Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 6.5
CVE-2016-6161

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) …

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 6.5
CVE-2016-6132

The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of…

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Linux Kernel HIGH 7.8
CVE-2016-2064

sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) …

Fix: after 3.19.8
Fix from $1,950 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5352

epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to c…

Patch available
Fix from $1,600 2016-08-07
Libgd HIGH 7.6
CVE-2013-7456EPSS 6%

gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allo…

Patch available
Fix from $1,950 2016-08-07
Android HIGH 7.8
CVE-2016-3855

drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows at…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2016-3854

drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attacke…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Openoffice HIGH 7.8
CVE-2016-1513EPSS 8%

The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute…

Fix: after 4.1.2
Fix from $1,950 2016-08-05
OpenSSL HIGH 7.5
CVE-2016-2180EPSS 28%

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL throug…

Patch available
Fix from $1,950 2016-08-01
Mac Os X MEDIUM 6.3
CVE-2016-4652

CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or …

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Iphone Os MEDIUM 5.5
CVE-2016-4628

IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause…

Fix: after 9.3.2
Fix from $1,600 2016-07-22
Vtscada HIGH 7.5
CVE-2016-4523 KEVEPSS 31%

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bo…

Fix: 11.2.02+
Fix from $1,950 2016-06-09
Ubuntu Linux MEDIUM 5.5
CVE-2016-1839EPSS 13%

The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before …

Patch available
Fix from $1,600 2016-05-20
Ubuntu Linux MEDIUM 5.5
CVE-2016-1838EPSS 12%

The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, an…

Patch available
Fix from $1,600 2016-05-20
Debian Linux MEDIUM 5.5
CVE-2016-1833

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2…

Patch available
Fix from $1,600 2016-05-20
Tvos HIGH 7.8
CVE-2016-1823EPSS 10%

The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows att…

Fix: 2.2.1 / 9.2.1+
Fix from $1,950 2016-05-20
Proface Gp Pro Ex Ex Ed MEDIUM 6.5
CVE-2016-2291

Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers …

Fix: after 4.0.4
Fix from $1,600 2016-04-06
Debian Linux HIGH 8.8
CVE-2016-1646 KEVEPSS 48%

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider elem…

Fix: 49.0.2623.108+
Fix from $1,950 2016-03-29
Linux MEDIUM 5.3
CVE-2015-8629

The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verif…

Patch available
Fix from $1,600 2016-02-13
Debian Linux MEDIUM 6.5
CVE-2015-8783

tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.

Fix: 4.0.7+
Fix from $1,600 2016-02-01
Grassroots Dicom HIGH 8.2
CVE-2015-8397

The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote att…

Fix: 2.6.2+
Fix from $1,950 2016-01-12
Ubuntu Linux MEDIUM 6.8
CVE-2014-9669

Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memor…

Patch available
Fix from $1,600 2015-02-08
Ubuntu Linux HIGH 7.5
CVE-2014-9658EPSS 5%

The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to…

Patch available
Fix from $1,950 2015-02-08
Enterprise Linux Desktop HIGH 7.5
CVE-2014-9657EPSS 5%

The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers…

Patch available
Fix from $1,950 2015-02-08
Linux Kernel HIGH 7.8
CVE-2014-7825

kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, w…

Fix: 3.2.65 / 3.4.106+
Fix from $1,950 2014-11-10
Ubuntu Linux MEDIUM 5.0
CVE-2014-8483

The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a mal…

Patch available
Fix from $1,600 2014-11-06
Shim MEDIUM 5.0
CVE-2014-3675

Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.

Fix: 0.8+
Fix from $1,600 2014-10-22
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-4341EPSS 7%

MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting in…

Patch available
Fix from $1,600 2014-07-20
Fedora HIGH 9.3
CVE-2014-1522EPSS 5%

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 al…

Fix: 2.26 / 29.0+
Fix from $1,950 2014-04-30
Ioserver Opc Server HIGH 7.8
CVE-2014-0777

The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers to cause a denial of service …

Fix: after 1.0.20
Fix from $1,950 2014-04-11