Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
MEDIUM 6.8
CVE-2015-0555EPSS 6%
Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote attackers to execute arbitra…
Ipolis Device Manager
No fix yet
HIGH 10.0
CVE-2015-2052EPSS 5%
Stack-based buffer overflow in the DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitra…
Dir 645 Firmware
after 1.04b12
HIGH 7.5
CVE-2015-1315
Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a craf…
Ubuntu Linux
Patch available
MEDIUM 6.8
CVE-2015-0880
Buffer overflow in CREAR AL-Mail32 before 1.13d allows remote attackers to execute arbitrary code via a long filename of an attachment.
Al Mail32
after 1.13
MEDIUM 6.8
CVE-2014-9679
Integer underflow in the cupsRasterReadPixels function in filter/raster.c in CUPS before 2.0.2 allows remote attackers to have unspecified impact via…
Cups
after 2.0.1
MEDIUM 6.8
CVE-2015-1500EPSS 8%
Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to…
Server And Application Monitor
Patch available
MEDIUM 6.8
CVE-2015-1495
Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open metho…
Motorola Scanner Sdk
Patch available
HIGH 10.0
CVE-2014-8385
Buffer overflow on Advantech EKI-1200 gateways with firmware before 1.63 allows remote attackers to execute arbitrary code via unspecified vectors.
Eki 1200 Gateway Series Firmware
after 1.62
MEDIUM 5.0
CVE-2015-1548
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol stri…
Mini Httpd
after 1.21
MEDIUM 6.8
CVE-2014-9673
Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial o…
Ubuntu Linux
No fix yet
MEDIUM 5.8
CVE-2014-9672
Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bo…
Debian Linux
after 2.5.3
MEDIUM 6.8
CVE-2014-9667
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus…
Debian Linux
No fix yet
HIGH 7.5
CVE-2014-9668
The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, whi…
Fedora
after 2.5.3
HIGH 7.5
CVE-2014-9665
The Load_SBit_Png function in sfnt/pngshim.c in FreeType before 2.5.4 does not restrict the rows and pitch values of PNG data, which allows remote at…
Fedora
after 2.5.3
MEDIUM 6.8
CVE-2014-9664
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of servi…
Enterprise Linux Desktop
Patch available
HIGH 7.5
CVE-2014-9663EPSS 5%
The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely cal…
Debian Linux
Patch available
HIGH 7.5
CVE-2014-9662
cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a deni…
Debian Linux
after 2.5.3
HIGH 7.5
CVE-2014-9659EPSS 8%
cff/cf2intrp.c in the CFF CharString interpreter in FreeType before 2.5.4 proceeds with additional hints after the hint mask has been computed, which…
Fedora
after 2.5.3
HIGH 7.5
CVE-2014-9656
The tt_sbit_decoder_load_image function in sfnt/ttsbit.c in FreeType before 2.5.4 does not properly check for an integer overflow, which allows remot…
Fedora
after 2.5.3
MEDIUM 5.0
CVE-2014-9203
Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, …
12400 Level Transmitter Device Type Manager
Mitigation only
MEDIUM 5.0
CVE-2014-9636EPSS 12%
unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size s…
Ubuntu Linux
Patch available
HIGH 7.5
CVE-2015-1462
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upx packer file, related to a "heap out of bounds condition."
Fedora
after 0.98.5
HIGH 7.5
CVE-2015-1461
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted (1) Yoda's crypter or (2) mew packer file, related to a "heap o…
Fedora
after 0.98.5
HIGH 7.8
CVE-2015-1348
Heap-based buffer overflow in Aruba Instant (IAP) with firmware before 4.0.0.7 and 4.1.x before 4.1.1.2 allows remote attackers to cause a denial of …
Instant Access Point Firmware
after 4.0.0.6
HIGH 7.5
CVE-2014-9328
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
Fedora
after 0.98.5
HIGH 10.0
CVE-2015-1449
Buffer overflow in the integrated web server on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware b…
Ruggedcom Firmware
Mitigation only
HIGH 7.5
CVE-2014-9200EPSS 6%
Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modb…
Somachine
Mitigation only
HIGH 9.3
CVE-2014-9161
CoolType.dll in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows, and 10.x through 10.1.13 and 11.x through 11.0.10 on…
Acrobat Reader
No fix yet
MEDIUM 6.8
CVE-2014-8830
Heap-based buffer overflow in SceneKit in Apple OS X before 10.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (a…
Mac Os X
after 10.10.1
HIGH 7.5
CVE-2014-8829
SceneKit in Apple OS X before 10.10.2 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted app.
Mac Os X
after 10.10.1