Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Tcpdump CRITICAL 9.8
CVE-2017-12992

The RIPng parser in tcpdump before 4.9.2 has a buffer over-read in print-ripng.c:ripng_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12993

The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12994

The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgp_attr_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12995

The DNS parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-domain.c:ns_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12996

The PIMv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c:pimv2_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Tcpdump CRITICAL 9.8
CVE-2017-12997

The LLDP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-lldp.c:lldp_private_8021_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Mp3gain MEDIUM 5.5
CVE-2017-14407

A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2. The vulnerability causes an application cras…

Mitigation only
Fix from $1,600 2017-09-13
Mp3gain MEDIUM 5.5
CVE-2017-14408

A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an applic…

Mitigation only
Fix from $1,600 2017-09-13
Mp3gain MEDIUM 5.5
CVE-2017-14410

A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application…

Mitigation only
Fix from $1,600 2017-09-13
Xen HIGH 8.8
CVE-2017-14316

A parameter verification issue was discovered in Xen through 4.9.x. The function `alloc_heap_pages` allows callers to specify the first NUMA node tha…

Fix: after 4.9.0
Fix from $1,950 2017-09-12
Debian Linux MEDIUM 6.5
CVE-2017-14314

Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDash…

Patch available
Fix from $1,600 2017-09-12
Imagemagick MEDIUM 6.5
CVE-2017-14248

A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service…

Patch available
Fix from $1,600 2017-09-11
Libreoffice HIGH 7.5
CVE-2017-14226

WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause…

Fix: after 5.3.6
Fix from $1,950 2017-09-09
MongoDB HIGH 7.5
CVE-2017-14227

In MongoDB libbson 1.7.0, the bson_iter_codewscope function in bson-iter.c miscalculates a bson_utf8_validate length argument, which allows remote at…

Mitigation only
Fix from $1,950 2017-09-09
Debian Linux MEDIUM 6.5
CVE-2017-14166

libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar …

Patch available
Fix from $1,600 2017-09-06
Binutils MEDIUM 5.5
CVE-2017-14128

The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remot…

Patch available
Fix from $1,600 2017-09-04
Binutils MEDIUM 5.5
CVE-2017-14129

The read_section function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote at…

Patch available
Fix from $1,600 2017-09-04
Binutils MEDIUM 5.5
CVE-2017-14130

The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, …

Patch available
Fix from $1,600 2017-09-04
Debian Linux MEDIUM 6.5
CVE-2017-14132

JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.90…

Patch available
Fix from $1,600 2017-09-04
Debian Linux CRITICAL 9.1
CVE-2017-14122

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.

Mitigation only
Fix from $2,300 2017-09-03
Debian Linux MEDIUM 5.5
CVE-2017-13672

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out…

Fix: after 2.10.2
Fix from $1,600 2017-09-01
Wireshark HIGH 7.5
CVE-2017-13765

In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the IrCOMM dissector has a buffer over-read and application crash. This was addressed in plu…

Fix: after 2.2.8
Fix from $1,950 2017-08-30
Ubuntu Linux MEDIUM 6.5
CVE-2017-13769

The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-r…

Fix: 6.9.9-11+
Fix from $1,600 2017-08-30
Binutils MEDIUM 5.5
CVE-2017-13757

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remo…

Patch available
Fix from $1,600 2017-08-29
Debian Linux MEDIUM 5.5
CVE-2017-13755

In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libt…

Patch available
Fix from $1,600 2017-08-29
Liblouis HIGH 8.8
CVE-2017-13738

There is an illegal address access in the _lou_getALine function in compileTranslationTable.c:346 in Liblouis 3.2.0.

Mitigation only
Fix from $1,950 2017-08-29
Liblouis MEDIUM 6.5
CVE-2017-13744

There is an illegal address access in the function _lou_getALine() in compileTranslationTable.c:343 in Liblouis 3.2.0.

Mitigation only
Fix from $1,600 2017-08-29
Libgig MEDIUM 6.5
CVE-2017-12951

The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (stack-based b…

No fix yet
Fix from $1,600 2017-08-28
Libgig MEDIUM 6.5
CVE-2017-12954

The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (invalid memory read …

No fix yet
Fix from $1,600 2017-08-28
Debian Linux CRITICAL 9.8
CVE-2017-13139

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.

Fix: after 6.9.9-0
Fix from $2,300 2017-08-23