Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Lame MEDIUM 5.5
CVE-2015-9099

The lame_init_params function in lame.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid read and applica…

Mitigation only
Fix from $1,600 2017-06-25
Lame MEDIUM 5.5
CVE-2017-9869

The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a deni…

No fix yet
Fix from $1,600 2017-06-25
Lame MEDIUM 5.5
CVE-2017-9870

The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2017-06-25
Debian Linux MEDIUM 5.5
CVE-2017-9865

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over…

Mitigation only
Fix from $1,600 2017-06-25
Libtorrent MEDIUM 5.5
CVE-2017-9847

The bdecode function in bdecode.cpp in libtorrent 1.1.3 allows remote attackers to cause a denial of service (heap-based buffer over-read and applica…

Patch available
Fix from $1,600 2017-06-24
Jasper MEDIUM 5.5
CVE-2017-9782

JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related t…

Patch available
Fix from $1,600 2017-06-21
Freeware Advanced Audio Coder MEDIUM 5.5
CVE-2017-9130

The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (invali…

No fix yet
Fix from $1,600 2017-06-21
HTTP Server HIGH 7.5
CVE-2017-7668EPSS 57%

The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to searc…

Patch available
Fix from $1,950 2017-06-20
Uclibc CRITICAL 9.8
CVE-2017-9728

In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression.

Mitigation only
Fix from $2,300 2017-06-16
Android HIGH 7.8
CVE-2017-7365

In all Android releases from CAF using the Linux kernel, a buffer overread can occur if a particular string is not NULL terminated.

Patch available
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2017-8234

In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.

Patch available
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2017-8240

In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.

Patch available
Fix from $1,950 2017-06-13
Libquicktime MEDIUM 6.5
CVE-2017-9123

The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (invalid memory read an…

No fix yet
Fix from $1,600 2017-06-12
Libquicktime MEDIUM 6.5
CVE-2017-9125

The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer over…

No fix yet
Fix from $1,600 2017-06-12
Libquicktime MEDIUM 6.5
CVE-2017-9128

The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer o…

No fix yet
Fix from $1,600 2017-06-12
Horizon View HIGH 7.8
CVE-2017-4910

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG200…

Mitigation only
Fix from $1,950 2017-06-08
Horizon View HIGH 7.8
CVE-2017-4912

VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueTyp…

Mitigation only
Fix from $1,950 2017-06-08
Ubuntu Linux MEDIUM 5.5
CVE-2017-9471

In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and applicatio…

No fix yet
Fix from $1,600 2017-06-07
Ytnef MEDIUM 5.5
CVE-2017-9472

In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and applicati…

No fix yet
Fix from $1,600 2017-06-07
Ytnef MEDIUM 5.5
CVE-2017-9474

In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and appli…

No fix yet
Fix from $1,600 2017-06-07
Yara HIGH 7.1
CVE-2017-9465

The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtai…

Patch available
Fix from $1,950 2017-06-06
Crypto\+\+ MEDIUM 5.3
CVE-2017-9434

Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.

Fix: after 5.6.4
Fix from $1,600 2017-06-05
Open Source HIGH 7.5
CVE-2017-9359

The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.1…

Mitigation only
Fix from $1,950 2017-06-02
Vlc Media Player HIGH 7.8
CVE-2017-9301

plugins\audio_filter\libmpgatofixed32_plugin.dll in VideoLAN VLC media player 2.2.4 allows remote attackers to cause a denial of service (invalid rea…

Fix: after 2.2.4
Fix from $1,950 2017-05-29
Openvswitch CRITICAL 9.8
CVE-2017-9264

In lib/conntrack.c in the firewall implementation in Open vSwitch (OvS) 2.6.1, there is a buffer over-read while parsing malformed TCP, UDP, and IPv6…

Patch available
Fix from $2,300 2017-05-29
Openvswitch CRITICAL 9.8
CVE-2017-9265

In Open vSwitch (OvS) v2.7.0, there is a buffer over-read while parsing the group mod OpenFlow message sent from the controller in `lib/ofp-util.c` i…

Patch available
Fix from $2,300 2017-05-29
PHP CRITICAL 9.8
CVE-2017-9224EPSS 7%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r…

Fix: 5.6.31 / 7.0.21+
Fix from $2,300 2017-05-24
PHP CRITICAL 9.8
CVE-2017-9227EPSS 6%

An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7.1.5. A stack out-of-bounds r…

Fix: 5.6.31 / 7.0.21+
Fix from $2,300 2017-05-24
Botan CRITICAL 9.8
CVE-2017-2801

A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certif…

No fix yet
Fix from $2,300 2017-05-24
Vlc Media Player MEDIUM 5.5
CVE-2017-8310

Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows attackers to read data beyond al…

Mitigation only
Fix from $1,600 2017-05-23