Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Leap HIGH 7.5
CVE-2017-5335EPSS 8%

The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of …

Fix: after 3.3.25
Fix from $1,950 2017-03-24
Pcre MEDIUM 5.5
CVE-2017-7244

The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via …

Mitigation only
Fix from $1,600 2017-03-23
Libdwarf HIGH 7.5
CVE-2016-9276

The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bound…

Fix: 2016-11-24+
Fix from $1,950 2017-03-23
Samsung Mobile CRITICAL 9.8
CVE-2017-5538

The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos …

Patch available
Fix from $2,300 2017-03-23
Linux Kernel CRITICAL 9.8
CVE-2017-5897

The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via vectors involving GRE flags …

Fix: 3.10.106 / 3.12.71+
Fix from $2,300 2017-03-23
Binutils CRITICAL 9.1
CVE-2017-7226

The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-b…

Patch available
Fix from $2,300 2017-03-22
Libav HIGH 7.1
CVE-2017-7206

The ff_h2645_extract_rbsp function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (heap-based buffer over-read) or …

Mitigation only
Fix from $1,950 2017-03-21
Libav HIGH 7.1
CVE-2017-7208

The decode_residual function in libavcodec in libav 9.21 allows remote attackers to cause a denial of service (buffer over-read) or obtain sensitive …

Mitigation only
Fix from $1,950 2017-03-21
Virglrenderer MEDIUM 5.5
CVE-2017-5956

The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QE…

Fix: after 0.5.0
Fix from $1,600 2017-03-20
Audiofile MEDIUM 5.5
CVE-2017-6829

The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a c…

Patch available
Fix from $1,600 2017-03-20
Glibc MEDIUM 5.9
CVE-2015-8984

The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (appl…

Fix: after 2.21
Fix from $1,600 2017-03-20
Ubuntu Linux MEDIUM 5.5
CVE-2014-9844

The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a craf…

Patch available
Fix from $1,600 2017-03-20
Binutils CRITICAL 9.1
CVE-2017-6969

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger pro…

No fix yet
Fix from $2,300 2017-03-17
Debian Linux MEDIUM 6.5
CVE-2017-5667

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial …

Fix: after 2.8.1.1
Fix from $1,600 2017-03-16
Imagemagick MEDIUM 5.5
CVE-2015-8897

The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application cr…

Fix: after 6.9.2-3
Fix from $1,600 2017-03-15
Fedora MEDIUM 5.5
CVE-2017-5849

tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service…

No fix yet
Fix from $1,600 2017-03-15
Ettercap MEDIUM 5.5
CVE-2017-6430

The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of serv…

Fix: after 0.8.2
Fix from $1,600 2017-03-15
Debian Linux CRITICAL 9.8
CVE-2016-10195EPSS 7%

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_l…

Fix: after 2.1.5
Fix from $2,300 2017-03-15
Debian Linux HIGH 7.5
CVE-2016-10197EPSS 5%

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty…

Fix: after 2.1.5
Fix from $1,950 2017-03-15
Libplist MEDIUM 5.0
CVE-2017-6437

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a cr…

No fix yet
Fix from $1,600 2017-03-15
Podofo MEDIUM 5.5
CVE-2017-6840

The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (invalid read) …

Mitigation only
Fix from $1,600 2017-03-15
Jasper MEDIUM 5.5
CVE-2017-6851

The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.

Fix: after 2.0.9
Fix from $1,600 2017-03-15
Libgd MEDIUM 5.5
CVE-2016-6906

The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out…

Fix: after 2.2.3
Fix from $1,600 2017-03-15
Wavpack MEDIUM 5.5
CVE-2016-10169

The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafte…

Fix: after 5.0.0
Fix from $1,600 2017-03-14
Wavpack MEDIUM 5.5
CVE-2016-10170

The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a cr…

Fix: after 5.0.0
Fix from $1,600 2017-03-14
Wavpack MEDIUM 5.5
CVE-2016-10171

The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) v…

Fix: after 5.0.0
Fix from $1,600 2017-03-14
Wavpack MEDIUM 5.5
CVE-2016-10172

The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) v…

Fix: after 5.0.0
Fix from $1,600 2017-03-14
Graphicsmagick MEDIUM 5.5
CVE-2017-6335

The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-b…

Fix: after 1.3.25
Fix from $1,600 2017-03-14
Popup HIGH 7.5
CVE-2017-2786

A denial of service vulnerability exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can …

Mitigation only
Fix from $1,950 2017-03-10
Debian Linux HIGH 7.5
CVE-2017-6800

An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, r…

Fix: after 1.9.1
Fix from $1,950 2017-03-10