Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2016-6161
The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) …
Debian Linux
after 2.2.2
MEDIUM 6.5
CVE-2016-6132
The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of…
Debian Linux
after 2.2.2
HIGH 7.8
CVE-2016-2064
sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) …
Linux Kernel
after 3.19.8
MEDIUM 5.9
CVE-2016-5352
epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to c…
Wireshark
Patch available
HIGH 7.6
CVE-2013-7456EPSS 6%
gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allo…
Libgd
Patch available
HIGH 7.8
CVE-2016-3855
drivers/thermal/supply_lm_core.c in the Qualcomm components in Android before 2016-08-05 does not validate a certain count parameter, which allows at…
Android
after 6.0.1
HIGH 7.8
CVE-2016-3854
drivers/media/video/msm/msm_mctl_buf.c in the Qualcomm components in Android before 2016-08-05 does not validate the image mode, which allows attacke…
Android
after 6.0.1
HIGH 7.8
CVE-2016-1513EPSS 8%
The Impress tool in Apache OpenOffice 4.1.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read or write) or execute…
Openoffice
after 4.1.2
HIGH 7.5
CVE-2016-2180EPSS 28%
The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL throug…
OpenSSL
Patch available
MEDIUM 6.3
CVE-2016-4652
CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or …
Mac Os X
after 10.11.5
MEDIUM 5.5
CVE-2016-4628
IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause…
Iphone Os
after 9.3.2
HIGH 7.5
CVE-2016-4523 KEVEPSS 31%
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bo…
Vtscada
11.2.02+
MEDIUM 5.5
CVE-2016-1839EPSS 13%
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before …
Ubuntu Linux
Patch available
MEDIUM 5.5
CVE-2016-1838EPSS 12%
The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, an…
Ubuntu Linux
Patch available
MEDIUM 5.5
CVE-2016-1833
The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2…
Debian Linux
Patch available
HIGH 7.8
CVE-2016-1823EPSS 10%
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows att…
Tvos
2.2.1 / 9.2.1+
MEDIUM 6.5
CVE-2016-2291
Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers …
Proface Gp Pro Ex Ex Ed
after 4.0.4
HIGH 8.8
CVE-2016-1646 KEVEPSS 48%
The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider elem…
Debian Linux
49.0.2623.108+
MEDIUM 5.3
CVE-2015-8629
The xdr_nullstring function in lib/kadm5/kadm_rpc_xdr.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13.4 and 1.14.x before 1.14.1 does not verif…
Linux
Patch available
MEDIUM 6.5
CVE-2015-8783
tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.
Debian Linux
4.0.7+
HIGH 8.2
CVE-2015-8397
The JPEGLSCodec::DecodeExtent function in MediaStorageAndFileFormat/gdcmJPEGLSCodec.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows remote att…
Grassroots Dicom
2.6.2+
MEDIUM 6.8
CVE-2014-9669
Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memor…
Ubuntu Linux
Patch available
HIGH 7.5
CVE-2014-9658EPSS 5%
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to…
Ubuntu Linux
Patch available
HIGH 7.5
CVE-2014-9657EPSS 5%
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers…
Enterprise Linux Desktop
Patch available
HIGH 7.8
CVE-2014-7825
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, w…
Linux Kernel
3.2.65 / 3.4.106+
MEDIUM 5.0
CVE-2014-8483
The blowfishECB function in core/cipher.cpp in Quassel IRC 0.10.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a mal…
Ubuntu Linux
Patch available
MEDIUM 5.0
CVE-2014-3675
Shim allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted DHCPv6 packet.
Shim
0.8+
MEDIUM 5.0
CVE-2014-4341EPSS 7%
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting in…
Enterprise Linux Desktop
Patch available
HIGH 9.3
CVE-2014-1522EPSS 5%
The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 al…
Fedora
2.26 / 29.0+
HIGH 7.8
CVE-2014-0777
The Modbus slave/outstation driver in the OPC Drivers 1.0.20 and earlier in IOServer OPC Server allows remote attackers to cause a denial of service …
Ioserver Opc Server
after 1.0.20