Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Linux Kernel HIGH 7.8
CVE-2017-6264

An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used a…

Patch available
Fix from $1,950 2017-11-14
Radare2 MEDIUM 5.5
CVE-2017-16805

In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, …

Patch available
Fix from $1,600 2017-11-13
Tcpdump MEDIUM 5.5
CVE-2017-16808EPSS 6%

tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.

No fix yet
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13817

An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Swftools MEDIUM 5.5
CVE-2017-16794

The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows rem…

Mitigation only
Fix from $1,600 2017-11-12
Linux Kernel MEDIUM 6.6
CVE-2017-16643

The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of se…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
Linux Kernel MEDIUM 6.6
CVE-2017-16645

The ims_pcu_get_cdc_union_desc function in drivers/input/misc/ims-pcu.c in the Linux kernel through 4.13.11 allows local users to cause a denial of s…

Fix: after 4.13.11
Fix from $1,600 2017-11-07
PHP HIGH 7.5
CVE-2017-16642EPSS 21%

In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back …

Fix: 5.6.32 / 7.0.25+
Fix from $1,950 2017-11-07
Mongoose HIGH 8.2
CVE-2017-2895

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT …

Mitigation only
Fix from $1,950 2017-11-07
Debian Linux HIGH 8.8
CVE-2017-15672

The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via …

Fix: after 3.3.4
Fix from $1,950 2017-11-06
Ubuntu Linux CRITICAL 9.8
CVE-2017-16548EPSS 5%

The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allo…

Fix: after 3.1.2
Fix from $2,300 2017-11-06
Linux Kernel MEDIUM 6.6
CVE-2017-16533

The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16535

The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (…

Fix: after 4.13.9
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16529

The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bou…

Fix: 3.2.95 / 3.16.50+
Fix from $1,600 2017-11-04
Linux Kernel MEDIUM 6.6
CVE-2017-16530

The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly ha…

Fix: 3.16.50 / 3.18.75+
Fix from $1,600 2017-11-04
Radare2 HIGH 7.8
CVE-2017-16358

In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.

Patch available
Fix from $1,950 2017-11-01
Debian Linux MEDIUM 6.5
CVE-2017-16353EPSS 11%

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…

No fix yet
Fix from $1,600 2017-11-01
Foxit Reader MEDIUM 6.5
CVE-2017-10942

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…

Patch available
Fix from $1,600 2017-10-31
Foxit Reader MEDIUM 6.5
CVE-2017-10943

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…

Patch available
Fix from $1,600 2017-10-31
Foxit Reader MEDIUM 6.5
CVE-2017-10944

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…

Patch available
Fix from $1,600 2017-10-31
Radare2 HIGH 7.8
CVE-2017-15931

In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/fo…

Patch available
Fix from $1,950 2017-10-27
Radare2 HIGH 7.8
CVE-2017-15932

In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/for…

Patch available
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5077

Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, …

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5088

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, …

Fix: 59.0.3071.104 / 59.0.3071.117+
Fix from $1,950 2017-10-27
Chrome CRITICAL 9.6
CVE-2017-5053

An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote atta…

Fix: 57.0.2987.132 / 57.0.2987.133+
Fix from $2,300 2017-10-27
Chrome HIGH 8.8
CVE-2017-5054

An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote atta…

Fix: 57.0.2987.132 / 57.0.2987.133+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5055

A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memo…

Fix: 57.0.2987.133+
Fix from $1,950 2017-10-27
Libextractor MEDIUM 5.5
CVE-2017-15922

In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.

No fix yet
Fix from $1,600 2017-10-26
Portable Runtime HIGH 7.1
CVE-2017-12613

When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, ou…

Fix: 1.7.0+
Fix from $1,950 2017-10-24
Irssi HIGH 7.5
CVE-2017-15228

Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.

Fix: after 1.0.4
Fix from $1,950 2017-10-22