Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Android HIGH 10.0
CVE-2015-1539EPSS 86%

Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remote attacke…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2015-1538EPSS 99%

Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allows remot…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 8.5
CVE-2015-1536

Integer overflow in the Bitmap_createFromParcel function in core/jni/android/graphics/Bitmap.cpp in Android before 5.1.1 LMY48I allows attackers to c…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-1528

Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a differ…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2014-7917

Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342615.

Fix: after 4.4.4
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2014-7916

Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15342751.

Fix: after 4.4.4
Fix from $1,950 2015-10-01
Android HIGH 10.0
CVE-2014-7915

Integer overflow in SampleTable.cpp in libstagefright in Android before 5.0.0 has unspecified impact and attack vectors, aka internal bug 15328708.

Fix: after 4.4.4
Fix from $1,950 2015-10-01
Freeimage MEDIUM 5.0
CVE-2015-0852

Multiple integer underflows in PluginPCX.cpp in FreeImage 3.17.0 and earlier allow remote attackers to cause a denial of service (heap memory corrupt…

Fix: after 3.17.0
Fix from $1,600 2015-09-29
Ffmpeg HIGH 7.5
CVE-2015-6819

Multiple integer underflows in the ff_mjpeg_decode_frame function in libavcodec/mjpegdec.c in FFmpeg before 2.7.2 allow remote attackers to cause a d…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Debian Linux HIGH 7.5
CVE-2015-6525

Multiple integer overflows in the evbuffer API in Libevent 2.0.x before 2.0.22 and 2.1.x before 2.1.5-beta allow context-dependent attackers to cause…

Mitigation only
Fix from $1,950 2015-08-24
Debian Linux HIGH 7.5
CVE-2014-6272

Multiple integer overflows in the evbuffer API in Libevent 1.4.x before 1.4.15, 2.0.x before 2.0.22, and 2.1.x before 2.1.5-beta allow context-depend…

Mitigation only
Fix from $1,950 2015-08-24
Mac Os X HIGH 9.3
CVE-2015-3768

Integer overflow in the kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context v…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Perl HIGH 7.5
CVE-2013-7422

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to ex…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Firefox HIGH 9.3
CVE-2015-4496

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metad…

Fix: after 37.0.2
Fix from $1,950 2015-08-16
Ubuntu Linux MEDIUM 6.8
CVE-2015-4491EPSS 8%

Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox…

Fix: after 2.31.4
Fix from $1,600 2015-08-16
Ubuntu Linux HIGH 9.3
CVE-2015-4480EPSS 6%

Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 …

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Firefox HIGH 10.0
CVE-2015-4479EPSS 9%

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitr…

Fix: after 39.0.3
Fix from $1,950 2015-08-16
Office HIGH 9.3
CVE-2015-2470EPSS 27%

Integer underflow in Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office for Mac 2011, and Word Viewer allows rem…

No fix yet
Fix from $1,950 2015-08-15
Flash Player HIGH 10.0
CVE-2015-5560EPSS 66%

Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR…

Fix: after 18.0.0.209
Fix from $1,950 2015-08-14
Xmltooling MEDIUM 5.0
CVE-2015-0851

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which …

Fix: after 1.5.4
Fix from $1,600 2015-08-12
Afpl Ghostscript MEDIUM 6.8
CVE-2015-3228

Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of …

Fix: after 9.15
Fix from $1,600 2015-08-11
Firefox Os MEDIUM 5.0
CVE-2015-5962

Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics…

Fix: after 2.1.0
Fix from $1,600 2015-08-08
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2015-1279

Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allow…

Fix: after 43.0.2357.134
Fix from $1,950 2015-07-23
Ubuntu Linux HIGH 7.5
CVE-2015-3279EPSS 7%

Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or pos…

Fix: after 1.0.70
Fix from $1,950 2015-07-14
Photoshop Cc HIGH 10.0
CVE-2015-3110EPSS 17%

Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to execute arbitrary code via unsp…

Fix: after 15.2.2
Fix from $1,950 2015-06-24
Libmspack MEDIUM 6.8
CVE-2015-4472

Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) …

Fix: after 0.4-3
Fix from $1,600 2015-06-11
Air HIGH 10.0
CVE-2015-3104EPSS 6%

Integer overflow in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux…

Fix: after 17.0.0.172
Fix from $1,950 2015-06-10
Enterprise Linux Desktop HIGH 7.5
CVE-2015-4022EPSS 21%

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP ser…

Fix: after 5.4.40
Fix from $1,950 2015-06-09
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-4021EPSS 21%

The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first ch…

Fix: after 5.4.40
Fix from $1,600 2015-06-09
Linux Kernel HIGH 7.8
CVE-2015-4003EPSS 6%

The oz_usb_handle_ep_data function in drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attacke…

Fix: 3.4.109 / 3.10.81+
Fix from $1,950 2015-06-07