Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
OpenSSL HIGH 7.5
CVE-2014-0160 KEVEPSS 100%

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attac…

Fix: 1.0.1g+
Fix from $1,950 2014-04-07
Firefox HIGH 8.8
CVE-2014-1497

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonke…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19
Firefox CRITICAL 9.1
CVE-2014-1508

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey befor…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Vlc Media Player MEDIUM 6.3
CVE-2013-3245

plugins/demux/libmkv_plugin.dll in VideoLAN VLC Media Player 2.0.7, and possibly other versions, allows remote attackers to cause a denial of service…

No fix yet
Fix from $1,600 2013-07-10
Chrome MEDIUM 5.0
CVE-2013-0888

Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a deni…

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,600 2013-02-23
Firefox HIGH 9.3
CVE-2013-0778

The ClusterIterator::NextCluster function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attacker…

Fix: 2.16 / 17.0.3+
Fix from $1,950 2013-02-19
Firefox HIGH 9.3
CVE-2013-0779EPSS 5%

The nsCodingStateMachine::NextState function in Mozilla Firefox before 19.0, Thunderbird before 17.0.3, and SeaMonkey before 2.16 allows remote attac…

Fix: 2.16 / 17.0.3+
Fix from $1,950 2013-02-19
Firefox HIGH 10.0
CVE-2013-0767EPSS 6%

The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird…

Fix: 2.15 / 10.0.12+
Fix from $1,950 2013-01-13
Chrome MEDIUM 5.0
CVE-2012-5130

Skia, as used in Google Chrome before 23.0.1271.91, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 23.0.1271.89
Fix from $1,600 2012-11-28
Firefox HIGH 9.3
CVE-2012-3995EPSS 5%

The IsCSSWordSpacingSpace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x befo…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Chrome MEDIUM 5.0
CVE-2012-5109

The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of servic…

Fix: after 22.0.1229.91
Fix from $1,600 2012-10-09
Chrome MEDIUM 5.0
CVE-2012-5110

The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: after 22.0.1229.91
Fix from $1,600 2012-10-09
File MEDIUM 6.5
CVE-2012-1571

file before 5.11 and libmagic allow remote attackers to cause a denial of service (crash) via a crafted Composite Document File (CDF) file that trigg…

Fix: after 5.10
Fix from $1,600 2012-07-17
Debian Linux MEDIUM 6.5
CVE-2012-1798

The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds…

Patch available
Fix from $1,600 2012-06-05
Debian Linux MEDIUM 6.5
CVE-2012-0259

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a ze…

Fix: 6.7.6-3+
Fix from $1,600 2012-06-05
Chrome MEDIUM 6.8
CVE-2011-3066

Skia, as used in Google Chrome before 18.0.1025.151, does not properly perform clipping, which allows remote attackers to cause a denial of service (…

Fix: 18.0.1025.151+
Fix from $1,600 2012-04-05
Chrome MEDIUM 6.8
CVE-2011-3059

Google Chrome before 18.0.1025.142 does not properly handle SVG text elements, which allows remote attackers to cause a denial of service (out-of-bou…

Fix: 6.0 / 10.7+
Fix from $1,600 2012-03-30
Chrome MEDIUM 6.8
CVE-2011-3060

Google Chrome before 18.0.1025.142 does not properly handle text fragments, which allows remote attackers to cause a denial of service (out-of-bounds…

Fix: 6.0 / 10.7+
Fix from $1,600 2012-03-30
Chrome MEDIUM 5.0
CVE-2011-3963

Google Chrome before 17.0.963.46 does not properly handle PDF FAX images, which allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: 17.0.963.46+
Fix from $1,600 2012-02-09
Chrome MEDIUM 5.0
CVE-2011-3905

libxml2, as used in Google Chrome before 16.0.912.63, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vecto…

Fix: 16.0.912.63+
Fix from $1,600 2011-12-13
Chrome MEDIUM 5.0
CVE-2011-3906

The PDF parser in Google Chrome before 16.0.912.63 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

Fix: 16.0.912.63+
Fix from $1,600 2011-12-13
Chrome MEDIUM 5.0
CVE-2011-3908

Google Chrome before 16.0.912.63 does not properly parse SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds rea…

Fix: 5.1 / 5.1.4+
Fix from $1,600 2011-12-13
Chrome MEDIUM 5.0
CVE-2011-3910

Google Chrome before 16.0.912.63 does not properly handle YUV video frames, which allows remote attackers to cause a denial of service (out-of-bounds…

Fix: 16.0.912.63+
Fix from $1,600 2011-12-13
Chrome MEDIUM 5.0
CVE-2011-3911

Google Chrome before 16.0.912.63 does not properly handle PDF documents, which allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: 16.0.912.63+
Fix from $1,600 2011-12-13
Chrome MEDIUM 5.0
CVE-2011-3916

Google Chrome before 16.0.912.63 does not properly handle PDF cross references, which allows remote attackers to cause a denial of service (out-of-bo…

Fix: 16.0.912.63+
Fix from $1,600 2011-12-13
Chrome MEDIUM 5.0
CVE-2011-3893

Google Chrome before 15.0.874.120 does not properly implement the MKV and Vorbis media handlers, which allows remote attackers to cause a denial of s…

Fix: 15.0.874.120+
Fix from $1,600 2011-11-11
Chrome MEDIUM 5.0
CVE-2011-2850

Google Chrome before 14.0.835.163 does not properly handle Khmer characters, which allows remote attackers to cause a denial of service (out-of-bound…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome MEDIUM 5.0
CVE-2011-2851

Google Chrome before 14.0.835.163 does not properly handle video, which allows remote attackers to cause a denial of service (out-of-bounds read) via…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome MEDIUM 5.0
CVE-2011-2858

Google Chrome before 14.0.835.163 does not properly handle triangle arrays, which allows remote attackers to cause a denial of service (out-of-bounds…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome MEDIUM 5.0
CVE-2011-2864

Google Chrome before 14.0.835.163 does not properly handle Tibetan characters, which allows remote attackers to cause a denial of service (out-of-bou…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19