Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Libdwarf MEDIUM 5.5
CVE-2016-7410

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a craft…

No fix yet
Fix from $1,600 2017-01-23
Foxit Reader HIGH 8.1
CVE-2017-5556

The ConvertToPDF plugin in Foxit Reader before 8.2 and PhantomPDF before 8.2 on Windows, when the gflags app is enabled, allows remote attackers to c…

Mitigation only
Fix from $1,950 2017-01-23
Libtiff HIGH 8.8
CVE-2017-5563

LibTIFF version 4.0.7 is vulnerable to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution via a crafted bmp image to tools…

Mitigation only
Fix from $1,950 2017-01-23
Libplist CRITICAL 9.1
CVE-2017-5545

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or ca…

Fix: after 1.12
Fix from $2,300 2017-01-21
Libtiff MEDIUM 6.5
CVE-2016-5316

Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by…

Fix: after 4.0.6
Fix from $1,600 2017-01-20
Mujs HIGH 7.5
CVE-2016-9109

Artifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this vulnerabi…

No fix yet
Fix from $1,950 2017-01-18
Libtiff MEDIUM 5.5
CVE-2016-9273EPSS 7%

tiffsplit in libtiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file, related to changing td_nstri…

Mitigation only
Fix from $1,600 2017-01-18
Libtiff HIGH 7.5
CVE-2016-9297EPSS 6%

The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted TIFF_SETGET_C1…

Patch available
Fix from $1,950 2017-01-18
Imagemagick MEDIUM 6.5
CVE-2016-7101

The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sg…

Fix: 6.9.5-8 / 7.0.2-10+
Fix from $1,600 2017-01-18
Mujs HIGH 7.5
CVE-2016-7563

The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of …

No fix yet
Fix from $1,950 2017-01-18
Debian Linux MEDIUM 6.5
CVE-2016-7799

MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.6-0 / 7.0.3-2+
Fix from $1,600 2017-01-18
Gstreamer HIGH 7.8
CVE-2016-9809

Off-by-one error in the gst_h264_parse_set_caps function in GStreamer before 1.10.2 allows remote attackers to have unspecified impact via a crafted …

Fix: after 1.10.1
Fix from $1,950 2017-01-13
Gstreamer MEDIUM 5.5
CVE-2016-9810

The gst_decode_chain_free_internal function in the flxdex decoder in gst-plugins-good in GStreamer before 1.10.2 allows remote attackers to cause a d…

Fix: after 1.10.1
Fix from $1,600 2017-01-13
Gstreamer HIGH 7.5
CVE-2016-9812

The gst_mpegts_section_new function in the mpegts decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bou…

Fix: after 1.10.1
Fix from $1,950 2017-01-13
Gstreamer MEDIUM 5.5
CVE-2016-9807

The flx_decode_chunks function in gst/flx/gstflxdec.c in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (invalid memory…

Fix: after 1.10.1
Fix from $1,600 2017-01-13
Libplist CRITICAL 9.1
CVE-2017-5209

The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory …

Fix: after 1.12
Fix from $2,300 2017-01-11
Ubuntu Linux MEDIUM 5.9
CVE-2016-2366

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potent…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2367

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result i…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2370

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could poten…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2372

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result i…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2373

A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potent…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2374

An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Ubuntu Linux MEDIUM 5.3
CVE-2016-2375

An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the ser…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Matrixssl HIGH 7.5
CVE-2016-6891

MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 …

Fix: after 3.8.5
Fix from $1,950 2017-01-05
PHP CRITICAL 9.8
CVE-2016-9935EPSS 7%

The php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.29 and 7.x before 7.0.14 allows remote attackers to cause a denial of service…

Fix: after 5.6.28
Fix from $2,300 2017-01-04
Debian Linux HIGH 7.1
CVE-2015-8743

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'i…

Fix: after 2.5.1
Fix from $1,950 2016-12-29
Qemu MEDIUM 5.5
CVE-2015-8817

QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue.…

Patch available
Fix from $1,600 2016-12-29
Linux Kernel HIGH 7.8
CVE-2016-9777

KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host …

Fix: 4.8.12+
Fix from $1,950 2016-12-28
Msgpuck HIGH 7.5
CVE-2016-9036

An exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially crafted packet …

No fix yet
Fix from $1,950 2016-12-23
Tarantool HIGH 7.5
CVE-2016-9037

An exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A specially crafted …

No fix yet
Fix from $1,950 2016-12-23