Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Sysklogd HIGH 7.5
CVE-2014-3634EPSS 8%

rsyslog before 7.6.6 and 8.x before 8.4.1 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (crash), possibly execute…

Fix: after 7.6.5
Fix from $1,950 2014-11-02
Freeradius HIGH 7.5
CVE-2014-2015

Stack-based buffer overflow in the normify function in the rlm_pap module (modules/rlm_pap/rlm_pap.c) in FreeRADIUS 2.x, possibly 2.2.3 and earlier, …

Patch available
Fix from $1,950 2014-11-02
Bootstrap Dht HIGH 7.5
CVE-2014-8509EPSS 5%

The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which t…

Patch available
Fix from $1,950 2014-10-31
Allplayer HIGH 7.5
CVE-2013-7409EPSS 68%

Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…

Fix: after 5.8.1
Fix from $1,950 2014-10-30
Pidgin MEDIUM 5.0
CVE-2014-3695

markup.c in the MXit protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (application crash) via…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Pidgin MEDIUM 5.0
CVE-2014-3696

nmevent.c in the Novell GroupWise protocol plugin in libpurple in Pidgin before 2.10.10 allows remote servers to cause a denial of service (applicati…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
FreeBSD HIGH 10.0
CVE-2014-3954

Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execut…

Patch available
Fix from $1,950 2014-10-27
Cpuminer MEDIUM 6.0
CVE-2014-6251

Stack-based buffer overflow in CPUMiner before 2.4.1 allows remote attackers to have an unspecified impact by sending a mining.subscribe response wit…

Fix: after 2.4.0
Fix from $1,600 2014-10-25
Ubuntu Linux MEDIUM 6.8
CVE-2014-3564

Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remot…

Fix: after 1.5.0
Fix from $1,600 2014-10-20
Mac Os X HIGH 7.2
CVE-2014-4433

Heap-based buffer overflow in the kernel in Apple OS X before 10.10 allows physically proximate attackers to execute arbitrary code via crafted resou…

Fix: after 10.9.5
Fix from $1,950 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4351

Buffer overflow in QuickTime in Apple OS X before 10.10 allows remote attackers to execute arbitrary code or cause a denial of service (application c…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Foxit Pdf Sdk Activex MEDIUM 6.8
CVE-2014-8074

Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote a…

Mitigation only
Fix from $1,600 2014-10-17
Tigervnc HIGH 7.5
CVE-2014-8240

Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related t…

Mitigation only
Fix from $1,950 2014-10-16
Firefox HIGH 7.5
CVE-2014-1576EPSS 5%

Heap-based buffer overflow in the nsTransformedTextRun function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x be…

Fix: after 32.0
Fix from $1,950 2014-10-15
Firefox HIGH 7.5
CVE-2014-1578

The get_tile function in Mozilla Firefox before 33.0, Firefox ESR 31.x before 31.2, and Thunderbird 31.x before 31.2 allows remote attackers to cause…

Fix: after 32.0
Fix from $1,950 2014-10-15
Junos HIGH 7.8
CVE-2014-3818

Juniper Junos OS 9.1 through 11.4 before 11.4R11, 12.1 before R10, 12.1X44 before D40, 12.1X46 before D30, 12.1X47 before D11 and 12.147-D15, 12.1X48…

Mitigation only
Fix from $1,950 2014-10-14
Chrome MEDIUM 5.0
CVE-2014-3201

core/rendering/compositing/RenderLayerCompositor.cpp in Blink, as used in Google Chrome before 38.0.2125.102 on Android, does not properly handle a c…

Fix: after 38.0.2125.101
Fix from $1,600 2014-10-10
Chrome MEDIUM 5.0
CVE-2014-3198

The Instance::HandleInputEvent function in pdf/instance.cc in the PDFium component in Google Chrome before 38.0.2125.101 interprets a certain -1 valu…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Cyberoam Os HIGH 9.3
CVE-2014-5501

Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to exe…

Fix: after 10.6.1
Fix from $1,950 2014-10-07
Solaris HIGH 10.0
CVE-2014-0397

Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vectors related to "Buffer errors."

Mitigation only
Fix from $1,950 2014-10-06
Ubuntu Linux MEDIUM 5.8
CVE-2014-3633

The qemuDomainGetBlockIoTune function in qemu/qemu_driver.c in libvirt before 1.2.9, when a disk has been hot-plugged or removed from the live image,…

Fix: after 1.2.8
Fix from $1,600 2014-10-06
Embarcadero C\+\+builder Xe6 MEDIUM 6.8
CVE-2014-0994

Heap-based buffer overflow in the ReadDIB function in the Vcl.Graphics.TPicture.Bitmap implementation in the Visual Component Library (VCL) in Embarc…

No fix yet
Fix from $1,600 2014-10-06
Fedora MEDIUM 6.5
CVE-2014-6055EPSS 8%

Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users …

Fix: after 0.9.9
Fix from $1,600 2014-09-30
Advanced Package Tool MEDIUM 6.8
CVE-2014-6273

Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash…

Fix: after 1.0.1
Fix from $1,600 2014-09-30
Bash HIGH 10.0
CVE-2014-7186EPSS 64%

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds arra…

Mitigation only
Fix from $1,950 2014-09-28
Bash HIGH 10.0
CVE-2014-7187EPSS 58%

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,950 2014-09-28
Linux Kernel MEDIUM 6.9
CVE-2014-0205

The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue opera…

Fix: after 2.6.36.4
Fix from $1,600 2014-09-28
Linux Kernel HIGH 7.8
CVE-2014-3535

include/linux/netdevice.h in the Linux kernel before 2.6.36 incorrectly uses macros for netdev_printk and its related logging implementation, which a…

Fix: after 2.6.35.13
Fix from $1,950 2014-09-28
Linux Kernel MEDIUM 6.9
CVE-2014-3181

Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux…

Fix: 3.2.63 / 3.4.104+
Fix from $1,600 2014-09-28
Linux Kernel MEDIUM 6.9
CVE-2014-3182

Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate at…

Fix: 3.2.63 / 3.4.104+
Fix from $1,600 2014-09-28