Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Chrome MEDIUM 5.0
CVE-2011-3234

Google Chrome before 14.0.835.163 does not properly handle boxes, which allows remote attackers to cause a denial of service (out-of-bounds read) via…

Fix: 5.0 / 5.1.1+
Fix from $1,600 2011-09-19
Chrome MEDIUM 5.0
CVE-2011-2843

Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attackers to cause a denial of service (out-of-bounds r…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome MEDIUM 5.0
CVE-2011-2844

Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers to cause a denial of service (out-of-bounds read…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome MEDIUM 6.8
CVE-2011-2794

Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds…

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Chrome MEDIUM 6.8
CVE-2011-2803

Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers to cause a denial of service (out-of-bounds read…

Fix: 13.0.782.107+
Fix from $1,600 2011-08-03
Fedora MEDIUM 6.5
CVE-2011-2501

The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows re…

Fix: 1.0.55 / 1.2.45+
Fix from $1,600 2011-07-17
Chrome MEDIUM 6.8
CVE-2011-1445

Google Chrome before 11.0.696.57 does not properly handle SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds re…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03
Chrome MEDIUM 6.8
CVE-2011-1455

Google Chrome before 11.0.696.57 does not properly handle PDF documents with multipart encoding, which allows remote attackers to cause a denial of s…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03
Chrome MEDIUM 5.0
CVE-2011-1192

Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows remote attackers to cause a denial of service (out-o…

Fix: 10.0.648.127+
Fix from $1,600 2011-03-11
Chrome MEDIUM 5.0
CVE-2011-1113

Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserialization, which allows remote attackers to cause a…

Fix: 9.0.597.107+
Fix from $1,600 2011-03-01
Chrome MEDIUM 5.0
CVE-2011-1120

The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecifie…

Fix: 9.0.597.107+
Fix from $1,600 2011-03-01
Chrome MEDIUM 5.0
CVE-2011-1122

The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecifie…

Fix: 9.0.597.107+
Fix from $1,600 2011-03-01
Chrome MEDIUM 5.0
CVE-2011-0984

Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (out-of-bounds read) vi…

Fix: 9.0.597.94+
Fix from $1,600 2011-02-10
Chrome HIGH 7.5
CVE-2010-4577

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.55…

Fix: 1.2.6 / 8.0.552.224+
Fix from $1,950 2010-12-22
HTTP Server MEDIUM 5.0
CVE-2007-3847EPSS 13%

The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a …

Fix: 2.0.61 / 2.2.6+
Fix from $1,600 2007-08-23
WordPress MEDIUM 6.5
CVE-2006-6016

wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id p…

Fix: after 2.0.4
Fix from $1,600 2006-11-21
Secure Desktop MEDIUM 5.5
CVE-2006-5393

Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local u…

Mitigation only
Fix from $1,600 2006-10-18
Kphone MEDIUM 5.0
CVE-2004-1940

sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLe…

Fix: after 4.0.1
Fix from $1,600 2004-12-31
Firewall Services Module MEDIUM 5.0
CVE-2004-0112EPSS 10%

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos …

Mitigation only
Fix from $1,600 2004-11-23
Libpng MEDIUM 5.0
CVE-2004-0421

The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image fil…

Patch available
Fix from $1,600 2004-08-18
Tcpdump MEDIUM 5.0
CVE-2004-0183EPSS 6%

TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large nu…

Fix: after 3.8.1
Fix from $1,600 2004-05-04
Tcpdump MEDIUM 5.0
CVE-2004-0184EPSS 60%

Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP pac…

Fix: after 3.8.1
Fix from $1,600 2004-05-04
OpenBSD MEDIUM 5.0
CVE-2004-0221

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing…

Fix: after 3.4
Fix from $1,600 2004-05-04
Qpopper CRITICAL 9.8
CVE-1999-0006EPSS 12%

Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.

Mitigation only
Fix from $2,300 1998-07-14
Irix HIGH 8.4
CVE-1999-0029

root privileges via buffer overflow in ordist command on SGI IRIX systems.

Mitigation only
Fix from $1,950 1997-07-16
FreeBSD HIGH 7.8
CVE-1999-0022

Local user gains root privileges via buffer overflow in rdist, via expstr() function.

Mitigation only
Fix from $1,950 1996-07-03