Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 6.5 CVE-2017-13134 In ImageMagick 7.0.6-6 and GraphicsMagick 1.3.26, a heap-based buffer over-read was found in the function SFWScan in coders/sfw.c, which allows attac… Imagemagick Patch available Fix from $1,6002017-08-23 MEDIUM 6.5 CVE-2017-12967 The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attacker… Binutils Patch available Fix from $1,6002017-08-19 MEDIUM 6.5 CVE-2017-12956 There is an illegal address access in Exiv2::FileIo::path[abi:cxx11]() in basicio.cpp of libexiv2 in Exiv2 0.26 that will lead to remote denial of se… Exiv2 Mitigation only Fix from $1,6002017-08-18 MEDIUM 6.5 CVE-2017-12957 There is a heap-based buffer over-read in libexiv2 in Exiv2 0.26 that is triggered in the Exiv2::Image::io function in image.cpp. It will lead to rem… Exiv2 Mitigation only Fix from $1,6002017-08-18 HIGH 7.5 CVE-2017-12958 There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to … Pspp Mitigation only Fix from $1,9502017-08-18 HIGH 7.5 CVE-2017-12963 There is an illegal address access in Sass::Eval::operator() in eval.cpp of LibSass 3.4.5, leading to a remote denial of service attack. NOTE: this i… Libsass Mitigation only Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-8256 In all Qualcomm products with Android releases from CAF using the Linux kernel, array out of bounds access can occur if userspace sends more than 16 … Android Patch available Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-8268 In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer proc… Android Mitigation only Fix from $1,9502017-08-18 CRITICAL 9.8 CVE-2015-9050 In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists where an array out of bounds access can occur … Android No fix yet Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2017-12940 libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function. Unrar after 5.5.6 Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2017-12941 libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the Unpack::Unpack20 function. Unrar after 5.5.6 Fix from $2,3002017-08-18 HIGH 7.5 CVE-2017-9454 Buffer overflow in the ares_parse_a_reply function in the embedded ares library in ReSIProcate before 1.12.0 allows remote attackers to cause a denia… Resiprocate after 1.10.2 Fix from $1,9502017-08-18 HIGH 8.8 CVE-2017-12935 The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColo… Debian Linux Patch available Fix from $1,9502017-08-18 HIGH 8.8 CVE-2017-12937 The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read. Debian Linux Patch available Fix from $1,9502017-08-18 CRITICAL 9.8 CVE-2017-12933EPSS 6% The finish_nested_data function in ext/standard/var_unserializer.re in PHP before 5.6.31, 7.0.x before 7.0.21, and 7.1.x before 7.1.7 is prone to a b… PHP after 5.6.30 Fix from $2,3002017-08-18 HIGH 7.5 CVE-2017-11661EPSS 9% The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) v… Wildmidi No fix yet Fix from $1,9502017-08-17 HIGH 7.5 CVE-2017-11662EPSS 8% The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) via a crafted m… Wildmidi No fix yet Fix from $1,9502017-08-17 MEDIUM 6.5 CVE-2017-11663EPSS 5% The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) v… Wildmidi No fix yet Fix from $1,6002017-08-17 MEDIUM 6.5 CVE-2017-11664EPSS 8% The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and application crash) v… Wildmidi Patch available Fix from $1,6002017-08-17 MEDIUM 6.5 CVE-2017-12441 The row_is_empty function in base/4bitmap.c:274 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a craft… Minidjvu Mitigation only Fix from $1,6002017-08-17 MEDIUM 6.5 CVE-2017-12442 The row_is_empty function in base/4bitmap.c:272 in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a craft… Minidjvu Mitigation only Fix from $1,6002017-08-17 MEDIUM 6.5 CVE-2017-12443 The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a … Minidjvu Mitigation only Fix from $1,6002017-08-17 MEDIUM 6.5 CVE-2017-12444 The mdjvu_bitmap_get_bounding_box function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash… Minidjvu Mitigation only Fix from $1,6002017-08-17 MEDIUM 6.5 CVE-2017-12445 The JB2BitmapCoder::code_row_by_refinement function in jb2/bmpcoder.cpp in minidjvu 0.8 can cause a denial of service (invalid memory read and applic… Minidjvu Mitigation only Fix from $1,6002017-08-17 MEDIUM 5.5 CVE-2017-8258 An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver. Android Patch available Fix from $1,6002017-08-11 MEDIUM 5.5 CVE-2017-0725 A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194. Android Patch available Fix from $1,6002017-08-09 HIGH 8.8 CVE-2017-12640 ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c. Debian Linux Patch available Fix from $1,9502017-08-07 MEDIUM 5.5 CVE-2017-6418 libclamav/message.c in ClamAV 0.99.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted e-mail message. Clamav Patch available Fix from $1,6002017-08-07 HIGH 7.8 CVE-2017-12596 In OpenEXR 2.2.0, a crafted image causes a heap-based buffer over-read in the hufDecode function in IlmImf/ImfHuf.cpp during exrmaketiled execution; … Openexr No fix yet Fix from $1,9502017-08-07 HIGH 8.8 CVE-2017-12598 OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcod… Debian Linux after 3.3.0 Fix from $1,9502017-08-07