Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Libgd MEDIUM 6.5
CVE-2016-6905

The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out…

Fix: after 2.2.2
Fix from $1,600 2016-10-03
Libtiff HIGH 7.5
CVE-2016-3658

The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause …

Fix: after 4.0.6
Fix from $1,950 2016-10-03
Libtiff HIGH 7.5
CVE-2016-3634

The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out…

Fix: after 4.0.6
Fix from $1,950 2016-10-03
Libtiff HIGH 7.5
CVE-2016-3633

The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via …

Fix: after 4.0.6
Fix from $1,950 2016-10-03
Libtiff HIGH 7.5
CVE-2016-3631

The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (ou…

Fix: after 4.0.6
Fix from $1,950 2016-10-03
Libtiff MEDIUM 6.5
CVE-2016-3625

tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted T…

Fix: after 4.0.6
Fix from $1,600 2016-10-03
Libtiff HIGH 8.8
CVE-2016-3621

The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to c…

Fix: after 4.0.6
Fix from $1,950 2016-10-03
Libtiff HIGH 7.5
CVE-2016-3620

The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to c…

Fix: after 4.0.6
Fix from $1,950 2016-10-03
Libtiff MEDIUM 6.5
CVE-2016-3619

The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote att…

No fix yet
Fix from $1,600 2016-10-03
OpenSSL MEDIUM 5.9
CVE-2016-6306EPSS 42%

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read…

Fix: 0.10.47 / 0.12.16+
Fix from $1,600 2016-09-26
Iphone Os HIGH 7.1
CVE-2016-4776

The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout informa…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Iphone Os HIGH 7.1
CVE-2016-4774

The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout informa…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Iphone Os HIGH 7.1
CVE-2016-4773

The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout informa…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Firefox MEDIUM 6.5
CVE-2016-5271

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds …

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Firefox MEDIUM 6.5
CVE-2016-2827

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Ubuntu Linux MEDIUM 5.5
CVE-2015-8934

The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of …

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8928

The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Libarchive MEDIUM 5.5
CVE-2015-8927

The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of ser…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8925

The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8924EPSS 10%

The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a d…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2015-8921EPSS 12%

The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) v…

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Ubuntu Linux MEDIUM 5.5
CVE-2015-8920

The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Libarchive MEDIUM 5.5
CVE-2015-8915

bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file.

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Wireshark MEDIUM 5.9
CVE-2016-7175

epan/dissectors/packet-qnet6.c in the QNX6 QNET dissector in Wireshark 2.x before 2.0.6 mishandles MAC address data, which allows remote attackers to…

Patch available
Fix from $1,600 2016-09-09
Libidn HIGH 7.5
CVE-2016-6263

The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-…

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux HIGH 7.5
CVE-2016-6262EPSS 6%

idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-…

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux HIGH 7.5
CVE-2016-6261

The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read…

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux HIGH 7.5
CVE-2015-8948EPSS 6%

idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an …

Fix: after 1.32
Fix from $1,950 2016-09-07
Ubuntu Linux MEDIUM 6.0
CVE-2016-5107

The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrat…

Fix: after 2.6.2
Fix from $1,600 2016-09-02
Debian Linux MEDIUM 6.5
CVE-2016-6214

gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted …

Fix: after 2.2.2
Fix from $1,600 2016-08-12