Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Realplayer HIGH 7.5
CVE-2013-7260EPSS 67%

Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote att…

Fix: after 17.0.4.60
Fix from $1,950 2014-01-03
Castripper HIGH 7.5
CVE-2009-5137

Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] sect…

No fix yet
Fix from $1,950 2014-01-03
Irfanview HIGH 7.6
CVE-2013-6932EPSS 6%

Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitra…

Fix: after 4.36
Fix from $1,950 2013-12-28
Enterprise Virtualization Hypervisor HIGH 7.4
CVE-2010-0430

libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other produ…

Fix: after 5.4-2.1
Fix from $1,950 2013-12-27
Ffmpeg MEDIUM 5.0
CVE-2012-6616

The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bou…

Fix: after 1.0.1
Fix from $1,600 2013-12-24
Xen MEDIUM 5.2
CVE-2013-4553

The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same …

Mitigation only
Fix from $1,600 2013-12-24
Mymp3pro HIGH 9.3
CVE-2013-7186EPSS 12%

Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file.

No fix yet
Fix from $1,950 2013-12-20
Antivirus Pro HIGH 7.2
CVE-2013-6767

Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denial of servi…

No fix yet
Fix from $1,950 2013-12-20
Realplayer HIGH 9.3
CVE-2013-6877EPSS 11%

Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to …

No fix yet
Fix from $1,950 2013-12-19
Asterisk MEDIUM 5.0
CVE-2013-7100

Buffer overflow in the unpacksms16 function in apps/app_sms.c in Asterisk Open Source 1.8.x before 1.8.24.1, 10.x before 10.12.4, and 11.x before 11.…

Patch available
Fix from $1,600 2013-12-19
Wireshark MEDIUM 5.0
CVE-2013-7114

Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x be…

Patch available
Fix from $1,600 2013-12-19
Safari MEDIUM 6.8
CVE-2013-5198

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5199

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5225

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5228

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Rational Clearcase HIGH 7.2
CVE-2013-5415

Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges …

Mitigation only
Fix from $1,950 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5196

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5197

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Safari MEDIUM 6.8
CVE-2013-5195

WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (me…

Fix: after 12.0
Fix from $1,600 2013-12-18
Sketchup Viewer MEDIUM 6.8
CVE-2013-6038

Stack-based buffer overflow in Trimble SketchUp Viewer 13.0.4124 allows remote attackers to execute arbitrary code via a crafted .SKP file.

Mitigation only
Fix from $1,600 2013-12-17
PHP HIGH 7.5
CVE-2013-6420EPSS 36%

The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (…

Fix: after 10.9.1
Fix from $1,950 2013-12-17
Interstage Application Server HIGH 10.0
CVE-2013-7105

Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1, and 10.…

Mitigation only
Fix from $1,950 2013-12-14
Openttd MEDIUM 5.0
CVE-2013-6411

The HandleCrashedAircraft function in aircraft_cmd.cpp in OpenTTD 0.3.6 through 1.3.2 allows remote attackers to cause a denial of service (out-of-bo…

Patch available
Fix from $1,600 2013-12-14
Libmicrohttpd MEDIUM 6.4
CVE-2013-7038

The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of servi…

Fix: after 0.9.31
Fix from $1,600 2013-12-13
Libmicrohttpd MEDIUM 5.1
CVE-2013-7039

Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a…

Fix: after 0.9.31
Fix from $1,600 2013-12-13
Icofx HIGH 9.3
CVE-2013-4988EPSS 67%

Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structu…

Fix: after 2.5
Fix from $1,950 2013-12-13
Openjpeg HIGH 7.5
CVE-2013-6054

Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.

Fix: after 1.3
Fix from $1,950 2013-12-12
Openjpeg HIGH 7.5
CVE-2013-6045EPSS 6%

Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 1.3
Fix from $1,950 2013-12-12
Glibc MEDIUM 5.0
CVE-2013-4458

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows …

Fix: after 2.18
Fix from $1,600 2013-12-12
Intelligent Platform Management Firmware HIGH 9.0
CVE-2013-3622EPSS 5%

Buffer overflow in logout.cgi in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generat…

Fix: after 2.26
Fix from $1,950 2013-12-10