Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 7.5
CVE-2017-6801

An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.

Fix: after 1.9.1
Fix from $1,950 2017-03-10
Debian Linux HIGH 7.5
CVE-2017-6802

An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to Decomp…

Fix: after 1.9.1
Fix from $1,950 2017-03-10
Debian Linux MEDIUM 5.5
CVE-2016-5315

The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a c…

Fix: after 4.0.6
Fix from $1,600 2017-03-07
Debian Linux HIGH 7.8
CVE-2016-10244EPSS 5%

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote atta…

Fix: 2.7.1+
Fix from $1,950 2017-03-06
Debian Linux MEDIUM 5.5
CVE-2017-6500

An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.

Patch available
Fix from $1,600 2017-03-06
Imagemagick MEDIUM 5.5
CVE-2016-10070

Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of serv…

Fix: after 6.9.3-10
Fix from $1,600 2017-03-03
Matrixssl MEDIUM 6.5
CVE-2016-6884

TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read)…

Fix: after 3.8.2
Fix from $1,600 2017-03-03
Fedora HIGH 7.5
CVE-2016-7969

The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via u…

Fix: after 0.13.3
Fix from $1,950 2017-03-03
Libplist MEDIUM 5.5
CVE-2017-5834

The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted …

Patch available
Fix from $1,600 2017-03-03
Irssi HIGH 7.5
CVE-2017-5195EPSS 5%

Irssi 0.8.17 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ANSI x8 color code.

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Irssi HIGH 7.5
CVE-2017-5196

Irssi 0.8.18 before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via vectors involving strings that are…

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Debian Linux HIGH 7.5
CVE-2017-5356

Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence…

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Imagemagick MEDIUM 5.5
CVE-2016-10071

coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a craf…

Fix: after 6.9.3-10
Fix from $1,600 2017-03-02
Radare2 MEDIUM 5.5
CVE-2017-6387

The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and appli…

Patch available
Fix from $1,600 2017-03-02
Linux Kernel HIGH 7.8
CVE-2017-6347

The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, whic…

Fix: 4.4.52 / 4.9.13+
Fix from $1,950 2017-03-01
Zziplib MEDIUM 5.5
CVE-2017-5977

The zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (invalid memory read and…

No fix yet
Fix from $1,600 2017-03-01
Zziplib MEDIUM 5.5
CVE-2017-5978

The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read and crash) v…

No fix yet
Fix from $1,600 2017-03-01
Jasper MEDIUM 5.5
CVE-2017-5504

The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and…

No fix yet
Fix from $1,600 2017-03-01
Argus HIGH 7.8
CVE-2016-8388

An exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will explicit…

No fix yet
Fix from $1,950 2017-02-28
Qemu MEDIUM 5.5
CVE-2016-10028

The virgl_cmd_get_capset function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows loc…

Fix: after 2.8.1.1
Fix from $1,600 2017-02-27
Qemu MEDIUM 5.5
CVE-2016-10029

The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a…

Fix: after 2.6.2
Fix from $1,600 2017-02-27
Libiberty MEDIUM 5.5
CVE-2016-4493

The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of serv…

Patch available
Fix from $1,600 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6301

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6304

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6305

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6309

An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid rea…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6310

An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to i…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Iphone Os HIGH 8.1
CVE-2016-7643

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Mac Os X HIGH 7.1
CVE-2016-4682

An issue was discovered in certain Apple products. macOS before 10.12 is affected. macOS before 10.12.1 is affected. The issue involves the "ImageIO"…

Fix: after 10.12.0
Fix from $1,950 2017-02-20
Libdwarf MEDIUM 6.5
CVE-2016-7510

The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of ser…

Fix: 2016-09-23+
Fix from $1,600 2017-02-17