Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Ffmpeg HIGH 7.8
CVE-2017-11719

The dnxhd_decode_header function in libavcodec/dnxhddec.c in FFmpeg 3.0 through 3.3.2 allows remote attackers to cause a denial of service (out-of-ar…

Fix: after 3.3.2
Fix from $1,950 2017-07-28
Soundtouch MEDIUM 5.5
CVE-2017-9260EPSS 6%

The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of serv…

No fix yet
Fix from $1,600 2017-07-27
Mpg123 MEDIUM 5.5
CVE-2017-9545

The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted …

No fix yet
Fix from $1,600 2017-07-27
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9610

The xps_load_sfnt_name function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-base…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9611

The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9620

The xps_select_font_encoding function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (hea…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9726

The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

Mitigation only
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9727

The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-base…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9739

The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

No fix yet
Fix from $1,950 2017-07-26
Ghostscript Ghostxps HIGH 7.8
CVE-2017-9740

The xps_decode_font_char_imp function in xps/xpsfont.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (hea…

No fix yet
Fix from $1,950 2017-07-26
Sipcrack MEDIUM 5.9
CVE-2017-11654

An out-of-bounds read and write flaw was found in the way SIPcrack 0.2 processed SIP traffic, because 0x00 termination of a payload array was mishand…

No fix yet
Fix from $1,600 2017-07-26
Imagemagick MEDIUM 6.5
CVE-2017-11639

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/…

Patch available
Fix from $1,600 2017-07-26
Debian Linux MEDIUM 5.5
CVE-2017-11434

The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read a…

Fix: after 2.9.1
Fix from $1,600 2017-07-25
Libsass MEDIUM 6.5
CVE-2017-11608

There is a heap-based buffer over-read in the Sass::Prelexer::re_linebreak function in lexer.cpp in LibSass 3.4.5. A crafted input will lead to a rem…

Mitigation only
Fix from $1,600 2017-07-24
Linux Kernel HIGH 7.0
CVE-2017-11600

net/xfrm/xfrm_policy.c in the Linux kernel through 4.12.3, when CONFIG_XFRM_MIGRATE is enabled, does not ensure that the dir value of xfrm_userpolicy…

Fix: 3.2.93 / 3.10.108+
Fix from $1,950 2017-07-24
Libsass MEDIUM 6.5
CVE-2017-11605

There is a heap based buffer over-read in LibSass 3.4.5, related to address 0xb4803ea1. A crafted input will lead to a remote denial of service attac…

Mitigation only
Fix from $1,600 2017-07-24
Fontforge HIGH 7.8
CVE-2017-11568

FontForge 20161012 is vulnerable to a heap-based buffer over-read in PSCharStringToSplines (psread.c) resulting in DoS or code execution via a crafte…

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11569

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readttfcopyrights (parsettf.c) resulting in DoS or code execution via a crafted …

Mitigation only
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11570

FontForge 20161012 is vulnerable to a buffer over-read in umodenc (parsettf.c) resulting in DoS or code execution via a crafted otf file.

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11572

FontForge 20161012 is vulnerable to a heap-based buffer over-read in readcfftopdicts (parsettf.c) resulting in DoS or code execution via a crafted ot…

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11573

FontForge 20161012 is vulnerable to a buffer over-read in ValidatePostScriptFontName (parsettf.c) resulting in DoS or code execution via a crafted ot…

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11575

FontForge 20161012 is vulnerable to a buffer over-read in strnmatch (char.c) resulting in DoS or code execution via a crafted otf file, related to a …

Patch available
Fix from $1,950 2017-07-23
Fontforge HIGH 7.8
CVE-2017-11577

FontForge 20161012 is vulnerable to a buffer over-read in getsid (parsettf.c) resulting in DoS or code execution via a crafted otf file.

Patch available
Fix from $1,950 2017-07-23
Imagemagick MEDIUM 6.5
CVE-2017-11533

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/…

Patch available
Fix from $1,600 2017-07-23
Imagemagick MEDIUM 6.5
CVE-2017-11535

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WritePSImage() function in coders/p…

Patch available
Fix from $1,600 2017-07-23
Imagemagick MEDIUM 6.5
CVE-2017-11540

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the GetPixelIndex() function, called fr…

Patch available
Fix from $1,600 2017-07-23
Tcpdump CRITICAL 9.8
CVE-2017-11541

tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c.

No fix yet
Fix from $2,300 2017-07-23
Tcpdump CRITICAL 9.8
CVE-2017-11542

tcpdump 4.9.0 has a heap-based buffer over-read in the pimv1_print function in print-pim.c.

No fix yet
Fix from $2,300 2017-07-23
Mac Os X MEDIUM 5.5
CVE-2017-7036

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It all…

Fix: after 10.12.5
Fix from $1,600 2017-07-20
Icloud HIGH 7.8
CVE-2017-7010

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. iCloud before 6.2.2 on Windows is…

Fix: after 12.6.1
Fix from $1,950 2017-07-20