Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Chrome HIGH 8.8
CVE-2017-15388

Iteration through non-finite points in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to perform an out of bounds memory read …

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Debian Linux HIGH 7.8
CVE-2018-6767EPSS 5%

A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-o…

Patch available
Fix from $1,950 2018-02-06
Debian Linux MEDIUM 6.5
CVE-2018-6621

The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) v…

Fix: after 3.2
Fix from $1,600 2018-02-05
Jhead MEDIUM 5.5
CVE-2018-6612

An integer underflow bug in the process_EXIF function of the exif.c file of jhead 3.00 raises a heap-based buffer over-read when processing a malicio…

Mitigation only
Fix from $1,600 2018-02-04
Libopenmpt HIGH 8.8
CVE-2018-6611

soundlib/Load_stp.cpp in OpenMPT through 1.27.04.00, and libopenmpt before 0.3.6, has an out-of-bounds read via a malformed STP file.

Fix: 0.3.6+
Fix from $1,950 2018-02-04
Linux Kernel MEDIUM 5.9
CVE-2017-16912

The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a de…

Fix: 4.1.49+
Fix from $1,600 2018-01-31
Libwebm HIGH 8.8
CVE-2018-6406

The function ParseVP9SuperFrameIndex in common/libwebm_util.cc in libwebm through 2018-01-30 does not validate the child_frame_length data obtained f…

Fix: after 2018-01-30
Fix from $1,950 2018-01-30
Debian Linux MEDIUM 6.5
CVE-2018-6392

The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array ac…

Fix: after 3.4.1
Fix from $1,600 2018-01-29
Debian Linux CRITICAL 9.8
CVE-2017-12377EPSS 10%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $2,300 2018-01-26
Debian Linux MEDIUM 5.5
CVE-2017-12378

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $1,600 2018-01-26
Debian Linux HIGH 8.8
CVE-2018-6315

The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds re…

Fix: after 0.4.8
Fix from $1,950 2018-01-25
Debian Linux CRITICAL 9.1
CVE-2018-1000005

libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pu…

Fix: after 7.57.0
Fix from $2,300 2018-01-24
Debian Linux MEDIUM 6.0
CVE-2018-5683

The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by…

Patch available
Fix from $1,600 2018-01-23
Ethereum Virtual Machine HIGH 8.2
CVE-2017-14457

An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ether…

Mitigation only
Fix from $1,950 2018-01-19
Readstat HIGH 7.8
CVE-2018-5698

libreadstat.a in WizardMac ReadStat 0.1.1 has a heap-based buffer over-read via an unterminated string.

No fix yet
Fix from $1,950 2018-01-14
Libtiff HIGH 8.8
CVE-2018-5360

LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/t…

Fix: 4.0.6+
Fix from $1,950 2018-01-14
Android HIGH 7.5
CVE-2017-9712

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, if userspace provides a too-large IE …

Patch available
Fix from $1,950 2018-01-10
Enterprise Linux Desktop HIGH 7.5
CVE-2018-4871

An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data …

Fix: after 28.0.0.126
Fix from $1,950 2018-01-09
Debian Linux HIGH 8.8
CVE-2018-5248

In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode fun…

No fix yet
Fix from $1,950 2018-01-05
Workstation HIGH 7.1
CVE-2017-4948

VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll…

Fix: 4.7+
Fix from $1,950 2018-01-05
Edge MEDIUM 5.3
CVE-2018-0780EPSS 51%

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further comp…

Fix: 1.7.6+
Fix from $1,600 2018-01-04
Chakracore MEDIUM 5.3
CVE-2018-0767EPSS 58%

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise…

Fix: 1.7.6+
Fix from $1,600 2018-01-04
Opencv HIGH 7.5
CVE-2017-18009

In OpenCV 3.3.1, a heap-based buffer over-read exists in the function cv::HdrDecoder::checkSignature in modules/imgcodecs/src/grfmt_hdr.cpp.

Mitigation only
Fix from $1,950 2018-01-01
Libtiff HIGH 8.8
CVE-2017-17942

In LibTIFF 4.0.9, there is a heap-based buffer over-read in the function PackBitsEncode in tif_packbits.c.

No fix yet
Fix from $1,950 2017-12-28
Debian Linux HIGH 8.8
CVE-2017-17912

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17913

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17915

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte bef…

Patch available
Fix from $1,950 2017-12-27
Wireshark HIGH 7.5
CVE-2017-17935

The File_read_line function in epan/wslua/wslua_file.c in Wireshark through 2.2.11 does not properly strip '\n' characters, which allows remote attac…

Fix: after 2.2.11
Fix from $1,950 2017-12-27
Ubuntu Linux HIGH 8.8
CVE-2017-17879

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a heap-based buffer over-read in ReadOneMNGImage in coders/png.c, related to length calculati…

Mitigation only
Fix from $1,950 2017-12-27
Imagemagick HIGH 8.8
CVE-2017-17880

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_…

Mitigation only
Fix from $1,950 2017-12-27