Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Gstreamer HIGH 7.5
CVE-2017-5838

The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of servi…

Fix: after 1.10.2
Fix from $1,950 2017-02-09
Gstreamer HIGH 7.5
CVE-2017-5840

The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial o…

Fix: after 1.10.2
Fix from $1,950 2017-02-09
Gstreamer HIGH 7.5
CVE-2017-5841

The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a deni…

Fix: after 1.10.2
Fix from $1,950 2017-02-09
Gstreamer HIGH 7.5
CVE-2017-5845

The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a deni…

Fix: after 1.10.2
Fix from $1,950 2017-02-09
Gstreamer MEDIUM 5.5
CVE-2017-5846

The gst_asf_demux_process_ext_stream_props function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer before 1.10.3 allows remote attack…

Fix: after 1.10.2
Fix from $1,600 2017-02-09
Debian Linux HIGH 7.5
CVE-2017-5847

The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a…

Fix: 1.11.2+
Fix from $1,950 2017-02-09
Debian Linux HIGH 7.5
CVE-2017-5848

The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of serv…

Fix: 1.11.2+
Fix from $1,950 2017-02-09
Gstreamer MEDIUM 5.5
CVE-2016-10198

The gst_aac_parse_sink_setcaps function in gst/audioparsers/gstaacparse.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to c…

Fix: after 1.10.2
Fix from $1,600 2017-02-09
Gstreamer HIGH 7.5
CVE-2016-10199

The qtdemux_tag_add_str_full function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denia…

Fix: after 1.10.2
Fix from $1,950 2017-02-09
Perl CRITICAL 9.8
CVE-2015-8608

The VDir::MapPathA and VDir::MapPathW functions in Perl 5.22 allow remote attackers to cause a denial of service (out-of-bounds read) and possibly ex…

Patch available
Fix from $2,300 2017-02-07
Debian Linux HIGH 7.5
CVE-2016-7449

The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) vi…

Mitigation only
Fix from $1,950 2017-02-06
Debian Linux MEDIUM 5.5
CVE-2016-9532

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of servi…

Fix: after 4.0.6
Fix from $1,600 2017-02-06
Ubuntu Linux HIGH 7.1
CVE-2016-10165

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of servi…

Patch available
Fix from $1,950 2017-02-03
Openjpeg MEDIUM 5.5
CVE-2016-3183EPSS 6%

The sycc422_t_rgb function in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a…

Fix: after 2.1.0
Fix from $1,600 2017-02-03
Libavformat MEDIUM 5.5
CVE-2016-5115

The avcodec_decode_audio4 function in libavcodec in libavformat 57.34.103, as used in MPlayer, allows remote attackers to cause a denial of service (…

Mitigation only
Fix from $1,600 2017-02-03
Librsvg MEDIUM 5.5
CVE-2016-6163

The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds …

Patch available
Fix from $1,600 2017-02-03
Fedora MEDIUM 5.5
CVE-2016-8568

The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat…

Fix: after 0.24.2
Fix from $1,600 2017-02-03
Webkit MEDIUM 5.5
CVE-2016-9642

JavaScriptCore in WebKit allows attackers to cause a denial of service (out-of-bounds heap read) via a crafted Javascript file.

Mitigation only
Fix from $1,600 2017-02-03
Lepton MEDIUM 5.5
CVE-2016-6236

The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) …

Patch available
Fix from $1,600 2017-02-02
Lepton MEDIUM 5.5
CVE-2016-6238

The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a cra…

Patch available
Fix from $1,600 2017-02-02
Pacman MEDIUM 5.5
CVE-2016-5434

libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature …

Patch available
Fix from $1,600 2017-01-30
Debian Linux MEDIUM 5.3
CVE-2016-2518EPSS 15%

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an add…

Patch available
Fix from $1,600 2017-01-30
Libarchive HIGH 7.5
CVE-2017-5601

An error in the lha_read_file_header_1() function (archive_read_support_format_lha.c) in libarchive 3.2.2 allows remote attackers to trigger an out-o…

Patch available
Fix from $1,950 2017-01-27
Libical MEDIUM 5.5
CVE-2016-5825

The icalparser_parse_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a cra…

Mitigation only
Fix from $1,600 2017-01-27
Libical HIGH 7.5
CVE-2016-5826

The parser_get_next_char function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) by crafting …

Mitigation only
Fix from $1,950 2017-01-27
Libical HIGH 7.5
CVE-2016-5827

The icaltime_from_string function in libical 0.47 and 1.0 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafte…

Mitigation only
Fix from $1,950 2017-01-27
Database Server HIGH 8.2
CVE-2016-9050

An exploitable out-of-bounds read vulnerability exists in the client message-parsing functionality of Aerospike Database Server 3.10.0.3. A specially…

No fix yet
Fix from $1,950 2017-01-26
Libgd MEDIUM 5.5
CVE-2016-6911

The dynamicGetbuf function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: after 2.2.3
Fix from $1,600 2017-01-26
PHP HIGH 7.5
CVE-2016-10161EPSS 13%

The object_common1 function in ext/standard/var_unserializer.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attack…

Fix: after 5.6.29
Fix from $1,950 2017-01-24
Gstreamer HIGH 7.8
CVE-2016-9447

The ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write) and possibl…

Mitigation only
Fix from $1,950 2017-01-23