Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
HIGH 8.8 CVE-2018-11095 The decompileJUMP function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual si… Libming after 0.4.8 Fix from $1,9502018-05-15 HIGH 7.8 CVE-2018-11033 The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (applica… Xpdf Mitigation only Fix from $1,9502018-05-14 HIGH 8.8 CVE-2018-11017 The newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the actual size, w… Libming after 0.4.8 Fix from $1,9502018-05-13 CRITICAL 9.8 CVE-2018-10996EPSS 5% The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buf… Dir 629 B Firmware No fix yet Fix from $2,3002018-05-12 HIGH 7.8 CVE-2017-6289 In Android before the 2018-05-05 security patch level, NVIDIA Trusted Execution Environment (TEE) contains a memory corruption (due to unusual root c… Android Mitigation only Fix from $1,9502018-05-10 HIGH 7.8 CVE-2018-10655EPSS 16% DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH). Plug And Play Auditor No fix yet Fix from $1,9502018-05-10 HIGH 7.1 CVE-2018-8061 HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symboli… Amd64 Kernel Driver after 8.98 Fix from $1,9502018-05-10 MEDIUM 6.5 CVE-2018-10958 In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUnc… Debian Linux No fix yet Fix from $1,6002018-05-10 MEDIUM 5.5 CVE-2018-10940 The cdrom_ioctl_media_changed function in drivers/cdrom/cdrom.c in the Linux kernel before 4.16.6 allows local attackers to use a incorrect bounds ch… Linux Kernel 4.16.6+ Fix from $1,6002018-05-09 HIGH 7.5 CVE-2018-1089 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading … Enterprise Linux Desktop 1.3.6.15 / 1.4.0.9+ Fix from $1,9502018-05-09 HIGH 7.5 CVE-2018-10184EPSS 8% An issue was discovered in HAProxy before 1.8.8. The incoming H2 frame length was checked against the max_frame_size setting instead of being checked… Enterprise Linux 1.8.8+ Fix from $1,9502018-05-09 MEDIUM 6.5 CVE-2018-10774 Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of … Bibutils after 6.2 Fix from $1,6002018-05-07 HIGH 7.8 CVE-2018-10777 Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (appl… Mp3gain after 1.5.2 Fix from $1,9502018-05-07 MEDIUM 6.5 CVE-2018-10772 The tEXtToDataBuf function in pngimage.cpp in Exiv2 through 0.26 allows remote attackers to cause a denial of service (application crash) or possibly… Exiv2 after 0.26 Fix from $1,6002018-05-07 HIGH 8.8 CVE-2018-7494 WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length stack buffer where a value larger than the buffer can be read from a f… Wplsoft after 2.45.0 Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-7507 WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a fi… Wplsoft after 2.45.0 Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10746 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'get' parameter to the '/userfs/bin/tca… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10747 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10748 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tc… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10749 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10750 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/b… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-04 MEDIUM 6.7 CVE-2018-7522 In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, when a system call is made, registers are stored to a fixed memory l… Triconex Tricon Mp 3008 Firmware after 10.0-10.4 Fix from $1,6002018-05-04 HIGH 8.1 CVE-2018-8872 In Schneider Electric Triconex Tricon MP model 3008 firmware versions 10.0-10.4, system calls read directly from memory addresses within the control … Triconex Tricon Mp 3008 Firmware after 10.4 Fix from $1,9502018-05-04 HIGH 7.8 CVE-2018-9063 MapDrv (C:\Program Files\Lenovo\System Update\mapdrv.exe) In Lenovo System Update versions earlier than 5.07.0072 contains a local vulnerability wher… System Update 5.07.0072+ Fix from $1,9502018-05-04 HIGH 8.8 CVE-2018-10713 An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'read' parameter to the '/userfs/bin/tc… Dsl 3782 Firmware No fix yet Fix from $1,9502018-05-03 MEDIUM 5.5 CVE-2018-10689 blktrace (aka Block IO Tracing) 1.2.0, as used with the Linux kernel and Android, has a buffer overflow in the dev_map_read function in btt/devmap.c … Blktrace Patch available Fix from $1,6002018-05-03 CRITICAL 9.8 CVE-2016-10721 partclone.restore in Partclone 0.2.87 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the partclone image he… Partclone Mitigation only Fix from $2,3002018-05-02 CRITICAL 9.8 CVE-2016-10722 partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient validation of the FAT superblock,… Partclone 0.2.88+ Fix from $2,3002018-05-02 HIGH 8.6 CVE-2018-0252 A vulnerability in the IP Version 4 (IPv4) fragment reassembly function of Cisco 3500, 5500, and 8500 Series Wireless LAN Controller Software could a… Wireless Lan Controller Software Mitigation only Fix from $1,9502018-05-02 MEDIUM 6.8 CVE-2018-6242 Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with p… Tegra Bootrom Rcm Mitigation only Fix from $1,6002018-05-01