Vulnerability index

Browse CVEs

2,665 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Heap-based Buffer OverflowCWE-122 × clear
CRITICAL 9.8 CVE-2018-14794 Fuji Electric Alpha5 Smart Loader Versions 3.7 and prior. The device does not perform a check on the length/size of a project file before copying the… Alpha5 Smart Loader Firmware after 3.7 Fix from $2,3002018-10-01 CRITICAL 9.8 CVE-2018-14813 Fuji Electric V-Server 4.0.3.0 and prior, A heap-based buffer overflow vulnerability has been identified, which may allow remote code execution. V Server Firmware after 4.0.3.0 Fix from $2,3002018-09-26 HIGH 8.8 CVE-2018-10606 WECON LeviStudio Versions 1.8.29 and 1.8.44 have multiple heap-based buffer overflow vulnerabilities that can be exploited when the application proce… Levistudiou Mitigation only Fix from $1,9502018-09-26 HIGH 7.5 CVE-2018-14821 Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally s… Rslinx after 4.00.01 Fix from $1,9502018-09-20 HIGH 8.8 CVE-2018-10893 Multiple integer overflow and buffer overflow issues were discovered in spice-client's handling of LZ compressed frames. A malicious server could cau… Spice Patch available Fix from $1,9502018-09-11 CRITICAL 9.8 CVE-2018-14618EPSS 11% curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multipl… Ubuntu Linux 7.61.1+ Fix from $2,3002018-09-05 HIGH 7.8 CVE-2016-8654 A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before… Debian Linux 2.0.0+ Fix from $1,9502018-08-01 HIGH 8.8 CVE-2016-9580 An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow. Openjpeg Patch available Fix from $1,9502018-08-01 HIGH 8.8 CVE-2016-9581 An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2. Openjpeg Patch available Fix from $1,9502018-08-01 CRITICAL 9.8 CVE-2016-8622 The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to … Libcurl 7.51.0+ Fix from $2,3002018-07-31 HIGH 8.8 CVE-2018-14290 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is requ… Foxit Reader after 9.1.0.5096 Fix from $1,9502018-07-31 CRITICAL 9.9 CVE-2016-9603 A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a V… Xenserver Mitigation only Fix from $2,3002018-07-27 HIGH 8.8 CVE-2016-9577 A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th… Debian Linux 0.13.90+ Fix from $1,9502018-07-27 HIGH 7.8 CVE-2018-1056 An out-of-bounds heap buffer read flaw was found in the way advancecomp before 2.1-2018/02 handled processing of ZIP files. An attacker could potenti… Ubuntu Linux 2.1+ Fix from $1,9502018-07-27 HIGH 7.8 CVE-2018-3857 An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the … Canvas Draw No fix yet Fix from $1,9502018-07-19 HIGH 7.8 CVE-2018-3858 An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the … Canvas Draw No fix yet Fix from $1,9502018-07-19 MEDIUM 6.6 CVE-2018-10840 Linux kernel is vulnerable to a heap-based buffer overflow in the fs/ext4/xattr.c:ext4_xattr_set_entry() function. An attacker could exploit this by … Linux Kernel Patch available Fix from $1,6002018-07-16 MEDIUM 5.3 CVE-2018-1120EPSS 7% A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line argu… Linux Kernel 4.17+ Fix from $1,6002018-06-20 CRITICAL 9.8 CVE-2018-10617 Delta Electronics Delta Industrial Automation DOPSoft version 4.00.04 and prior utilizes a fixed-length heap buffer where a value larger than the buf… Delta Industrial Automation Dopsoft after 4.00.04 Fix from $2,3002018-06-18 HIGH 8.8 CVE-2018-4833 A vulnerability has been identified in RFID 181EIP (All versions), RUGGEDCOM Win (V4.4, V4.5, V5.0, and V5.1), SCALANCE X-200 switch family (incl. SI… Rfid 181 Eip Firmware 5.2.3 / 5.4.1+ Fix from $1,9502018-06-14 CRITICAL 9.8 CVE-2018-8871 In Delta Electronics Automation TPEditor version 1.89 or prior, parsing a malformed program file may cause heap-based buffer overflow vulnerability, … Tpeditor 1.89+ Fix from $2,3002018-05-25 HIGH 7.5 CVE-2018-1123EPSS 9% procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection in ps maps a guard page at th… Ubuntu Linux 3.3.15+ Fix from $1,9502018-05-23 HIGH 7.8 CVE-2018-1124 procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privi… Ubuntu Linux 3.3.15 / 7.6.0+ Fix from $1,9502018-05-23 HIGH 8.8 CVE-2018-9974 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is requ… Foxit Reader after 9.0.1.1049 Fix from $1,9502018-05-17 HIGH 8.8 CVE-2018-9947 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is req… Foxit Reader after 9.0.1.1049 Fix from $1,9502018-05-17 HIGH 8.8 CVE-2018-9949 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is req… Foxit Reader after 9.0.1.1049 Fix from $1,9502018-05-17 HIGH 8.8 CVE-2018-10488 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is req… Foxit Reader after 9.0.1.1049 Fix from $1,9502018-05-17 CRITICAL 9.8 CVE-2018-8845EPSS 6% In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc… Webaccess 8.3.1+ Fix from $2,3002018-05-15 HIGH 7.5 CVE-2018-1089 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading … Enterprise Linux Desktop 1.3.6.15 / 1.4.0.9+ Fix from $1,9502018-05-09 HIGH 8.8 CVE-2018-7507 WPLSoft in Delta Electronics versions 2.45.0 and prior utilizes a fixed length heap buffer where a value larger than the buffer can be read from a fi… Wplsoft after 2.45.0 Fix from $1,9502018-05-04