Vulnerability index

Browse CVEs

2,665 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Alpha5 Smart Loader Firmware CRITICAL 9.8
CVE-2018-14794

Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the…

Fix: after 3.7
Fix from $2,300 2018-10-01
V Server Firmware CRITICAL 9.8
CVE-2018-14813

Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution.

Fix: after 4.0.3.0
Fix from $2,300 2018-09-26
Levistudiou HIGH 8.8
CVE-2018-10606

WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple heap-based buffer overflow vulnerabilities that can be exploited when the application proce…

Mitigation only
Fix from $1,950 2018-09-26
Rslinx HIGH 7.5
CVE-2018-14821

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally s…

Fix: after 4.00.01
Fix from $1,950 2018-09-20
Spice HIGH 8.8
CVE-2018-10893

Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cau…

Patch available
Fix from $1,950 2018-09-11
Ubuntu Linux CRITICAL 9.8
CVE-2018-14618EPSS 11%

curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multipl…

Fix: 7.61.1+
Fix from $2,300 2018-09-05
Debian Linux HIGH 7.8
CVE-2016-8654

A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before…

Fix: 2.0.0+
Fix from $1,950 2018-08-01
Openjpeg HIGH 8.8
CVE-2016-9580

An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.

Patch available
Fix from $1,950 2018-08-01
Openjpeg HIGH 8.8
CVE-2016-9581

An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.

Patch available
Fix from $1,950 2018-08-01
Libcurl CRITICAL 9.8
CVE-2016-8622

The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to …

Fix: 7.51.0+
Fix from $2,300 2018-07-31
Foxit Reader HIGH 8.8
CVE-2018-14290

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is requ…

Fix: after 9.1.0.5096
Fix from $1,950 2018-07-31
Xenserver CRITICAL 9.9
CVE-2016-9603

A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a V…

Mitigation only
Fix from $2,300 2018-07-27
Debian Linux HIGH 8.8
CVE-2016-9577

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Ubuntu Linux HIGH 7.8
CVE-2018-1056

An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potenti…

Fix: 2.1+
Fix from $1,950 2018-07-27
Canvas Draw HIGH 7.8
CVE-2018-3857

An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the …

No fix yet
Fix from $1,950 2018-07-19
Canvas Draw HIGH 7.8
CVE-2018-3858

An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the …

No fix yet
Fix from $1,950 2018-07-19
Linux Kernel MEDIUM 6.6
CVE-2018-10840

Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by …

Patch available
Fix from $1,600 2018-07-16
Linux Kernel MEDIUM 5.3
CVE-2018-1120EPSS 7%

A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line argu…

Fix: 4.17+
Fix from $1,600 2018-06-20
Delta Industrial Automation Dopsoft CRITICAL 9.8
CVE-2018-10617

Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buf…

Fix: after 4.00.04
Fix from $2,300 2018-06-18
Rfid 181 Eip Firmware HIGH 8.8
CVE-2018-4833

A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SI…

Fix: 5.2.3 / 5.4.1+
Fix from $1,950 2018-06-14
Tpeditor CRITICAL 9.8
CVE-2018-8871

In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, …

Fix: 1.89+
Fix from $2,300 2018-05-25
Ubuntu Linux HIGH 7.5
CVE-2018-1123EPSS 9%

procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at th…

Fix: 3.3.15+
Fix from $1,950 2018-05-23
Ubuntu Linux HIGH 7.8
CVE-2018-1124

procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privi…

Fix: 3.3.15 / 7.6.0+
Fix from $1,950 2018-05-23
Foxit Reader HIGH 8.8
CVE-2018-9974

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-17
Foxit Reader HIGH 8.8
CVE-2018-9947

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is req…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-17
Foxit Reader HIGH 8.8
CVE-2018-9949

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is req…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-17
Foxit Reader HIGH 8.8
CVE-2018-10488

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is req…

Fix: after 9.0.1.1049
Fix from $1,950 2018-05-17
Webaccess CRITICAL 9.8
CVE-2018-8845EPSS 6%

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Enterprise Linux Desktop HIGH 7.5
CVE-2018-1089

389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading …

Fix: 1.3.6.15 / 1.4.0.9+
Fix from $1,950 2018-05-09
Wplsoft HIGH 8.8
CVE-2018-7507

WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a fi…

Fix: after 2.45.0
Fix from $1,950 2018-05-04