Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Bento4 MEDIUM 6.5
CVE-2017-14645

A heap-based buffer over-read was discovered in AP4_BitStream::ReadBytes in Codecs/Ap4BitStream.cpp in Bento4 version 1.5.0-617. The vulnerability ca…

Mitigation only
Fix from $1,600 2017-09-21
Bento4 HIGH 7.5
CVE-2017-14646

The AP4_AvccAtom and AP4_HvccAtom classes in Bento4 version 1.5.0-617 do not properly validate data sizes, leading to a heap-based buffer over-read a…

Patch available
Fix from $1,950 2017-09-21
Android MEDIUM 5.5
CVE-2017-11002

In all Qualcomm products with Android releases from CAF using the Linux kernel, while processing a vendor sub-command, a buffer over-read can occur.

Fix: after 8.0
Fix from $1,600 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14245

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14246

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14633

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…

Mitigation only
Fix from $1,600 2017-09-21
Ubuntu Linux HIGH 8.1
CVE-2017-14607

In ImageMagick 7.0.7-4 Q16, an out of bounds read flaw related to ReadTIFFImage has been reported in coders/tiff.c. An attacker could possibly exploi…

Patch available
Fix from $1,950 2017-09-20
Libraw CRITICAL 9.1
CVE-2017-14608

In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp…

Fix: after 0.18.4
Fix from $2,300 2017-09-20
Binutils MEDIUM 5.5
CVE-2017-14529

The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles H…

Patch available
Fix from $1,600 2017-09-18
Libarchive MEDIUM 6.5
CVE-2017-14501

An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted…

Mitigation only
Fix from $1,600 2017-09-17
Libarchive HIGH 7.5
CVE-2017-14502

read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an…

Patch available
Fix from $1,950 2017-09-17
Libarchive MEDIUM 6.5
CVE-2017-14503

libarchive 3.3.2 suffers from an out-of-bounds read within lha_read_data_none() in archive_read_support_format_lha.c when extracting a specially craf…

Mitigation only
Fix from $1,600 2017-09-17
Tcpdump CRITICAL 9.8
CVE-2017-13049

The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13050

The RPKI-Router parser in tcpdump before 4.9.2 has a buffer over-read in print-rpki-rtr.c:rpki_rtr_pdu_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13051

The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvp_obj_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13052

The CFM parser in tcpdump before 4.9.2 has a buffer over-read in print-cfm.c:cfm_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13053

The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decode_rt_routing_info().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13054

The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_private_8023_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13055

The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print_is_reach_subtlv().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13687

The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13688

The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13689

The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13690

The IKEv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13725

The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13022

The IP parser in tcpdump before 4.9.2 has a buffer over-read in print-ip.c:ip_printroute().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13023

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13024

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13025

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13026

The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-13027

The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldp_mgmt_addr_tlv_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14