Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Ffmpeg HIGH 7.8
CVE-2016-7450

The ff_log2_16bit_c function in libavutil/intmath.h in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when it decodes a malformed …

Fix: after 3.1.3
Fix from $1,950 2016-12-23
Ffmpeg HIGH 7.8
CVE-2016-7502

The cavs_idct8_add_c function in libavcodec/cavsdsp.c in FFmpeg before 3.1.4 is vulnerable to reading out-of-bounds memory when decoding with cavs_de…

Fix: after 3.1.3
Fix from $1,950 2016-12-23
Office HIGH 7.1
CVE-2016-7290EPSS 17%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7291EPSS 17%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Ser…

Mitigation only
Fix from $1,950 2016-12-20
Excel HIGH 7.1
CVE-2016-7264EPSS 17%

Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain se…

Mitigation only
Fix from $1,950 2016-12-20
Excel HIGH 7.1
CVE-2016-7265EPSS 17%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services …

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7268EPSS 17%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on S…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.1
CVE-2016-7276EPSS 21%

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive …

Mitigation only
Fix from $1,950 2016-12-20
Chrome MEDIUM 5.3
CVE-2016-5186

Devtools in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android incorrectly handled objects after a tab crash, …

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Fedora CRITICAL 9.8
CVE-2016-7951

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the l…

Fix: after 1.2.2
Fix from $2,300 2016-12-13
Fedora HIGH 7.5
CVE-2016-7945

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite l…

Fix: after 1.7.6
Fix from $1,950 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-5407

The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access…

Fix: after 1.0.10
Fix from $2,300 2016-12-13
Imagemagick CRITICAL 9.1
CVE-2016-6520

Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel…

Fix: 7.0.2-7+
Fix from $2,300 2016-12-13
Imagemagick HIGH 8.8
CVE-2016-6491EPSS 6%

Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers…

Fix: after 6.9.5-3
Fix from $1,950 2016-12-13
Imagemagick HIGH 7.5
CVE-2016-5842EPSS 6%

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variab…

Fix: 6.9.4-10 / 7.0.2-1+
Fix from $1,950 2016-12-13
Imagemagick CRITICAL 9.8
CVE-2016-5687

The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact …

Fix: after 6.9.4-2
Fix from $2,300 2016-12-13
W3m MEDIUM 6.5
CVE-2016-9433

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (out-of-bounds ar…

Fix: after 0.5.3-30
Fix from $1,600 2016-12-12
Bluez HIGH 7.5
CVE-2016-9918

In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by pr…

No fix yet
Fix from $1,950 2016-12-08
Bluez MEDIUM 5.3
CVE-2016-9803

In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subev…

No fix yet
Fix from $1,600 2016-12-03
Bluez MEDIUM 5.3
CVE-2016-9797

In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by process…

No fix yet
Fix from $1,600 2016-12-03
Linux Kernel CRITICAL 9.8
CVE-2016-9555EPSS 9%

The sctp_sf_ootb function in net/sctp/sm_statefuns.c in the Linux kernel before 4.8.8 lacks chunk-length checking for the first chunk, which allows r…

Fix: 3.2.85 / 3.10.105+
Fix from $2,300 2016-11-28
Libtiff CRITICAL 9.8
CVE-2016-9539

tools/tiffcrop.c in libtiff 4.0.6 has an out-of-bounds read in readContigTilesIntoBuffer(). Reported as MSVR 35092.

Patch available
Fix from $2,300 2016-11-22
Linux Kernel MEDIUM 5.0
CVE-2016-7917

The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is…

Fix: after 4.4.32
Fix from $1,600 2016-11-16
Linux Kernel MEDIUM 5.5
CVE-2016-7915

The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive infor…

Fix: after 4.5.7
Fix from $1,600 2016-11-16
Linux Kernel MEDIUM 5.5
CVE-2016-7914

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, whi…

Fix: after 4.5.2
Fix from $1,600 2016-11-16
Phantompdf HIGH 8.8
CVE-2016-8878

Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to exe…

Fix: after 8.0.5
Fix from $1,950 2016-10-31
Phantompdf HIGH 7.5
CVE-2016-8876

Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to exe…

Fix: after 8.0.5
Fix from $1,950 2016-10-31
Phantompdf MEDIUM 5.3
CVE-2016-8875

The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a deni…

Fix: after 8.0.5
Fix from $1,600 2016-10-31
Mujs HIGH 7.5
CVE-2016-7506

An out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before 5000749f5afe3b956fc916e407309de8…

Fix: after 8c805b4eb19cf2af689c860b77e6111d2ee439d5
Fix from $1,950 2016-10-29
Mujs HIGH 7.5
CVE-2016-9017

Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by usi…

Fix: after 5c337af4b3df80cf967e4f9f6a21522de84b392a
Fix from $1,950 2016-10-28