Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Ubuntu Linux CRITICAL 9.8
CVE-2016-10714

In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters.

Fix: 5.3+
Fix from $2,300 2018-02-27
Pngcrush HIGH 7.8
CVE-2015-2158

Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (…

Fix: after 1.7.83
Fix from $1,950 2017-10-06
Fedora CRITICAL 9.8
CVE-2016-9961

game-music-emu before 0.6.1 mishandles unspecified integer values.

Fix: after 0.6.0
Fix from $2,300 2017-06-06
Android HIGH 7.8
CVE-2014-9924

In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.

Patch available
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2015-9002

In TrustZone an out-of-range pointer offset vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux ker…

Patch available
Fix from $1,950 2017-05-16
Imagemagick MEDIUM 6.5
CVE-2016-7513

Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.

Fix: 6.9.4-0+
Fix from $1,600 2017-04-20
Imagemagick CRITICAL 9.8
CVE-2016-10145EPSS 5%

Off-by-one error in coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via vectors related to a string copy.

Fix: 6.9.7-1+
Fix from $2,300 2017-03-24
Libming MEDIUM 6.5
CVE-2016-9266

listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.

Mitigation only
Fix from $1,600 2017-03-23
Imagemagick MEDIUM 5.5
CVE-2014-9915

Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.

Fix: after 6.6.0-3
Fix from $1,600 2017-03-23
OpenBSD HIGH 7.8
CVE-2016-6240

Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with kernel privileges via a …

No fix yet
Fix from $1,950 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6242

OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ident value in a kevent system c…

No fix yet
Fix from $1,600 2017-03-07
Libtiff HIGH 7.8
CVE-2016-10094

Off-by-one error in the t2p_readwrite_pdf_image_tile function in tools/tiff2pdf.c in LibTIFF 4.0.7 allows remote attackers to have unspecified impact…

Patch available
Fix from $1,950 2017-03-01
Libav MEDIUM 5.5
CVE-2016-9819

libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative valu…

No fix yet
Fix from $1,600 2017-03-01
Libav MEDIUM 5.5
CVE-2016-9820

libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negati…

No fix yet
Fix from $1,600 2017-03-01
Libav MEDIUM 5.5
CVE-2016-9825

libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.

No fix yet
Fix from $1,600 2017-03-01
Libav MEDIUM 5.5
CVE-2016-9826

libavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative val…

No fix yet
Fix from $1,600 2017-03-01
Debian Linux MEDIUM 5.5
CVE-2016-5241

magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via…

Fix: after 1.3.23
Fix from $1,600 2017-02-03
PHP HIGH 7.5
CVE-2016-10158EPSS 8%

The exif_convert_any_to_int function in ext/exif/exif.c in PHP before 5.6.30, 7.0.x before 7.0.15, and 7.1.x before 7.1.1 allows remote attackers to …

Fix: after 5.6.29
Fix from $1,950 2017-01-24
Libtiff CRITICAL 9.1
CVE-2016-6223

The TIFFReadRawStrip1 and TIFFReadRawTile1 functions in tif_read.c in libtiff before 4.0.7 allows remote attackers to cause a denial of service (cras…

Fix: after 4.0.6
Fix from $2,300 2017-01-23
C2box HIGH 7.5
CVE-2015-4626

B.A.S C2Box before 4.0.0 (r19171) relies on client-side validation, which allows remote attackers to "corrupt the business logic" via a negative valu…

Fix: after 4.0.0
Fix from $1,950 2017-01-23
OpenSSL HIGH 7.5
CVE-2016-2181EPSS 23%

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large seq…

Mitigation only
Fix from $1,950 2016-09-16
Wireshark MEDIUM 5.9
CVE-2016-6510

Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers…

Mitigation only
Fix from $1,600 2016-08-06
Android HIGH 7.8
CVE-2014-9876

drivers/char/diag/diagfwd.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices mishandles certain in…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2016-2507

Integer overflow in codecs/on2/h264dec/source/h264bsd_storage.c in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2015-8891

Multiple integer overflows in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allow attacke…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2015-8888

Integer overflow in app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to bypass intended …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9801

Multiple integer overflows in lib/libfdt/fdt_rw.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allow attackers to gain …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9800

Integer overflow in lib/heap/heap.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices allows attackers to gain …

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9795

app/aboot/aboot.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices does not properly check for an integer overflow, which a…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2014-9792

arch/arm/mach-msm/ipc_router.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices uses an incorrect integer data type, which …

Fix: after 6.0.1
Fix from $1,950 2016-07-11