Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
.net Framework HIGH 9.3
CVE-2013-0002EPSS 25%

Buffer overflow in the Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, and 4.5 …

Mitigation only
Fix from $1,950 2013-01-09
Libtiff MEDIUM 6.8
CVE-2012-5581

Stack-based buffer overflow in tif_dir.c in LibTIFF before 4.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute ar…

Fix: after 4.0.1
Fix from $1,600 2013-01-04
Swi Prolog HIGH 7.5
CVE-2012-6089

Multiple stack-based buffer overflows in the canoniseFileName function in os/pl-os.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote a…

Fix: after 6.2.4
Fix from $1,950 2013-01-04
Swi Prolog HIGH 7.5
CVE-2012-6090

Multiple stack-based buffer overflows in the expand function in os/pl-glob.c in SWI-Prolog before 6.2.5 and 6.3.x before 6.3.7 allow remote attackers…

Fix: after 6.2.4
Fix from $1,950 2013-01-04
Asterisk MEDIUM 5.0
CVE-2012-5976

Multiple stack consumption vulnerabilities in Asterisk Open Source 1.8.x before 1.8.19.1, 10.x before 10.11.1, and 11.x before 11.1.2; Certified Aste…

Fix: after 1.8.19.0
Fix from $1,600 2013-01-04
Opera Browser HIGH 9.3
CVE-2012-6470EPSS 8%

Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary code or cause a denial of ser…

Fix: after 12.11
Fix from $1,950 2013-01-02
Opera Browser HIGH 9.3
CVE-2012-6468

Heap-based buffer overflow in Opera before 12.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v…

Fix: after 12.10
Fix from $1,950 2013-01-02
Edirectory HIGH 10.0
CVE-2012-0432EPSS 59%

Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecifie…

Mitigation only
Fix from $1,950 2012-12-25
MySQL HIGH 7.5
CVE-2012-0882EPSS 5%

Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote at…

Mitigation only
Fix from $1,950 2012-12-21
Hyperion Interactive Reporting MEDIUM 6.8
CVE-2012-3133

Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11…

Mitigation only
Fix from $1,600 2012-12-21
Realplayer HIGH 9.3
CVE-2012-5691EPSS 53%

Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code vi…

Fix: after 16.0.0
Fix from $1,950 2012-12-19
Bogofilter HIGH 7.5
CVE-2012-5468EPSS 6%

Heap-based buffer overflow in iconvert.c in the bogolexer component in Bogofilter before 1.2.3 allows remote attackers to cause a denial of service (…

Fix: after 1.2.2
Fix from $1,950 2012-12-18
Perl HIGH 7.5
CVE-2012-5195

Heap-based buffer overflow in the Perl_repeatcpy function in util.c in Perl 5.12.x before 5.12.5, 5.14.x before 5.14.3, and 5.15.x before 15.15.5 all…

Patch available
Fix from $1,950 2012-12-18
Camera Raw HIGH 7.5
CVE-2012-5679

Buffer underflow in Adobe Photoshop Camera Raw before 7.3 allows attackers to execute arbitrary code via unspecified vectors.

Fix: after 7.2
Fix from $1,950 2012-12-13
Camera Raw HIGH 10.0
CVE-2012-5680EPSS 9%

Buffer overflow in Adobe Photoshop Camera Raw before 7.3 allows attackers to execute arbitrary code via unspecified vectors.

Fix: after 7.2
Fix from $1,950 2012-12-13
Ubuntu Linux HIGH 10.0
CVE-2012-5144

Google Chrome before 23.0.1271.97, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, do not properly perform AAC decoding, which allows remote att…

Fix: after 23.0.1271.96
Fix from $1,950 2012-12-12
Flash Player HIGH 10.0
CVE-2012-5676EPSS 8%

Buffer overflow in Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on …

Fix: 3.5.0.880 / 3.5.0.890+
Fix from $1,950 2012-12-12
Flash Player HIGH 10.0
CVE-2012-5678EPSS 5%

Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on Mac OS X, before 10…

Fix: 3.5.0.880 / 3.5.0.890+
Fix from $1,950 2012-12-12
Directx HIGH 9.3
CVE-2012-1537EPSS 23%

Heap-based buffer overflow in DirectPlay in DirectX 9.0 through 11.1 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2,…

Mitigation only
Fix from $1,950 2012-12-12
Informix Dynamic Server HIGH 9.0
CVE-2012-4857

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via …

Mitigation only
Fix from $1,950 2012-12-08
Intelligent Management Center HIGH 10.0
CVE-2012-3274EPSS 62%

Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allow…

Fix: after 5.1
Fix from $1,950 2012-12-06
Chrome HIGH 7.5
CVE-2012-5129

Heap-based buffer overflow in the WebGL subsystem in Google Chrome OS before 23.0.1271.94 allows remote attackers to cause a denial of service (GPU p…

Fix: after 21.0.1180.57
Fix from $1,950 2012-12-04
MariaDB MEDIUM 6.5
CVE-2012-5611EPSS 24%

Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5…

No fix yet
Fix from $1,600 2012-12-03
Libssh HIGH 7.5
CVE-2012-4560EPSS 6%

Multiple buffer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via u…

Fix: after 0.5.2
Fix from $1,950 2012-11-30
Chrome MEDIUM 6.8
CVE-2012-5134

Heap-based buffer underflow in the xmlParseAttValueComplex function in parser.c in libxml2 2.9.0 and earlier, as used in Google Chrome before 23.0.12…

Fix: after 23.0.1271.89
Fix from $1,600 2012-11-28
Guitar Pro MEDIUM 5.0
CVE-2012-6048

Guitar Pro 6.1.1 r10791 allows remote attackers to cause a denial of service (crash) via a long string in a gpx file.

No fix yet
Fix from $1,600 2012-11-27
Trousers MEDIUM 5.0
CVE-2012-0698EPSS 11%

tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to…

Fix: after 0.3.9
Fix from $1,600 2012-11-26
Mcrypt MEDIUM 6.8
CVE-2012-4409EPSS 15%

Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute a…

Fix: after 2.6.8
Fix from $1,600 2012-11-21
Mcrypt MEDIUM 6.8
CVE-2012-4527EPSS 8%

Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execu…

Fix: after 2.6.8
Fix from $1,600 2012-11-21
Firefox HIGH 9.3
CVE-2012-5833

The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunde…

Fix: 2.14 / 10.0.11+
Fix from $1,950 2012-11-21