Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
MariaDB MEDIUM 5.0
CVE-2013-1861EPSS 19%

MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earli…

Fix: 5.5.32 / 10.0.4+
Fix from $1,600 2013-03-28
Bind HIGH 7.8
CVE-2013-2266EPSS 43%

libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows re…

Mitigation only
Fix from $1,950 2013-03-28
Chrome MEDIUM 5.0
CVE-2013-0917

The URL loader in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Chrome MEDIUM 5.0
CVE-2013-0923

The USB Apps API in Google Chrome before 26.0.1410.43 allows remote attackers to cause a denial of service (memory corruption) via unspecified vector…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Linux Kernel MEDIUM 6.8
CVE-2013-1796

The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_…

Fix: after 3.8.4
Fix from $1,600 2013-03-22
Linux Kernel MEDIUM 6.9
CVE-2013-1860

Heap-based buffer overflow in the wdm_in_callback function in drivers/usb/class/cdc-wdm.c in the Linux kernel before 3.8.4 allows physically proximat…

Fix: 3.0.70 / 3.2.41+
Fix from $1,600 2013-03-22
Simatic Pcs7 MEDIUM 6.8
CVE-2013-0674

Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remot…

Fix: after 8.0
Fix from $1,600 2013-03-21
Simatic Pcs7 MEDIUM 6.1
CVE-2013-0675

Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other…

Fix: after 8.0
Fix from $1,600 2013-03-21
Realplayer HIGH 9.3
CVE-2013-1750

Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitra…

Fix: after 16.0.0.282
Fix from $1,950 2013-03-20
Latd HIGH 10.0
CVE-2013-0251

Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) an…

Mitigation only
Fix from $1,950 2013-03-19
Chrome Os HIGH 10.0
CVE-2013-0915

The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have unspecified other impact via …

Fix: after 25.0.1364.172
Fix from $1,950 2013-03-18
Firebird MEDIUM 6.8
CVE-2013-2492EPSS 42%

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to…

No fix yet
Fix from $1,600 2013-03-15
Mac Os X MEDIUM 6.8
CVE-2013-0976

IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption…

Fix: after 10.8.2
Fix from $1,600 2013-03-15
Openafs MEDIUM 6.5
CVE-2013-1794

Buffer overflow in certain client utilities in OpenAFS before 1.6.2 allows remote authenticated users to cause a denial of service (crash) and possib…

Fix: after 1.6.1
Fix from $1,600 2013-03-14
Cfingerd HIGH 10.0
CVE-2013-1049

Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execu…

Patch available
Fix from $1,950 2013-03-14
Qpid MEDIUM 5.0
CVE-2012-4460

The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial o…

Fix: after 0.20
Fix from $1,600 2013-03-14
Flash Player HIGH 10.0
CVE-2013-1371EPSS 5%

Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11.2.202.275 on Linux,…

Fix: after 11.6.602.171
Fix from $1,950 2013-03-13
Flash Player HIGH 10.0
CVE-2013-1375EPSS 9%

Heap-based buffer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x…

Fix: after 11.6.602.171
Fix from $1,950 2013-03-13
Sharepoint Foundation HIGH 7.8
CVE-2013-0085EPSS 34%

Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP…

Mitigation only
Fix from $1,950 2013-03-13
Sharepoint Foundation MEDIUM 5.0
CVE-2013-0086EPSS 24%

Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive infor…

Mitigation only
Fix from $1,600 2013-03-13
Ffmpeg HIGH 7.5
CVE-2013-2496

The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allo…

Fix: after 1.1.3
Fix from $1,950 2013-03-09
Curl HIGH 7.5
CVE-2013-0249EPSS 22%

Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when ne…

No fix yet
Fix from $1,950 2013-03-08
Javafx HIGH 10.0
CVE-2013-0402EPSS 10%

Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier all…

Fix: after 2.2.7
Fix from $1,950 2013-03-08
Chrome HIGH 7.5
CVE-2013-0904

The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possib…

Fix: after 25.0.1364.126
Fix from $1,950 2013-03-05
Chrome HIGH 7.5
CVE-2013-0906

The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possib…

Fix: after 25.0.1364.126
Fix from $1,950 2013-03-05
Nss Pam Ldapd MEDIUM 6.8
CVE-2013-0288

nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly …

Fix: after 0.7.17
Fix from $1,600 2013-03-05
Writer 2007 HIGH 9.3
CVE-2013-0710

Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.

Fix: after 2723
Fix from $1,950 2013-03-05
Aironet Access Point Software MEDIUM 6.1
CVE-2012-6026

The HTTP Profiler on the Cisco Aironet Access Point with software 15.2 and earlier does not properly manage buffers, which allows remote attackers to…

Mitigation only
Fix from $1,600 2013-03-05
Rack MEDIUM 5.0
CVE-2013-0183

multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and ou…

Patch available
Fix from $1,600 2013-03-01
Wireless Lan Controller Software MEDIUM 6.1
CVE-2013-1141

The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, w…

Fix: after 7.4.1.54
Fix from $1,600 2013-02-28