Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Firefox MEDIUM 5.0
CVE-2012-0441

The ASN.1 decoder in the QuickDER decoder in Mozilla Network Security Services (NSS) before 3.13.4, as used in Firefox 4.x through 12.0, Firefox ESR …

Fix: after 3.12.3
Fix from $1,600 2012-06-05
Firefox HIGH 9.3
CVE-2012-1939

jsinfer.cpp in Mozilla Firefox ESR 10.x before 10.0.5 and Thunderbird ESR 10.x before 10.0.5 does not properly determine data types, which allows rem…

Mitigation only
Fix from $1,950 2012-06-05
Firefox HIGH 9.3
CVE-2012-1941

Heap-based buffer overflow in the nsHTMLReflowState::CalculateHypotheticalBox function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 1…

Fix: after 2.9
Fix from $1,950 2012-06-05
Firefox HIGH 9.3
CVE-2012-1947

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 th…

Fix: after 2.9
Fix from $1,950 2012-06-05
Firefox HIGH 9.3
CVE-2012-3105

The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12…

Fix: after 2.9
Fix from $1,950 2012-06-05
Nut HIGH 7.5
CVE-2012-2944EPSS 6%

Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows remote attackers to execute arbi…

Fix: after 2.6.3-3
Fix from $1,950 2012-06-01
Autostart HIGH 7.5
CVE-2012-0409

Multiple buffer overflows in EMC AutoStart 5.3.x and 5.4.x before 5.4.3 allow remote attackers to cause a denial of service (agent crash) or possibly…

Mitigation only
Fix from $1,950 2012-06-01
Cvs HIGH 10.0
CVE-2012-0804EPSS 8%

Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of s…

Mitigation only
Fix from $1,950 2012-05-29
Libpng MEDIUM 6.8
CVE-2011-3048EPSS 7%

The png_set_text_2 function in pngset.c in libpng 1.0.x before 1.0.59, 1.2.x before 1.2.49, 1.4.x before 1.4.11, and 1.5.x before 1.5.10 allows remot…

Mitigation only
Fix from $1,600 2012-05-29
Haproxy MEDIUM 5.1
CVE-2012-2942EPSS 5%

Buffer overflow in the trash buffer in the header capture functionality in HAProxy before 1.4.21, when global.tune.bufsize is set to a value greater …

Fix: after 1.4.20
Fix from $1,600 2012-05-27
Lotus Quickr HIGH 9.3
CVE-2012-2176EPSS 31%

Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote at…

Mitigation only
Fix from $1,950 2012-05-25
Xarrow HIGH 10.0
CVE-2012-2427

Heap-based buffer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via packets that trigger an invalid…

Fix: after 3.4
Fix from $1,950 2012-05-25
Linux Kernel HIGH 8.8
CVE-2011-3191

Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denia…

Fix: 3.0.5+
Fix from $1,950 2012-05-24
Linux Kernel HIGH 7.5
CVE-2011-3359

The dma_rx function in drivers/net/wireless/b43/dma.c in the Linux kernel before 2.6.39 does not properly allocate receive buffers, which allows remo…

Fix: 2.6.39+
Fix from $1,950 2012-05-24
Linux Kernel HIGH 7.2
CVE-2011-2517

Multiple buffer overflows in net/wireless/nl80211.c in the Linux kernel before 2.6.39.2 allow local users to gain privileges by leveraging the CAP_NE…

Fix: 2.6.39.2+
Fix from $1,950 2012-05-24
Chrome HIGH 10.0
CVE-2011-3106

The WebSockets implementation in Google Chrome before 19.0.1084.52 does not properly handle use of SSL, which allows remote attackers to execute arbi…

Fix: after 19.0.1084.51
Fix from $1,950 2012-05-24
Chrome HIGH 7.5
CVE-2011-3110

The PDF functionality in Google Chrome before 19.0.1084.52 allows remote attackers to cause a denial of service or possibly have unspecified other im…

Fix: after 19.0.1084.51
Fix from $1,950 2012-05-24
Chrome MEDIUM 5.0
CVE-2011-3111

Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (invalid read operation) via unspecifie…

Fix: after 19.0.1084.51
Fix from $1,600 2012-05-24
Chrome HIGH 7.5
CVE-2011-3114

Multiple buffer overflows in the PDF functionality in Google Chrome before 19.0.1084.52 allow remote attackers to cause a denial of service or possib…

Fix: after 19.0.1084.51
Fix from $1,950 2012-05-24
Chrome HIGH 7.5
CVE-2011-3115

Google V8, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service or possibly have unspecified other impa…

Fix: after 19.0.1084.51
Fix from $1,950 2012-05-24
Chrome MEDIUM 5.0
CVE-2011-3104

Skia, as used in Google Chrome before 19.0.1084.52, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 19.0.1084.51
Fix from $1,600 2012-05-24
Illustrator HIGH 10.0
CVE-2012-2042

Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a d…

Fix: after 15
Fix from $1,950 2012-05-24
Endpoint Protection HIGH 7.2
CVE-2012-0289

Buffer overflow in Symantec Endpoint Protection (SEP) 11.0.600x through 11.0.710x and Symantec Network Access Control (SNAC) 11.0.600x through 11.0.7…

No fix yet
Fix from $1,950 2012-05-23
Skincrafter HIGH 10.0
CVE-2012-2271EPSS 8%

Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0 allows remote attackers to e…

Mitigation only
Fix from $1,950 2012-05-21
Pac Designer HIGH 9.3
CVE-2012-2915EPSS 29%

Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a V…

Mitigation only
Fix from $1,950 2012-05-21
Realplayer HIGH 9.3
CVE-2012-2411EPSS 5%

Buffer overflow in RealNetworks RealPlayer before 15.0.4.53, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code v…

Fix: after 15.0.4
Fix from $1,950 2012-05-18
Chrome MEDIUM 5.0
CVE-2011-3088

Google Chrome before 19.0.1084.46 does not properly draw hairlines, which allows remote attackers to cause a denial of service (out-of-bounds read) v…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3083

browser/profiles/profile_impl_io_data.cc in Google Chrome before 19.0.1084.46 does not properly handle a malformed ftp URL in the SRC attribute of a …

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Chrome MEDIUM 5.0
CVE-2011-3085

The Autofill feature in Google Chrome before 19.0.1084.46 does not properly restrict field values, which allows remote attackers to cause a denial of…

Fix: after 19.0.1084.45
Fix from $1,600 2012-05-16
Netweaver MEDIUM 5.0
CVE-2012-2511

The DiagTraceAtoms function in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2 allows remote…

No fix yet
Fix from $1,600 2012-05-15