Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Icloud HIGH 7.8
CVE-2017-7013

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. iCloud before 6.2.2 on Windows is…

Fix: after 12.6.1
Fix from $1,950 2017-07-20
Ruby CRITICAL 9.8
CVE-2017-11465

The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have …

Patch available
Fix from $2,300 2017-07-19
Libmspack MEDIUM 5.5
CVE-2017-11423

The cabd_read_string function in mspack/cabd.c in libmspack 0.5alpha, as used in ClamAV 0.99.2 and other products, allows remote attackers to cause a…

Mitigation only
Fix from $1,600 2017-07-18
Ffmpeg HIGH 7.8
CVE-2017-11399

Integer overflow in the ape_decode_frame function in libavcodec/apedec.c in FFmpeg 2.4 through 3.3.2 allows remote attackers to cause a denial of ser…

Fix: after 3.3.2
Fix from $1,950 2017-07-17
Freeradius HIGH 7.5
CVE-2017-10982

An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.

Patch available
Fix from $1,950 2017-07-17
Freeradius HIGH 7.5
CVE-2017-10987

An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.

Mitigation only
Fix from $1,950 2017-07-17
Shoco HIGH 7.5
CVE-2017-11367

The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of service (buffer over-read and appli…

Fix: after 2017-07-17
Fix from $1,950 2017-07-17
Cairo HIGH 7.5
CVE-2017-9814

cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling …

Fix: after 1.15.6
Fix from $1,950 2017-07-17
Exiv2 MEDIUM 6.5
CVE-2017-11336

There is a heap-based buffer over-read in the Image::printIFDStructure function in image.cpp in Exiv2 0.26. A Crafted input will lead to a remote den…

Mitigation only
Fix from $1,600 2017-07-17
Libsass HIGH 7.5
CVE-2017-11341

There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

No fix yet
Fix from $1,950 2017-07-17
PHP CRITICAL 9.1
CVE-2017-11147

In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP in…

Fix: 5.6.30 / 7.0.15+
Fix from $2,300 2017-07-10
Mpg123 MEDIUM 5.5
CVE-2017-11126

The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and a…

Fix: after 1.25.1
Fix from $1,600 2017-07-10
Tcpdump HIGH 7.5
CVE-2017-11108

tcpdump 4.9.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packet data. The c…

Mitigation only
Fix from $1,950 2017-07-08
Imagemagick MEDIUM 5.5
CVE-2017-10995

The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read an…

Patch available
Fix from $1,600 2017-07-07
SQLite CRITICAL 9.8
CVE-2017-10989EPSS 8%

The getNodeSize function in ext/rtree/rtree.c in SQLite through 3.19.3, as used in GDAL and other products, mishandles undersized RTree blobs in a cr…

Fix: after 3.19.3
Fix from $2,300 2017-07-07
Swftools HIGH 7.5
CVE-2017-10976

When SWFTools 0.9.2 processes a crafted file in ttftool, it can lead to a heap-based buffer over-read in the readBlock() function in lib/ttf.c.

Mitigation only
Fix from $1,950 2017-07-06
Imagemagick HIGH 8.8
CVE-2017-10928

In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to obtain sensitive information…

No fix yet
Fix from $1,950 2017-07-05
Mpg123 HIGH 7.5
CVE-2017-10683

In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote den…

Mitigation only
Fix from $1,950 2017-06-29
Libsass HIGH 7.5
CVE-2017-10687

In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote d…

Mitigation only
Fix from $1,950 2017-06-29
Linux Kernel HIGH 7.8
CVE-2017-9984

The snd_msnd_interrupt function in sound/isa/msnd/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service …

Fix: 3.18.71 / 4.1.45+
Fix from $1,950 2017-06-28
Linux Kernel HIGH 7.8
CVE-2017-9985

The snd_msndmidi_input_read function in sound/isa/msnd/msnd_midi.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service…

Fix: 3.18.71 / 4.1.45+
Fix from $1,950 2017-06-28
Linux Kernel HIGH 7.8
CVE-2017-9986

The intr function in sound/oss/msnd_pinnacle.c in the Linux kernel through 4.11.7 allows local users to cause a denial of service (over-boundary acce…

Fix: after 4.11.7
Fix from $1,950 2017-06-28
Openvpn HIGH 7.4
CVE-2017-7520

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-mid…

Fix: after 2.3.16
Fix from $1,950 2017-06-27
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2017-9218

The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-27
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2017-9221

The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-27
Freeware Advanced Audio Decoder 2 MEDIUM 5.5
CVE-2017-9223

The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2017-06-27
Binutils MEDIUM 5.5
CVE-2017-9954

The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attack…

Patch available
Fix from $1,600 2017-06-26
Binutils MEDIUM 5.5
CVE-2017-9955

The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote at…

Patch available
Fix from $1,600 2017-06-26
Libtiff MEDIUM 6.5
CVE-2014-8127EPSS 7%

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesSt…

Mitigation only
Fix from $1,600 2017-06-26
Ubuntu Linux HIGH 8.8
CVE-2017-9935

In LibTIFF 4.0.8, there is a heap-based buffer overflow in the t2p_write_pdf function in tools/tiff2pdf.c. This heap overflow could lead to different…

Fix: after 4.0.8
Fix from $1,950 2017-06-26