Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-6264
An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used a…
Linux Kernel
Patch available
MEDIUM 5.5
CVE-2017-16805
In radare2 2.0.1, libr/bin/dwarf.c allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file, …
Radare2
Patch available
MEDIUM 5.5
CVE-2017-16808EPSS 6%
tcpdump before 4.9.3 has a heap-based buffer over-read related to aoe_print in print-aoe.c and lookup_emem in addrtoname.c.
Tcpdump
No fix yet
MEDIUM 5.5
CVE-2017-13817
An out-of-bounds read issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It…
Mac Os X
after 10.13.0
MEDIUM 5.5
CVE-2017-16794
The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows rem…
Swftools
Mitigation only
MEDIUM 6.6
CVE-2017-16643
The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local users to cause a denial of se…
Linux Kernel
after 4.13.11
MEDIUM 6.6
CVE-2017-16645
The ims_pcu_get_cdc_union_desc function in drivers/input/misc/ims-pcu.c in the Linux kernel through 4.13.11 allows local users to cause a denial of s…
Linux Kernel
after 4.13.11
HIGH 7.5
CVE-2017-16642EPSS 21%
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian handling of 'front of' and 'back …
PHP
5.6.32 / 7.0.25+
HIGH 8.2
CVE-2017-2895
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT …
Mongoose
Mitigation only
HIGH 8.8
CVE-2017-15672
The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via …
Debian Linux
after 3.3.4
CRITICAL 9.8
CVE-2017-16548EPSS 5%
The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character in an xattr name, which allo…
Ubuntu Linux
after 3.1.2
MEDIUM 6.6
CVE-2017-16533
The usbhid_parse function in drivers/hid/usbhid/hid-core.c in the Linux kernel before 4.13.8 allows local users to cause a denial of service (out-of-…
Linux Kernel
3.2.95 / 3.16.50+
MEDIUM 6.6
CVE-2017-16535
The usb_get_bos_descriptor function in drivers/usb/core/config.c in the Linux kernel before 4.13.10 allows local users to cause a denial of service (…
Linux Kernel
after 4.13.9
MEDIUM 6.6
CVE-2017-16529
The snd_usb_create_streams function in sound/usb/card.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bou…
Linux Kernel
3.2.95 / 3.16.50+
MEDIUM 6.6
CVE-2017-16530
The uas driver in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly ha…
Linux Kernel
3.16.50 / 3.18.75+
HIGH 7.8
CVE-2017-16358
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.
Radare2
Patch available
MEDIUM 6.5
CVE-2017-16353EPSS 11%
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…
Debian Linux
No fix yet
MEDIUM 6.5
CVE-2017-10942
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…
Foxit Reader
Patch available
MEDIUM 6.5
CVE-2017-10943
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…
Foxit Reader
Patch available
MEDIUM 6.5
CVE-2017-10944
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…
Foxit Reader
Patch available
HIGH 7.8
CVE-2017-15931
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/fo…
Radare2
Patch available
HIGH 7.8
CVE-2017-15932
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verdef() in libr/bin/for…
Radare2
Patch available
HIGH 8.8
CVE-2017-5077
Insufficient validation of untrusted input in Skia in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, …
Chrome
59.0.3071.86 / 59.0.3071.92+
HIGH 8.8
CVE-2017-5088
Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.104 for Mac, Windows, and Linux, and 59.0.3071.117 for Android, …
Chrome
59.0.3071.104 / 59.0.3071.117+
CRITICAL 9.6
CVE-2017-5053
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote atta…
Chrome
57.0.2987.132 / 57.0.2987.133+
HIGH 8.8
CVE-2017-5054
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote atta…
Chrome
57.0.2987.132 / 57.0.2987.133+
HIGH 8.8
CVE-2017-5055
A use after free in printing in Google Chrome prior to 57.0.2987.133 for Linux and Windows allowed a remote attacker to perform an out of bounds memo…
Chrome
57.0.2987.133+
MEDIUM 5.5
CVE-2017-15922
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
Libextractor
No fix yet
HIGH 7.1
CVE-2017-12613
When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, ou…
Portable Runtime
1.7.0+
HIGH 7.5
CVE-2017-15228
Irssi before 1.0.5, when installing themes with unterminated colour formatting sequences, may access data beyond the end of the string.
Irssi
after 1.0.4