Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Intelligent Platform Management Firmware HIGH 10.0
CVE-2013-3623EPSS 72%

Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Management Interface (IPMI) with firmw…

Fix: after 2.26
Fix from $1,950 2013-12-10
Samba HIGH 8.3
CVE-2013-4408

Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x be…

Patch available
Fix from $1,950 2013-12-10
Forms Viewer MEDIUM 6.8
CVE-2013-5447EPSS 34%

Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XF…

No fix yet
Fix from $1,600 2013-12-10
Linux Kernel MEDIUM 6.1
CVE-2013-7027

The ieee80211_radiotap_iterator_init function in net/wireless/radiotap.c in the Linux kernel before 3.11.7 does not check whether a frame contains an…

Fix: after 3.11.6
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7022

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers …

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7023

The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows rem…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7024

The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, wh…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7016

The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the expected sample separation, which allows remote attackers t…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7018

libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a …

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Debian Linux MEDIUM 6.8
CVE-2013-7020

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which a…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7011

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not prevent changes to global parameters, which allows remote attackers to…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7012

The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote at…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7009

The rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows remote att…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg HIGH 7.5
CVE-2011-4351

Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary c…

Fix: after 0.5.5
Fix from $1,950 2013-12-09
Ffmpeg HIGH 7.5
CVE-2011-3941

The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors relat…

Fix: after 0.9.1
Fix from $1,950 2013-12-09
Ffmpeg HIGH 9.3
CVE-2013-0845

libavcodec/alsdec.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impact via a crafted block length, which triggers an out-of…

Fix: after 1.0.3
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0847

The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, …

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0848

The decode_init function in libavcodec/huffyuv.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted width in hu…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0850

The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 da…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0851

The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Art…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0852

The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted R…

Fix: after 1.0
Fix from $1,950 2013-12-07
Chrome HIGH 7.5
CVE-2013-6639

The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, …

Fix: after 31.0.1650.62
Fix from $1,950 2013-12-07
Chrome HIGH 7.5
CVE-2013-6640

The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, …

Fix: after 31.0.1650.62
Fix from $1,950 2013-12-07
Chrome HIGH 7.5
CVE-2013-6638

Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause …

Fix: after 31.0.1650.62
Fix from $1,950 2013-12-07
Watermark Master HIGH 9.3
CVE-2013-6935EPSS 32%

Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath…

No fix yet
Fix from $1,950 2013-12-04
Connect Participant Application MEDIUM 6.8
CVE-2013-6029

Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code vi…

Fix: after 9.5.0
Fix from $1,600 2013-12-04
Watermark Master MEDIUM 6.8
CVE-2013-6937

Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attri…

No fix yet
Fix from $1,600 2013-12-04
PHP MEDIUM 5.0
CVE-2013-6712

The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might…

Fix: 5.3.29 / 5.4.24+
Fix from $1,600 2013-11-28
Linux Kernel MEDIUM 6.9
CVE-2013-6381

Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause…

Fix: 3.2.54 / 3.4.72+
Fix from $1,600 2013-11-27
Light Alloy HIGH 9.3
CVE-2013-6874EPSS 6%

Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.

Fix: after 4.7.3
Fix from $1,950 2013-11-26