Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 5.9 CVE-2017-15722 In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string. Debian Linux after 1.0.4 Fix from $1,6002017-10-22 HIGH 7.8 CVE-2017-15368 The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-rea… Radare2 Patch available Fix from $1,9502017-10-16 HIGH 7.1 CVE-2017-13720 In the PatternMatch function in fontfile/fontdir.c in libXfont through 1.5.2 and 2.x before 2.0.2, an attacker with access to an X connection can cau… Libxfont after 1.5.2 Fix from $1,9502017-10-11 HIGH 7.1 CVE-2017-13722 In the pcfGetProperties function in bitmap/pcfread.c in libXfont through 1.5.2 and 2.x before 2.0.2, a missing boundary check (for PCF files) could b… Libxfont after 1.5.2 Fix from $1,9502017-10-11 HIGH 7.5 CVE-2017-9715 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a vendor command, a … Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-9717 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing Netlink attributes, a b… Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11052 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted … Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11054 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted … Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11055 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted … Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11060 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during … Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11061 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing cfg80211 vendor sub … Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11062 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently attributes are not validate… Android Mitigation only Fix from $1,9502017-10-10 HIGH 7.5 CVE-2017-11064 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed during … Android Mitigation only Fix from $1,9502017-10-10 MEDIUM 5.5 CVE-2017-15045 LAME 3.99, 3.99.1, 3.99.2, 3.99.3, 3.99.4, 3.99.5, 3.98.4, 3.98.2 and 3.98 has a heap-based buffer over-read in fill_buffer in libmp3lame/util.c, rel… Lame No fix yet Fix from $1,6002017-10-06 HIGH 8.1 CVE-2017-15037 In FreeBSD through 11.1, the smb_strdupin function in sys/netsmb/smb_subr.c has a race condition with a resultant out-of-bounds read, because it can … FreeBSD after 11.1 Fix from $1,9502017-10-05 MEDIUM 5.5 CVE-2017-15018 LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handling a malformed file in k_34_… Lame No fix yet Fix from $1,6002017-10-05 HIGH 7.8 CVE-2017-15020 dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles pointers, which allows remote atta… Binutils Patch available Fix from $1,9502017-10-05 MEDIUM 5.5 CVE-2017-15021 bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote at… Binutils Patch available Fix from $1,6002017-10-05 HIGH 7.8 CVE-2017-0812 An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A… Android Patch available Fix from $1,9502017-10-04 HIGH 7.5 CVE-2017-14976 The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font d… Debian Linux Patch available Fix from $1,9502017-10-02 MEDIUM 5.5 CVE-2017-14931 ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read … Openexif Mitigation only Fix from $1,6002017-09-30 MEDIUM 5.5 CVE-2017-14939EPSS 11% decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calcu… Binutils Patch available Fix from $1,6002017-09-30 MEDIUM 5.5 CVE-2017-14860 There is a heap-based buffer over-read in the Exiv2::Jp2Image::readMetadata function of jp2image.cpp in Exiv2 0.26. A Crafted input will lead to a de… Exiv2 No fix yet Fix from $1,6002017-09-29 HIGH 8.8 CVE-2017-14795 The hevc_write_frame function in libbpg.c in libbpg 0.9.7 allows remote attackers to cause a denial of service (out-of-bounds read and application cr… Libbpg No fix yet Fix from $1,9502017-09-28 MEDIUM 6.5 CVE-2017-14731 ofx_proc_file in ofx_preproc.cpp in LibOFX 0.9.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application c… Libofx Patch available Fix from $1,6002017-09-25 MEDIUM 6.5 CVE-2017-14733 ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a de… Debian Linux Mitigation only Fix from $1,6002017-09-25 MEDIUM 6.5 CVE-2015-5327 Out-of-bounds memory read in the x509_decode_time function in x509_cert_parser.c in Linux kernels 4.3-rc1 and after. Linux Kernel Patch available Fix from $1,6002017-09-25 CRITICAL 9.8 CVE-2017-9283 An out-of-bounds read (CWE-125) vulnerability exists in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further atta… Visibroker No fix yet Fix from $2,3002017-09-21 CRITICAL 9.1 CVE-2017-7544 libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by … Libexif after 0.6.21 Fix from $2,3002017-09-21 MEDIUM 6.5 CVE-2017-14643 The AP4_HdlrAtom class in Core/Ap4HdlrAtom.cpp in Bento4 version 1.5.0-617 uses an incorrect character data type, leading to a heap-based buffer over… Bento4 Patch available Fix from $1,6002017-09-21