Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Imagemagick MEDIUM 6.5
CVE-2017-13134

In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attac…

Patch available
Fix from $1,600 2017-08-23
Binutils MEDIUM 6.5
CVE-2017-12967

The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attacker…

Patch available
Fix from $1,600 2017-08-19
Exiv2 MEDIUM 6.5
CVE-2017-12956

There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of se…

Mitigation only
Fix from $1,600 2017-08-18
Exiv2 MEDIUM 6.5
CVE-2017-12957

There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to rem…

Mitigation only
Fix from $1,600 2017-08-18
Pspp HIGH 7.5
CVE-2017-12958

There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to …

Mitigation only
Fix from $1,950 2017-08-18
Libsass HIGH 7.5
CVE-2017-12963

There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this i…

Mitigation only
Fix from $1,950 2017-08-18
Android HIGH 7.8
CVE-2017-8256

In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 …

Patch available
Fix from $1,950 2017-08-18
Android HIGH 7.8
CVE-2017-8268

In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer proc…

Mitigation only
Fix from $1,950 2017-08-18
Android CRITICAL 9.8
CVE-2015-9050

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access can occur …

No fix yet
Fix from $2,300 2017-08-18
Unrar CRITICAL 9.8
CVE-2017-12940

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.

Fix: after 5.5.6
Fix from $2,300 2017-08-18
Unrar CRITICAL 9.8
CVE-2017-12941

libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function.

Fix: after 5.5.6
Fix from $2,300 2017-08-18
Resiprocate HIGH 7.5
CVE-2017-9454

Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denia…

Fix: after 1.10.2
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12935

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColo…

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12937

The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.

Patch available
Fix from $1,950 2017-08-18
PHP CRITICAL 9.8
CVE-2017-12933EPSS 6%

The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a b…

Fix: after 5.6.30
Fix from $2,300 2017-08-18
Wildmidi HIGH 7.5
CVE-2017-11661EPSS 9%

The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) v…

No fix yet
Fix from $1,950 2017-08-17
Wildmidi HIGH 7.5
CVE-2017-11662EPSS 8%

The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted m…

No fix yet
Fix from $1,950 2017-08-17
Wildmidi MEDIUM 6.5
CVE-2017-11663EPSS 5%

The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) v…

No fix yet
Fix from $1,600 2017-08-17
Wildmidi MEDIUM 6.5
CVE-2017-11664EPSS 8%

The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) v…

Patch available
Fix from $1,600 2017-08-17
Minidjvu MEDIUM 6.5
CVE-2017-12441

The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a craft…

Mitigation only
Fix from $1,600 2017-08-17
Minidjvu MEDIUM 6.5
CVE-2017-12442

The row_is_empty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a craft…

Mitigation only
Fix from $1,600 2017-08-17
Minidjvu MEDIUM 6.5
CVE-2017-12443

The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a …

Mitigation only
Fix from $1,600 2017-08-17
Minidjvu MEDIUM 6.5
CVE-2017-12444

The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash…

Mitigation only
Fix from $1,600 2017-08-17
Minidjvu MEDIUM 6.5
CVE-2017-12445

The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and applic…

Mitigation only
Fix from $1,600 2017-08-17
Android MEDIUM 5.5
CVE-2017-8258

An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.

Patch available
Fix from $1,600 2017-08-11
Android MEDIUM 5.5
CVE-2017-0725

A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.

Patch available
Fix from $1,600 2017-08-09
Debian Linux HIGH 8.8
CVE-2017-12640

ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.

Patch available
Fix from $1,950 2017-08-07
Clamav MEDIUM 5.5
CVE-2017-6418

libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message.

Patch available
Fix from $1,600 2017-08-07
Openexr HIGH 7.8
CVE-2017-12596

In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; …

No fix yet
Fix from $1,950 2017-08-07
Debian Linux HIGH 8.8
CVE-2017-12598

OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcod…

Fix: after 3.3.0
Fix from $1,950 2017-08-07