Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Autotrace MEDIUM 6.8
CVE-2013-1953

Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impac…

Mitigation only
Fix from $1,600 2013-12-09
Ffmpeg HIGH 9.3
CVE-2013-0859

The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or z…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0844

Off-by-one error in the adpcm_decode_frame function in libavcodec/adpcm.c in FFmpeg before 1.0.4 allows remote attackers to have an unspecified impac…

Fix: after 1.0.3
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0853

The wavpack_decode_frame function in libavcodec/wavpack.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted WavP…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0855

Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact vi…

Fix: after 1.0
Fix from $1,950 2013-12-07
Ffmpeg HIGH 9.3
CVE-2013-0862

Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecifie…

Fix: after 1.1.1
Fix from $1,950 2013-11-23
Ffmpeg HIGH 10.0
CVE-2013-0864

The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows rem…

Fix: after 1.1.1
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0875

The ff_add_png_paeth_prediction function in libavcodec/pngdec.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via a cr…

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Ffmpeg HIGH 9.3
CVE-2013-0876

Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to…

Fix: after 1.1.2
Fix from $1,950 2013-11-23
Firefox HIGH 7.5
CVE-2013-5607

Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefo…

Fix: after 4.10.1
Fix from $1,950 2013-11-20
Gnutls MEDIUM 5.0
CVE-2013-4487

Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cau…

Patch available
Fix from $1,600 2013-11-20
Linux Kernel HIGH 7.1
CVE-2013-4563

The udp6_ufo_fragment function in net/ipv6/udp_offload.c in the Linux kernel through 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not …

Fix: 3.12.4+
Fix from $1,950 2013-11-20
Chrome MEDIUM 5.0
CVE-2013-6630

The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all …

Fix: after 31.0.1650.47
Fix from $1,600 2013-11-19
Network Security Services HIGH 7.5
CVE-2013-1741

Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have …

Mitigation only
Fix from $1,950 2013-11-18
Chrome HIGH 9.3
CVE-2013-6632EPSS 6%

Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupti…

Fix: 31.0.1650.57+
Fix from $1,950 2013-11-18
Linux Kernel MEDIUM 6.9
CVE-2013-4511

Multiple integer overflows in Alchemy LCD frame-buffer drivers in the Linux kernel before 3.12 allow local users to create a read-write memory mappin…

Fix: 3.2.53 / 3.4.69+
Fix from $1,600 2013-11-12
Chrony MEDIUM 5.0
CVE-2012-4502

Multiple integer overflows in pktlength.c in Chrony before 1.29 allow remote attackers to cause a denial of service (crash) via a crafted (1) REQ_SUB…

Fix: after 1.28
Fix from $1,600 2013-11-05
Dropbear Ssh MEDIUM 5.0
CVE-2013-4421EPSS 6%

The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumptio…

Fix: 2013.59+
Fix from $1,600 2013-10-25
Dropbear Ssh MEDIUM 5.0
CVE-2013-4434EPSS 6%

Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user accou…

Fix: 2013.59+
Fix from $1,600 2013-10-25
Mac Os X HIGH 7.1
CVE-2013-5172

The kernel in Apple Mac OS X before 10.9 does not properly determine the output length for SHA-2 digest function calls, which allows context-dependen…

Fix: after 10.8.5
Fix from $1,950 2013-10-24
Enterprise Linux MEDIUM 6.8
CVE-2013-4397EPSS 5%

Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash)…

Fix: after 1.2.19
Fix from $1,600 2013-10-17
Linux Kernel MEDIUM 5.8
CVE-2013-4345

Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attac…

Fix: after 3.11.4
Fix from $1,600 2013-10-10
Glibc HIGH 7.5
CVE-2012-4412EPSS 17%

Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denia…

Fix: after 2.17
Fix from $1,950 2013-10-09
Ubuntu Linux MEDIUM 5.0
CVE-2013-0211

Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64…

Fix: after 3.1.2
Fix from $1,600 2013-09-30
Proftpd MEDIUM 5.0
CVE-2013-4359

Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via …

Patch available
Fix from $1,600 2013-09-30
Iphone Os HIGH 7.1
CVE-2013-5141

The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to cause a denial of service (inf…

Fix: after 6.1.4
Fix from $1,950 2013-09-19
Scalance X 200 Series Firmware HIGH 8.3
CVE-2013-5709

The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of…

Fix: after 4.4
Fix from $1,950 2013-09-17
Debian Linux MEDIUM 6.8
CVE-2013-4233

Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service…

Fix: after 0.8.8.4
Fix from $1,600 2013-09-16
Acrobat HIGH 10.0
CVE-2013-3357EPSS 13%

Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code…

Patch available
Fix from $1,950 2013-09-12
Acrobat HIGH 10.0
CVE-2013-3358EPSS 13%

Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code…

Patch available
Fix from $1,950 2013-09-12