Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 5.9
CVE-2017-15722

In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.

Fix: after 1.0.4
Fix from $1,600 2017-10-22
Radare2 HIGH 7.8
CVE-2017-15368

The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-rea…

Patch available
Fix from $1,950 2017-10-16
Libxfont HIGH 7.1
CVE-2017-13720

In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cau…

Fix: after 1.5.2
Fix from $1,950 2017-10-11
Libxfont HIGH 7.1
CVE-2017-13722

In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could b…

Fix: after 1.5.2
Fix from $1,950 2017-10-11
Android HIGH 7.5
CVE-2017-9715

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a …

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-9717

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing Netlink attributes, a b…

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11052

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted …

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11054

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted …

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11055

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted …

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11060

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during …

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11061

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing cfg80211 vendor sub …

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11062

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently attributes are not validate…

Mitigation only
Fix from $1,950 2017-10-10
Android HIGH 7.5
CVE-2017-11064

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during …

Mitigation only
Fix from $1,950 2017-10-10
Lame MEDIUM 5.5
CVE-2017-15045

LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, rel…

No fix yet
Fix from $1,600 2017-10-06
FreeBSD HIGH 8.1
CVE-2017-15037

In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can …

Fix: after 11.1
Fix from $1,950 2017-10-05
Lame MEDIUM 5.5
CVE-2017-15018

LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_…

No fix yet
Fix from $1,600 2017-10-05
Binutils HIGH 7.8
CVE-2017-15020

dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles pointers, which allows remote atta…

Patch available
Fix from $1,950 2017-10-05
Binutils MEDIUM 5.5
CVE-2017-15021

bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote at…

Patch available
Fix from $1,600 2017-10-05
Android HIGH 7.8
CVE-2017-0812

An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A…

Patch available
Fix from $1,950 2017-10-04
Debian Linux HIGH 7.5
CVE-2017-14976

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font d…

Patch available
Fix from $1,950 2017-10-02
Openexif MEDIUM 5.5
CVE-2017-14931

ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read …

Mitigation only
Fix from $1,600 2017-09-30
Binutils MEDIUM 5.5
CVE-2017-14939EPSS 11%

decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calcu…

Patch available
Fix from $1,600 2017-09-30
Exiv2 MEDIUM 5.5
CVE-2017-14860

There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a de…

No fix yet
Fix from $1,600 2017-09-29
Libbpg HIGH 8.8
CVE-2017-14795

The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application cr…

No fix yet
Fix from $1,950 2017-09-28
Libofx MEDIUM 6.5
CVE-2017-14731

ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application c…

Patch available
Fix from $1,600 2017-09-25
Debian Linux MEDIUM 6.5
CVE-2017-14733

ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2017-09-25
Linux Kernel MEDIUM 6.5
CVE-2015-5327

Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after.

Patch available
Fix from $1,600 2017-09-25
Visibroker CRITICAL 9.8
CVE-2017-9283

An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further atta…

No fix yet
Fix from $2,300 2017-09-21
Libexif CRITICAL 9.1
CVE-2017-7544

libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by …

Fix: after 0.6.21
Fix from $2,300 2017-09-21
Bento4 MEDIUM 6.5
CVE-2017-14643

The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over…

Patch available
Fix from $1,600 2017-09-21