Vulnerability index

Browse CVEs

2,665 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
Enterprise Linux HIGH 7.5
CVE-2017-2591

389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute …

Fix: 1.3.6+
Fix from $1,950 2018-04-30
Webaccess Hmi Designer HIGH 7.8
CVE-2018-8833

Heap-based buffer overflow vulnerabilities in Advantech WebAccess HMI Designer 2.1.7.32 and prior caused by processing specially crafted .pm3 files m…

Fix: after 2.1.7.32
Fix from $1,950 2018-04-25
Curl HIGH 8.1
CVE-2016-9586

curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() fu…

Fix: 7.52.0+
Fix from $1,950 2018-04-23
Cx Flnet HIGH 7.8
CVE-2018-8834

Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-P…

Fix: after 9.65
Fix from $1,950 2018-04-17
E Designer CRITICAL 9.8
CVE-2017-9636

Mitsubishi E-Designer, Version 7.52 Build 344 contains five code sections which may be exploited to overwrite the heap. This can result in arbitrary …

Mitigation only
Fix from $2,300 2018-04-17
Cx Supervisor MEDIUM 5.3
CVE-2018-7519

In Omron CX-Supervisor Versions 3.30 and prior, parsing malformed project files may cause a heap-based buffer overflow.

Fix: after 3.30
Fix from $1,600 2018-03-21
Smartos HIGH 7.0
CVE-2018-1165

This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An …

Mitigation only
Fix from $1,950 2018-02-21
Levistudio Hmi Editor Firmware HIGH 7.8
CVE-2017-16737

An issue was discovered in WECON Technology LEVI Studio HMI Editor v1.8.29 and prior. A specially-crafted malicious file may be able to cause a heap-…

Fix: after 1.8.29
Fix from $1,950 2018-01-12
Levi Studio Hmi HIGH 8.6
CVE-2017-16717

A Heap-based Buffer Overflow issue was discovered in WECON LeviStudio HMI. The heap-based buffer overflow vulnerability has been identified, which ma…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-13090EPSS 37%

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser …

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Webaccess HIGH 8.8
CVE-2017-12704

A heap-based buffer overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulner…

Fix: after 8.2
Fix from $1,950 2017-08-30
Augeas CRITICAL 9.8
CVE-2017-7555EPSS 5%

Augeas versions up to and including 1.8.0 are vulnerable to heap-based buffer overflow due to improper handling of escaped strings. Attacker could se…

Fix: after 1.8.0
Fix from $2,300 2017-08-17
Libxml2 HIGH 7.5
CVE-2017-9050

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability cau…

Patch available
Fix from $1,950 2017-05-18
Levi Studio Hmi Editor HIGH 8.8
CVE-2017-6037

A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulnerability causes a buffer overf…

Fix: after 1.8.0
Fix from $1,950 2017-04-27
Libtiff HIGH 8.8
CVE-2017-5225

LibTIFF version 4.0.7 is vulnerable to a heap buffer overflow in the tools/tiffcp resulting in DoS or code execution via a crafted BitsPerSample valu…

Patch available
Fix from $1,950 2017-01-12
Ubuntu Linux HIGH 7.8
CVE-2016-1834

Heap-based buffer overflow in the xmlStrncat function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.…

Patch available
Fix from $1,950 2016-05-20
Safari HIGH 8.1
CVE-2016-1762EPSS 6%

The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML…

Fix: 9.1+
Fix from $1,950 2016-03-24
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…

Fix: 11.2.202.468 / 13.0.0.296+
Fix from $2,300 2015-06-23
Mac Os X HIGH 8.8
CVE-2014-9495

Heap-based buffer overflow in the png_combine_row function in libpng before 1.5.21 and 1.6.x before 1.6.16, when running on 64-bit systems, might all…

Fix: after 10.11.3
Fix from $1,950 2015-01-10
Libpng MEDIUM 6.5
CVE-2013-7353

Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause …

Fix: after 1.5.13
Fix from $1,600 2014-05-06
Libpng MEDIUM 6.5
CVE-2013-7354

Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png…

Fix: after 1.5.13
Fix from $1,600 2014-05-06
Opc Factory Server Tlxcdlfofs HIGH 7.8
CVE-2014-0789

Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and…

Fix: after 3.35
Fix from $1,950 2014-04-04
Centum Cs 3000 HIGH 9.3
CVE-2014-0781EPSS 25%

Heap-based buffer overflow in BKCLogSvr.exe in Yokogawa CENTUM CS 3000 R3.09.50 and earlier allows remote attackers to execute arbitrary code via cra…

No fix yet
Fix from $1,950 2014-03-14
Vlc Media Player MEDIUM 6.3
CVE-2013-3245

plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service…

No fix yet
Fix from $1,600 2013-07-10
Acrobat HIGH 8.8
CVE-2009-3459 KEVEPSS 87%

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbi…

Fix: 7.1.4 / 8.1.7+
Fix from $1,950 2009-10-13