Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Android HIGH 7.8
CVE-2014-9787

Integer overflow in drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices allows attackers to gain…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Norton Security CRITICAL 9.8
CVE-2016-3645EPSS 25%

Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:…

Fix: after 2016.0
Fix from $2,300 2016-06-30
Qemu HIGH 7.1
CVE-2016-2538

Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a …

Fix: after 2.5.0
Fix from $1,950 2016-06-16
Ubuntu Linux HIGH 7.5
CVE-2016-4574

Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of serv…

Fix: after 1.3.3
Fix from $1,950 2016-06-13
Android HIGH 8.4
CVE-2016-2463

Multiple integer overflows in the h264dec component in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.…

Mitigation only
Fix from $1,950 2016-06-13
Ubuntu Linux MEDIUM 6.2
CVE-2015-8872

The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memo…

Fix: after 3.0.28
Fix from $1,600 2016-06-03
Debian Linux HIGH 7.8
CVE-2015-8875

Multiple integer overflows in the (1) pixops_composite_nearest, (2) pixops_composite_color_nearest, and (3) pixops_process functions in pixops/pixops…

Fix: after 2.33
Fix from $1,950 2016-06-01
Debian Linux HIGH 7.8
CVE-2015-8312

Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) vi…

Fix: after 1.6.15
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9763

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2011-5326

imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

Fix: after 1.4.8
Fix from $1,950 2016-05-13
OpenSSL HIGH 7.5
CVE-2016-2106EPSS 27%

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers t…

Fix: after 1.0.1s
Fix from $1,950 2016-05-05
Linux Kernel HIGH 7.5
CVE-2016-2070

The tcp_cwnd_reduction function in net/ipv4/tcp_input.c in the Linux kernel before 4.3.5 allows remote attackers to cause a denial of service (divide…

Fix: 4.3.5+
Fix from $1,950 2016-05-02
Linux Kernel HIGH 7.8
CVE-2016-3135

Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32-bit platforms allows local u…

Fix: 4.4.21 / 4.6+
Fix from $1,950 2016-04-27
Ubuntu Linux CRITICAL 9.1
CVE-2015-8776

The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (applicat…

Mitigation only
Fix from $2,300 2016-04-19
Ubuntu MEDIUM 6.5
CVE-2015-5479

The ff_h263_decode_mba function in libavcodec/ituh263dec.c in Libav before 11.5 allows remote attackers to cause a denial of service (divide-by-zero …

Fix: after 11.4
Fix from $1,600 2016-04-19
Android HIGH 8.4
CVE-2016-0849

Multiple integer overflows in minzip/SysUtil.c in the Recovery Procedure in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01…

Patch available
Fix from $1,950 2016-04-18
Enterprise Linux Desktop Supplementary HIGH 8.8
CVE-2015-8540EPSS 6%

Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.…

Patch available
Fix from $1,950 2016-04-14
Ubuntu Linux CRITICAL 9.8
CVE-2014-9766EPSS 6%

Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (app…

Fix: after 0.32.5
Fix from $2,300 2016-04-13
Firefox HIGH 8.8
CVE-2016-1968

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Android HIGH 7.8
CVE-2016-0827

Multiple integer overflows in libeffects in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allow attacke…

Mitigation only
Fix from $1,950 2016-03-12
Firefox CRITICAL 9.8
CVE-2016-1946EPSS 6%

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operatio…

Fix: after 43.0.4
Fix from $2,300 2016-01-31
Firefox MEDIUM 6.5
CVE-2016-1933

Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
PHP HIGH 7.3
CVE-2016-1904

Multiple integer overflows in ext/standard/exec.c in PHP 7.x before 7.0.2 allow remote attackers to cause a denial of service or possibly have unspec…

Patch available
Fix from $1,950 2016-01-19
Webaccess CRITICAL 9.8
CVE-2016-0859EPSS 8%

Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of servi…

Fix: after 8.0
Fix from $2,300 2016-01-15
Windows MEDIUM 6.6
CVE-2016-1715

The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before b…

Patch available
Fix from $1,600 2016-01-12
Grassroots Dicom CRITICAL 10.0
CVE-2015-8396EPSS 16%

Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GD…

Fix: after 2.6.0
Fix from $2,300 2016-01-12
Subversion HIGH 8.6
CVE-2015-5259EPSS 57%

Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute ar…

Mitigation only
Fix from $1,950 2016-01-08
Samba MEDIUM 5.3
CVE-2015-3223EPSS 7%

The ldb_wildcard_compare function in ldb_match.c in ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, …

Mitigation only
Fix from $1,600 2015-12-29
Chrome HIGH 8.8
CVE-2015-8664EPSS 5%

Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 47.0.2526.106 allows remote at…

Fix: after 47.0.2526.80
Fix from $1,950 2015-12-24
Firefox MEDIUM 6.8
CVE-2015-7222

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5…

Fix: after 42.0
Fix from $1,600 2015-12-16