Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 5.5
CVE-2017-8312

Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a craft…

Fix: 2.2.6+
Fix from $1,600 2017-05-23
Vlc Media Player MEDIUM 5.5
CVE-2017-8313

Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond alloc…

Fix: after 2.2.4
Fix from $1,600 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9193

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:538:33.

Mitigation only
Fix from $2,300 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9194

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29.

Mitigation only
Fix from $2,300 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9195

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:620:27.

Mitigation only
Fix from $2,300 2017-05-23
Imageworsener MEDIUM 6.5
CVE-2017-9204

The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2017-05-23
Imageworsener MEDIUM 6.5
CVE-2017-9205

The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2017-05-23
Imageworsener MEDIUM 6.5
CVE-2017-9206

The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2017-05-23
Imageworsener MEDIUM 6.5
CVE-2017-9207

The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9166

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:18:11.

Mitigation only
Fix from $2,300 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9171

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-bmp.c:492:24.

Mitigation only
Fix from $2,300 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9174

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9177

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9179

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9180

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9189

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLO…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9152

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the pnm_load_raw function in input-pnm.c:346:41.

Mitigation only
Fix from $2,300 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9154

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace HIGH 7.5
CVE-2017-9155

libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the input_pnm_reader func…

Mitigation only
Fix from $1,950 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9164

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:16:11.

Mitigation only
Fix from $2,300 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9165

libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:17:11.

Mitigation only
Fix from $2,300 2017-05-23
Libtiff MEDIUM 6.5
CVE-2017-9147EPSS 7%

LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash…

No fix yet
Fix from $1,600 2017-05-22
Linux Kernel HIGH 7.8
CVE-2017-9074

The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid o…

Fix: 3.2.89 / 3.16.44+
Fix from $1,950 2017-05-19
Libxml2 HIGH 7.5
CVE-2017-9049

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerabilit…

Patch available
Fix from $1,950 2017-05-18
Libxml2 HIGH 7.5
CVE-2017-9050

libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability cau…

Patch available
Fix from $1,950 2017-05-18
Libdwarf CRITICAL 9.8
CVE-2017-9052

An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure t…

Mitigation only
Fix from $2,300 2017-05-18
Libdwarf CRITICAL 9.1
CVE-2017-9053

An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a f…

Mitigation only
Fix from $2,300 2017-05-18
Libdwarf CRITICAL 9.8
CVE-2017-9054

An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just bef…

Mitigation only
Fix from $2,300 2017-05-18
Libdwarf CRITICAL 9.8
CVE-2017-9055

An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in boun…

Mitigation only
Fix from $2,300 2017-05-18
Ubuntu Linux CRITICAL 9.8
CVE-2017-9058

In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c.

Fix: after 1.9.2
Fix from $2,300 2017-05-18