Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Firefox MEDIUM 5.0
CVE-2015-7219

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, …

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora MEDIUM 5.0
CVE-2015-7218

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, …

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora MEDIUM 6.8
CVE-2015-7213

Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR …

Fix: after 42.0
Fix from $1,600 2015-12-16
Fedora HIGH 7.5
CVE-2015-7212

Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before …

Fix: after 42.0
Fix from $1,950 2015-12-16
Fedora HIGH 10.0
CVE-2015-7205

Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote…

Fix: after 42.0
Fix from $1,950 2015-12-16
Design Review MEDIUM 6.8
CVE-2015-8571

Integer overflow in Autodesk Design Review (ADR) before 2013 Hotfix 2 allows remote attackers to execute arbitrary code via a crafted biClrUsed value…

Mitigation only
Fix from $1,600 2015-12-15
PHP MEDIUM 6.8
CVE-2015-7804EPSS 9%

Off-by-one error in the phar_parse_zipfile function in ext/phar/zip.c in PHP before 5.5.30 and 5.6.x before 5.6.14 allows remote attackers to cause a…

Fix: after 10.11.1
Fix from $1,600 2015-12-11
Air Sdk HIGH 9.3
CVE-2015-8445EPSS 7%

Integer overflow in the Shader filter implementation in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X …

Fix: after 19.0.0.241
Fix from $1,950 2015-12-10
Chrome HIGH 7.5
CVE-2015-6781

Integer overflow in the FontData::Bound function in data/font_data.cc in Google sfntly, as used in Google Chrome before 47.0.2526.73, allows remote a…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Leap HIGH 7.5
CVE-2015-8078

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…

Mitigation only
Fix from $1,950 2015-12-03
Imap HIGH 7.5
CVE-2015-8077

Integer overflow in the index_urlfetch function in imap/index.c in Cyrus IMAP 2.3.19, 2.4.18, and 2.5.6 allows remote attackers to have unspecified i…

Mitigation only
Fix from $1,950 2015-12-03
Ubuntu Linux HIGH 7.5
CVE-2015-0860EPSS 5%

Off-by-one error in the extracthalf function in dpkg-deb/extract.c in the dpkg-deb component in Debian dpkg 1.16.x before 1.16.17 and 1.17.x before 1…

Mitigation only
Fix from $1,950 2015-12-03
Ubuntu Linux MEDIUM 6.8
CVE-2015-8364

Integer overflow in the ff_ivi_init_planes function in libavcodec/ivi.c in FFmpeg before 2.6.5, 2.7.x before 2.7.3, and 2.8.x through 2.8.2 allows re…

Mitigation only
Fix from $1,600 2015-11-26
Ubuntu Linux MEDIUM 6.6
CVE-2015-7869

Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.8…

Fix: 304.131 / 340.96+
Fix from $1,600 2015-11-24
Picasa HIGH 10.0
CVE-2015-8221

Integer overflow in Google Picasa before 3.9.140 Build 259 allows remote attackers to execute arbitrary code via the CAMF section in a FOVb image, wh…

Fix: after 3.9.140
Fix from $1,950 2015-11-17
Ubuntu Linux MEDIUM 6.8
CVE-2015-5213EPSS 13%

Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corrupti…

Fix: after 4.4.4
Fix from $1,600 2015-11-10
Picasa HIGH 10.0
CVE-2015-8096

Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related t…

Mitigation only
Fix from $1,950 2015-11-09
Wpa Supplicant MEDIUM 5.0
CVE-2015-8041

Multiple integer overflows in the NDEF record parser in hostapd before 2.5 and wpa_supplicant before 2.5 allow remote attackers to cause a denial of …

Fix: after 2.4
Fix from $1,600 2015-11-09
Firefox HIGH 7.5
CVE-2015-7183EPSS 7%

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2…

Fix: after 41.0.2
Fix from $1,950 2015-11-05
Ubuntu Linux MEDIUM 6.8
CVE-2015-7674EPSS 6%

Integer overflow in the pixops_scale_nearest function in pixops/pixops.c in gdk-pixbuf before 2.32.1 allows remote attackers to cause a denial of ser…

Fix: after 2.32.0
Fix from $1,600 2015-10-26
Android HIGH 10.0
CVE-2015-6575

SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I does not properly consider integer promotion, which allows remote attackers to execu…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3864EPSS 87%

Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 LMY48M al…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3863

Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 5.0
CVE-2015-3861

Multiple integer overflows in the addVorbisCodecInfo function in matroska/MatroskaExtractor.cpp in libstagefright in mediaserver in Android before 5.…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 10.0
CVE-2015-3836

The Parse_wave function in arm-wt-22k/lib_src/eas_mdls.c in the Sonivox DLS-to-EAS converter in Android before 5.1.1 LMY48I does not reject a negativ…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3834

Multiple integer overflows in the BnHDCP::onTransact function in media/libmedia/IHDCP.cpp in libstagefright in Android before 5.1.1 LMY48I allow atta…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3829EPSS 90%

Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows remote atta…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-3828EPSS 85%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3827EPSS 81%

The MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not validate the relationship bet…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 5.0
CVE-2015-3826EPSS 74%

The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size…

Fix: after 5.1
Fix from $1,600 2015-10-01