Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Acrobat MEDIUM 6.5
CVE-2018-4886EPSS 6%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,600 2018-02-27
Acrobat MEDIUM 6.5
CVE-2018-4887EPSS 6%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,600 2018-02-27
Acrobat MEDIUM 6.5
CVE-2018-4889EPSS 6%

An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier …

Fix: after 18.009.20050
Fix from $1,600 2018-02-27
Ox MEDIUM 5.5
CVE-2017-16229

In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input…

No fix yet
Fix from $1,600 2018-02-26
Libcdio HIGH 8.8
CVE-2017-18198

print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or…

Fix: 1.0.0+
Fix from $1,950 2018-02-24
Xpdf MEDIUM 5.5
CVE-2018-7455

An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, a…

Mitigation only
Fix from $1,600 2018-02-24
Mdm9206 Firmware CRITICAL 9.8
CVE-2017-14910

In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 4…

Mitigation only
Fix from $2,300 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7435

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the freexl::destroy_cell function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7436

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a pointer dereference of the parse_SST function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7437

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7438

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7439

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 7.8
CVE-2018-7253EPSS 6%

The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buff…

Patch available
Fix from $1,950 2018-02-19
Debian Linux HIGH 7.8
CVE-2018-7254EPSS 16%

The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-…

Patch available
Fix from $1,950 2018-02-19
Debian Linux HIGH 7.5
CVE-2018-7051

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme str…

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Quidway S2700 Firmware HIGH 7.5
CVE-2017-17165

IPv6 function in Huawei Quidway S2700 V200R003C00SPC300, Quidway S5300 V200R003C00SPC300, Quidway S5700 V200R003C00SPC300, S2300 V200R003C00, V200R00…

Mitigation only
Fix from $1,950 2018-02-15
Ar120 S Firmware HIGH 7.5
CVE-2017-17202

Huawei AR120-S V200R005C32, V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R005C32, V200R006C10, V200R007C00, V200R007C01, V200R007C0…

Mitigation only
Fix from $1,950 2018-02-15
Dp300 Firmware MEDIUM 5.3
CVE-2017-17283

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00…

Mitigation only
Fix from $1,600 2018-02-15
Ar120 S Firmware MEDIUM 5.3
CVE-2017-15331

Huawei AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30, AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C2…

Mitigation only
Fix from $1,600 2018-02-15
Medfusion 4000 Wireless Syringe Infusion Pump MEDIUM 5.3
CVE-2017-12722

An Out-of-bounds Read issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version 1.1, 1.5, and 1.6. A third-party …

Mitigation only
Fix from $1,600 2018-02-15
Qpdf MEDIUM 5.5
CVE-2017-18184

An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.

Fix: 7.0.0+
Fix from $1,600 2018-02-13
Qpdf MEDIUM 5.5
CVE-2017-18185

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is …

Fix: 7.0.0+
Fix from $1,600 2018-02-13
Imagemagick MEDIUM 6.5
CVE-2018-6930

A stack-based buffer over-read in the ComputeResizeImage function in the MagickCore/accelerate.c file of ImageMagick 7.0.7-22 allows a remote attacke…

Mitigation only
Fix from $1,600 2018-02-13
Exiv2 HIGH 8.1
CVE-2017-17723

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::Image::byteSwap4 function in image.cpp. Remote attackers can exploit this vulnera…

No fix yet
Fix from $1,950 2018-02-12
Exiv2 MEDIUM 6.5
CVE-2017-17724

In Exiv2 0.26, there is a heap-based buffer over-read in the Exiv2::IptcData::printStructure function in iptc.cpp, related to the "!= 0x1c" case. Rem…

No fix yet
Fix from $1,600 2018-02-12
Carbon Black HIGH 7.5
CVE-2016-9570

cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application cr…

Mitigation only
Fix from $1,950 2018-02-12
Ffmpeg MEDIUM 6.5
CVE-2018-6912

The decode_plane function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read)…

Fix: after 3.4.2
Fix from $1,600 2018-02-12
Unzip CRITICAL 9.1
CVE-2018-1000033

An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.

Mitigation only
Fix from $2,300 2018-02-09
Unzip CRITICAL 9.1
CVE-2018-1000034

An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.

No fix yet
Fix from $2,300 2018-02-09
Binutils MEDIUM 5.5
CVE-2018-6872

The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote at…

Patch available
Fix from $1,600 2018-02-09