Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Ruby MEDIUM 6.8
CVE-2013-4164EPSS 35%

Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allo…

Patch available
Fix from $1,600 2013-11-23
Ffmpeg MEDIUM 5.0
CVE-2013-0861

The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corr…

Fix: after 1.0.2
Fix from $1,600 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0863

Buffer overflow in the rle_decode function in libavcodec/sanm.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unsp…

Fix: after 1.0.3
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0865

The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified i…

Fix: after 1.0.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0866

The aac_decode_init function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impa…

Fix: after 1.0.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0868

libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-b…

Fix: after 1.1.1
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0869

The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, rela…

Fix: after 1.1.1
Fix from $1,950 2013-11-23
Ffmpeg HIGH 10.0
CVE-2013-0872

The swr_init function in libswresample/swresample.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid or un…

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0874

The (1) doubles2str and (2) shorts2str functions in libavcodec/tiff.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via…

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0877

The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smus…

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0878

The advance_line function in libavcodec/targa.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted Targa image …

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 7.5
CVE-2013-4263

libavfilter in FFmpeg before 2.0.1 has unspecified impact and remote vectors related to a crafted "plane," which triggers an out-of-bounds heap write.

Fix: after 2.0
Fix from $1,950 2013-11-23
Ubuntu Linux HIGH 7.5
CVE-2013-4473EPSS 7%

Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial o…

Fix: after 0.24.1
Fix from $1,950 2013-11-23
Wireless Lan Controller MEDIUM 5.0
CVE-2013-6699

The Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation on Cisco Wireless LAN Controller (WLC) devices allows remote …

Mitigation only
Fix from $1,600 2013-11-22
iOS MEDIUM 5.4
CVE-2013-6693

The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial o…

Fix: after 15.3
Fix from $1,600 2013-11-22
Gnutls MEDIUM 5.0
CVE-2013-4466

Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote serv…

Patch available
Fix from $1,600 2013-11-20
Network Interface Router MEDIUM 6.8
CVE-2013-6817

Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrar…

Mitigation only
Fix from $1,600 2013-11-20
Linux Kernel HIGH 7.0
CVE-2013-4588

Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local use…

Fix: 2.6.33+
Fix from $1,950 2013-11-20
Linux Kernel MEDIUM 6.2
CVE-2013-4591

Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of…

Fix: after 3.7.1
Fix from $1,600 2013-11-20
Chrome MEDIUM 5.0
CVE-2013-6627EPSS 5%

net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows…

Fix: after 31.0.1650.47
Fix from $1,600 2013-11-13
Flash Player HIGH 10.0
CVE-2013-5329EPSS 6%

Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR …

Fix: 3.9.0.1210 / 11.2.202.327+
Fix from $1,950 2013-11-13
Flash Player HIGH 10.0
CVE-2013-5330EPSS 11%

Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR …

Fix: 3.9.0.1210 / 11.2.202.327+
Fix from $1,950 2013-11-13
Office HIGH 9.3
CVE-2013-0082EPSS 19%

Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "WPD Fil…

Mitigation only
Fix from $1,950 2013-11-13
Office HIGH 9.3
CVE-2013-1324EPSS 31%

Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2013-11-13
Office HIGH 9.3
CVE-2013-1325EPSS 31%

Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect docu…

Mitigation only
Fix from $1,950 2013-11-13
Linux Kernel MEDIUM 6.9
CVE-2013-6763

The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local …

Fix: 3.2.53 / 3.4.71+
Fix from $1,600 2013-11-12
Nx Os MEDIUM 5.0
CVE-2013-5566

Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication …

Fix: after 5.0
Fix from $1,600 2013-11-08
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-5562

The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTT…

Mitigation only
Fix from $1,600 2013-11-06
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2013-5559

Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-as…

Mitigation only
Fix from $1,600 2013-11-04
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-5564

The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2013-11-04