Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-11059
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, setting the HMAC key by different thr…
Android
Mitigation only
HIGH 7.8
CVE-2017-11067
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not hav…
Android
Mitigation only
MEDIUM 6.5
CVE-2014-9092
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
Fedora
after 1.2.90
CRITICAL 9.8
CVE-2017-14980EPSS 22%
Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login.
Syncbreeze
No fix yet
HIGH 7.8
CVE-2017-13723
In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing c…
Debian Linux
after 1.19.3
CRITICAL 9.8
CVE-2014-9474
Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors r…
Gnu Mpfr
after 3.1.2
MEDIUM 5.5
CVE-2015-1206
Heap-based buffer overflow in Google Chrome before M40 allows remote attackers to cause a denial of service (unpaged memory write and process crash) …
Chrome
after 41.0.2251.0
HIGH 7.5
CVE-2017-1000254EPSS 8%
libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not…
Libcurl
Patch available
MEDIUM 5.5
CVE-2017-15046
LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vul…
Lame
No fix yet
CRITICAL 9.8
CVE-2017-15047
The clusterLoadConfig function in cluster.c in Redis 4.0.2 allows attackers to cause a denial of service (out-of-bounds array index and application c…
Redis
Patch available
HIGH 7.0
CVE-2017-14088
Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and esc…
Officescan
Patch available
CRITICAL 9.8
CVE-2017-14089EPSS 10%
An Unauthorized Memory Corruption vulnerability in Trend Micro OfficeScan 11.0 and XG may allow remote unauthenticated users who can access the Offic…
Officescan
Patch available
MEDIUM 6.8
CVE-2017-12732
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet len…
Intelligent Platforms Proficy Hmi\/scada Cimplicity
after 9.0
HIGH 7.8
CVE-2017-12106
A memory corruption vulnerability exists in the .TGA parsing functionality of Computerinsel Photoline 20.02. A specially crafted .TGA file can cause …
Photoline
No fix yet
HIGH 7.8
CVE-2017-2880
An memory corruption vulnerability exists in the .GIF parsing functionality of Computerinsel Photoline 20.02. A specially crafted .GIF file can cause…
Photoline
No fix yet
HIGH 7.8
CVE-2017-2920
An memory corruption vulnerability exists in the .SVG parsing functionality of Computerinsel Photoline 20.02. A specially crafted .SVG file can cause…
Photoline
Patch available
MEDIUM 5.3
CVE-2017-12267
A vulnerability in the Independent Computing Architecture (ICA) accelerator feature for the Cisco Wide Area Application Services (WAAS) could allow a…
Virtual Wide Area Application Services
Mitigation only
HIGH 7.5
CVE-2017-12270
A vulnerability in the gRPC code of Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series Routers could allow an unauthenticat…
Ios Xr
Mitigation only
HIGH 7.5
CVE-2017-15035EPSS 6%
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
Pyrobatchftp
after 3.17
MEDIUM 6.5
CVE-2017-1000101
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfer…
Curl
Mitigation only
HIGH 7.5
CVE-2017-1000118
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service
HTTP Server
after 10.0.5
HIGH 7.8
CVE-2017-1000253 KEVEPSS 11%
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committ…
Enterprise Linux
3.2.70 / 3.4.109+
HIGH 7.5
CVE-2017-15011
The named pipes in qtsingleapp in Qt 5.x, as used in qBittorrent and SugarSync, are configured for remote access and allow remote attackers to cause …
Qt
Mitigation only
HIGH 7.5
CVE-2017-12818
Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to re…
Sentinel Ldk Rte Firmware
after 7.50
HIGH 7.5
CVE-2017-12820
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version…
Sentinel Ldk Rte Firmware
after 7.50
CRITICAL 9.8
CVE-2017-12821
Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execu…
Sentinel Ldk Rte Firmware
after 7.50
HIGH 7.8
CVE-2017-0809
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7…
Android
Patch available
HIGH 7.8
CVE-2017-0810
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Andr…
Android
Patch available
CRITICAL 9.8
CVE-2017-14492EPSS 93%
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafte…
Ubuntu Linux
after 2.77
CRITICAL 9.8
CVE-2017-14493EPSS 84%
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a craft…
Ubuntu Linux
after 2.77