Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Firefox MEDIUM 5.0
CVE-2014-1565

The mozilla::dom::AudioEventTimeline function in the Web Audio API implementation in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and T…

Fix: after 31.1.0
Fix from $1,600 2014-09-03
Chrome MEDIUM 5.0
CVE-2014-3173

The WebGL implementation in Google Chrome before 37.0.2062.94 does not ensure that clear calls interact properly with the state of a draw buffer, whi…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Chrome MEDIUM 5.0
CVE-2014-3174

modules/webaudio/BiquadDSPKernel.cpp in the Web Audio API implementation in Blink, as used in Google Chrome before 37.0.2062.94, does not properly co…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Qemu MEDIUM 6.8
CVE-2014-5263

vmstate_xhci_event in hw/usb/hcd-xhci.c in QEMU 1.6.0 does not terminate the list with the VMSTATE_END_OF_LIST macro, which allows attackers to cause…

Patch available
Fix from $1,600 2014-08-26
Panda Av Pro 2014 HIGH 7.2
CVE-2014-5307

Heap-based buffer overflow in the PavTPK.sys kernel mode driver of Panda Security 2014 products before hft131306s24_r1 allows local users to gain pri…

No fix yet
Fix from $1,950 2014-08-26
FreeBSD MEDIUM 5.0
CVE-2014-5384

The VIQR module in the iconv implementation in FreeBSD 10.0 before p6 and NetBSD allows context-dependent attackers to cause a denial of service (out…

Mitigation only
Fix from $1,600 2014-08-21
Spark Browser MEDIUM 5.0
CVE-2014-5349

Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested…

No fix yet
Fix from $1,600 2014-08-19
Safari MEDIUM 6.8
CVE-2014-1384

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1385

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1386

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1387

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1388

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1389

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Safari MEDIUM 6.8
CVE-2014-1390

WebKit, as used in Apple Safari before 6.1.6 and 7.x before 7.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 6.1.5
Fix from $1,600 2014-08-14
Substation Server HIGH 7.1
CVE-2014-2357

The GPT library in the Telegyr 8979 Master Protocol application in SUBNET SubSTATION Server 2 before SSNET 2.12 HF18808 allows remote attackers to ca…

Fix: after 2.12
Fix from $1,950 2014-08-11
Er\/studio Data Architect MEDIUM 6.8
CVE-2014-4647

Stack-based buffer overflow in the loadExtensionFactory method in the TSVisualization ActiveX control in Embarcadero ER/Studio Data Architect allows …

Mitigation only
Fix from $1,600 2014-08-07
Network Configuration Manager MEDIUM 6.8
CVE-2014-3459EPSS 12%

Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEs…

Fix: after 7.2.2
Fix from $1,600 2014-08-07
Endpoint Protection MEDIUM 6.9
CVE-2014-3434

Buffer overflow in the sysplant driver in Symantec Endpoint Protection (SEP) Client 11.x and 12.x before 12.1 RU4 MP1b, and Small Business Edition be…

No fix yet
Fix from $1,600 2014-08-06
Wireshark MEDIUM 5.0
CVE-2014-5161

The dissect_log function in plugins/irda/packet-irda.c in the IrDA dissector in Wireshark 1.10.x before 1.10.9 does not properly strip '\n' character…

Mitigation only
Fix from $1,600 2014-08-01
Wireshark MEDIUM 5.0
CVE-2014-5162

The read_new_line function in wiretap/catapult_dct2000.c in the Catapult DCT2000 dissector in Wireshark 1.10.x before 1.10.9 does not properly strip …

Mitigation only
Fix from $1,600 2014-08-01
Wireshark MEDIUM 5.0
CVE-2014-5163

The APN decode functionality in (1) epan/dissectors/packet-gtp.c and (2) epan/dissectors/packet-gsm_a_gm.c in the GTP and GSM Management dissectors i…

No fix yet
Fix from $1,600 2014-08-01
Wireshark MEDIUM 5.0
CVE-2014-5164

The rlc_decode_li function in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.10.x before 1.10.9 initializes a certain structure mem…

No fix yet
Fix from $1,600 2014-08-01
Wireshark MEDIUM 5.0
CVE-2014-5165

The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.10.x before 1.10.9 does not …

No fix yet
Fix from $1,600 2014-08-01
Netty MEDIUM 5.0
CVE-2014-3488

The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hell…

Fix: after 3.9.1.1
Fix from $1,600 2014-07-31
Micro Httpd HIGH 7.8
CVE-2014-4927EPSS 11%

Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to …

No fix yet
Fix from $1,950 2014-07-24
Sketchbook Pro HIGH 9.3
CVE-2014-3939EPSS 6%

Heap-based buffer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer bitmap data in…

Fix: after 6.2.5
Fix from $1,950 2014-07-23
Sgminer HIGH 10.0
CVE-2014-4501

Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unsp…

Fix: after 4.3.4
Fix from $1,950 2014-07-23
Bfgminer HIGH 10.0
CVE-2014-4502

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remo…

Fix: after 4.2.1
Fix from $1,950 2014-07-23
Firefox HIGH 9.3
CVE-2014-1549EPSS 6%

The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not prope…

Fix: after 30.0
Fix from $1,950 2014-07-23
Xenserver HIGH 10.0
CVE-2014-4947EPSS 5%

Buffer overflow in the HVM graphics console support in Citrix XenServer 6.2 Service Pack 1 and earlier has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2014-07-22