cause a denial of service (out-of…

Patch available
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8102

The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver …

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Xfree86 MEDIUM 6.5
CVE-2014-8100

The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 all…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Xfree86 MEDIUM 6.5
CVE-2014-8101

The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allo…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
X11 MEDIUM 6.5
CVE-2014-8099

The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 all…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8098EPSS 5%

The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows r…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
X Server MEDIUM 6.5
CVE-2014-8097

The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenti…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8096

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-se…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8095

The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authent…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Ffmpeg MEDIUM 5.0
CVE-2014-9319

The ff_hevc_decode_nal_sps function in libavcodec/hevc_ps.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attacke…

Fix: after 2.1.5
Fix from $1,600 2014-12-09
Ffmpeg HIGH 7.5
CVE-2014-9318

The raw_decode function in libavcodec/rawdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to cause a…

Fix: after 2.1.5
Fix from $1,950 2014-12-09
Ffmpeg HIGH 7.5
CVE-2014-9317

The decode_ihdr_chunk function in libavcodec/pngdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to …

Fix: after 2.1.5
Fix from $1,950 2014-12-09
Ffmpeg HIGH 7.5
CVE-2014-9316

The mjpeg_decode_app function in libavcodec/mjpegdec.c in FFMpeg before 2.1.6, 2.2.x through 2.3.x, and 2.4.x before 2.4.4 allows remote attackers to…

Fix: after 2.1.5
Fix from $1,950 2014-12-09