Vulnerability index

Browse CVEs

8,456 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
MEDIUM 5.5 CVE-2017-8312 Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a craft… Debian Linux 2.2.6+ Fix from $1,6002017-05-23 MEDIUM 5.5 CVE-2017-8313 Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attackers to read data beyond alloc… Vlc Media Player after 2.2.4 Fix from $1,6002017-05-23 CRITICAL 9.8 CVE-2017-9193 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:538:33. Autotrace Mitigation only Fix from $2,3002017-05-23 CRITICAL 9.8 CVE-2017-9194 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29. Autotrace Mitigation only Fix from $2,3002017-05-23 CRITICAL 9.8 CVE-2017-9195 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:620:27. Autotrace Mitigation only Fix from $2,3002017-05-23 MEDIUM 6.5 CVE-2017-9204 The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service … Imageworsener Patch available Fix from $1,6002017-05-23 MEDIUM 6.5 CVE-2017-9205 The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service … Imageworsener Patch available Fix from $1,6002017-05-23 MEDIUM 6.5 CVE-2017-9206 The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service … Imageworsener Patch available Fix from $1,6002017-05-23 MEDIUM 6.5 CVE-2017-9207 The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service … Imageworsener Patch available Fix from $1,6002017-05-23 CRITICAL 9.8 CVE-2017-9166 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:18:11. Autotrace Mitigation only Fix from $2,3002017-05-23 CRITICAL 9.8 CVE-2017-9171 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-bmp.c:492:24. Autotrace Mitigation only Fix from $2,3002017-05-23 HIGH 7.5 CVE-2017-9174 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in… Autotrace Mitigation only Fix from $1,9502017-05-23 HIGH 7.5 CVE-2017-9177 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in… Autotrace Mitigation only Fix from $1,9502017-05-23 HIGH 7.5 CVE-2017-9179 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in… Autotrace Mitigation only Fix from $1,9502017-05-23 HIGH 7.5 CVE-2017-9180 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in… Autotrace Mitigation only Fix from $1,9502017-05-23 HIGH 7.5 CVE-2017-9189 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLO… Autotrace Mitigation only Fix from $1,9502017-05-23 CRITICAL 9.8 CVE-2017-9152 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the pnm_load_raw function in input-pnm.c:346:41. Autotrace Mitigation only Fix from $2,3002017-05-23 HIGH 7.5 CVE-2017-9154 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the GET_COLOR function in… Autotrace Mitigation only Fix from $1,9502017-05-23 HIGH 7.5 CVE-2017-9155 libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the input_pnm_reader func… Autotrace Mitigation only Fix from $1,9502017-05-23 CRITICAL 9.8 CVE-2017-9164 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:16:11. Autotrace Mitigation only Fix from $2,3002017-05-23 CRITICAL 9.8 CVE-2017-9165 libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the GET_COLOR function in color.c:17:11. Autotrace Mitigation only Fix from $2,3002017-05-23 MEDIUM 6.5 CVE-2017-9147EPSS 7% LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cause a denial of service (crash… Libtiff No fix yet Fix from $1,6002017-05-22 HIGH 7.8 CVE-2017-9074 The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be associated with an invalid o… Linux Kernel 3.2.89 / 3.16.44+ Fix from $1,9502017-05-19 HIGH 7.5 CVE-2017-9049 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function in dict.c. This vulnerabilit… Libxml2 Patch available Fix from $1,9502017-05-18 HIGH 7.5 CVE-2017-9050 libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in dict.c. This vulnerability cau… Libxml2 Patch available Fix from $1,9502017-05-18 CRITICAL 9.8 CVE-2017-9052 An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure t… Libdwarf Mitigation only Fix from $2,3002017-05-18 CRITICAL 9.1 CVE-2017-9053 An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a f… Libdwarf Mitigation only Fix from $2,3002017-05-18 CRITICAL 9.8 CVE-2017-9054 An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just bef… Libdwarf Mitigation only Fix from $2,3002017-05-18 CRITICAL 9.8 CVE-2017-9055 An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in boun… Libdwarf Mitigation only Fix from $2,3002017-05-18 CRITICAL 9.8 CVE-2017-9058 In libytnef in ytnef through 1.9.2, there is a heap-based buffer over-read due to incorrect boundary checking in the SIZECHECK macro in lib/ytnef.c. Ubuntu Linux after 1.9.2 Fix from $2,3002017-05-18