Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 6.5
CVE-2018-8976

In Exiv2 0.26, jpgimage.cpp allows remote attackers to cause a denial of service (image.cpp Exiv2::Internal::stringFormat out-of-bounds read) via a c…

Patch available
Fix from $1,600 2018-03-25
Ubuntu Linux HIGH 8.8
CVE-2018-8960

The ReadTIFFImage function in coders/tiff.c in ImageMagick 7.0.7-26 Q16 does not properly restrict memory allocation, leading to a heap-based buffer …

No fix yet
Fix from $1,950 2018-03-23
Libav MEDIUM 6.5
CVE-2017-18245

The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a …

Mitigation only
Fix from $1,600 2018-03-23
Libav MEDIUM 6.5
CVE-2017-18246

The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-based buffer over-read) vi…

Mitigation only
Fix from $1,600 2018-03-23
Libav MEDIUM 6.5
CVE-2017-18242

The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) …

Mitigation only
Fix from $1,600 2018-03-22
Libav MEDIUM 6.5
CVE-2017-18244

The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a cr…

Mitigation only
Fix from $1,600 2018-03-22
Ubuntu Linux HIGH 7.3
CVE-2018-8881

Netwide Assembler (NASM) 2.13.02rc2 has a heap-based buffer over-read in the function tokenize in asm/preproc.c, related to an unterminated string.

Mitigation only
Fix from $1,950 2018-03-20
Netwide Assembler HIGH 7.8
CVE-2018-8883

Netwide Assembler (NASM) 2.13.02rc2 has a buffer over-read in the parse_line function in asm/parser.c via uncontrolled access to nasm_reg_flags.

Mitigation only
Fix from $1,950 2018-03-20
Maradns MEDIUM 5.9
CVE-2014-2031

Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of se…

Fix: 1.4.14 / 2.0.09+
Fix from $1,600 2018-03-20
Maradns MEDIUM 5.9
CVE-2014-2032

Deadwood before 2.3.09, 3.x before 3.2.05, and as used in MaraDNS before 1.4.14 and 2.x before 2.0.09, allow remote attackers to cause a denial of se…

Fix: 1.4.14 / 2.0.09+
Fix from $1,600 2018-03-20
Vns L21 Firmware MEDIUM 5.5
CVE-2017-17306

Some Huawei Smartphones with software of VNS-L21AUTC555B141, VNS-L21C10B160, VNS-L21C66B160, VNS-L21C703B140 have an array out-of-bounds read vulnera…

Mitigation only
Fix from $1,600 2018-03-20
Vns L21 Firmware MEDIUM 5.5
CVE-2017-17307

Some Huawei Smartphones with software of VNS-L21AUTC555B141 have an out-of-bounds read vulnerability. Due to the lack string terminator of string, an…

Mitigation only
Fix from $1,600 2018-03-20
Radare2 MEDIUM 5.5
CVE-2018-8808

In radare2 2.4.0, there is a heap-based buffer over-read in the r_asm_disassemble function of asm.c. Remote attackers could leverage this vulnerabili…

No fix yet
Fix from $1,600 2018-03-20
Radare2 MEDIUM 5.5
CVE-2018-8809

In radare2 2.4.0, there is a heap-based buffer over-read in the dalvik_op function of anal_dalvik.c. Remote attackers could leverage this vulnerabili…

No fix yet
Fix from $1,600 2018-03-20
Radare2 MEDIUM 5.5
CVE-2018-8810

In radare2 2.4.0, there is a heap-based buffer over-read in the get_ivar_list_t function of mach0_classes.c. Remote attackers could leverage this vul…

No fix yet
Fix from $1,600 2018-03-20
Elfutils HIGH 7.8
CVE-2018-8769

elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.

Patch available
Fix from $1,950 2018-03-18
Debian Linux MEDIUM 5.5
CVE-2018-8754

The libevt_record_values_read_event() function in libevt_record_values.c in libevt before 2018-03-17 does not properly check for out-of-bounds values…

Fix: 20180317+
Fix from $1,600 2018-03-18
Android HIGH 7.5
CVE-2017-18057

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.5
CVE-2017-18058

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for wow_buf…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.5
CVE-2017-18059

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev id…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.5
CVE-2017-18060

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for resp_ev…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.8
CVE-2017-18050

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_ma…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.5
CVE-2017-18051

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for event->…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.5
CVE-2017-18052

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for cmpl_pa…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.5
CVE-2017-18053

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for fix_par…

Patch available
Fix from $1,950 2018-03-16
Android HIGH 7.8
CVE-2017-18056

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper input validation for vdev_id…

Mitigation only
Fix from $1,950 2018-03-15
Android HIGH 7.5
CVE-2017-18069

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, improper message length calculation i…

Mitigation only
Fix from $1,950 2018-03-15
Debian Linux CRITICAL 9.1
CVE-2018-1000122EPSS 8%

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of serv…

Fix: 7.2+
Fix from $2,300 2018-03-14
Xpdf MEDIUM 5.5
CVE-2018-8101

The JPXStream::inverseTransformLevel function in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service (heap-based buffer over-read …

Mitigation only
Fix from $1,600 2018-03-14
Xpdf MEDIUM 5.5
CVE-2018-8102

The JBIG2MMRDecoder::getBlackCode function in JBIG2Stream.cc in xpdf 4.00 allows attackers to launch denial of service (buffer over-read and applicat…

Mitigation only
Fix from $1,600 2018-03-14