Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Linux Kernel HIGH 9.0
CVE-2015-4001EPSS 7%

Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5…

Fix: after 4.0.5
Fix from $1,950 2015-06-07
Netvault Backup HIGH 10.0
CVE-2015-4067EPSS 6%

Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template st…

Mitigation only
Fix from $1,950 2015-05-29
Wireshark MEDIUM 5.0
CVE-2015-3814

The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.…

Mitigation only
Fix from $1,600 2015-05-26
Wireshark HIGH 7.8
CVE-2015-3809

The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not properly track the c…

Mitigation only
Fix from $1,950 2015-05-26
Wireshark HIGH 7.8
CVE-2015-3808

The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not reject a zero length…

No fix yet
Fix from $1,950 2015-05-26
Mac Os X HIGH 7.5
CVE-2014-8147EPSS 23%

The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for U…

Fix: 55.1+
Fix from $1,950 2015-05-25
Debian Linux HIGH 7.5
CVE-2015-1258

Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to t…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Hanword Viewer 2007 HIGH 7.5
CVE-2015-2810

Integer overflow in the HwpApp::CHncSDS_Manager function in Hancom Office HanWord processor, as used in Hwp 2014 VP before 9.1.0.2342, HanWord Viewer…

Fix: after 9.1.0.2342
Fix from $1,950 2015-05-15
Firefox MEDIUM 6.8
CVE-2015-2717

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (hea…

Fix: after 37.0.2
Fix from $1,600 2015-05-14
Air HIGH 10.0
CVE-2015-3087EPSS 74%

Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux…

Fix: after 17.0.0.144
Fix from $1,950 2015-05-13
Domino HIGH 10.0
CVE-2015-0135EPSS 42%

IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (inte…

Patch available
Fix from $1,950 2015-04-21
Ubuntu Linux HIGH 7.5
CVE-2013-7439

Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote at…

Patch available
Fix from $1,950 2015-04-16
Xcode HIGH 7.5
CVE-2015-1149

Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have…

Fix: after 6.2
Fix from $1,950 2015-04-10
PHP HIGH 7.5
CVE-2015-2331EPSS 28%

Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x…

Fix: after 5.4.38
Fix from $1,950 2015-03-30
Fedora MEDIUM 5.0
CVE-2015-0295EPSS 6%

The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers t…

Fix: after 5.4.1
Fix from $1,600 2015-03-25
Tcpdump HIGH 7.5
CVE-2015-0261EPSS 7%

Integer signedness error in the mobility_opt_print function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a d…

Fix: after 4.7.0
Fix from $1,950 2015-03-24
Libxfont HIGH 8.5
CVE-2015-1804

The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x before 1.5.1 does not properly perform type conversion fo…

Fix: after 1.4.8
Fix from $1,950 2015-03-20
Mac Os X HIGH 10.0
CVE-2015-1066

Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafte…

Fix: after 10.10.2
Fix from $1,950 2015-03-12
Chrome HIGH 7.5
CVE-2015-1219

Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, al…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Wireshark MEDIUM 5.0
CVE-2015-2192

Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark 1.12.x bef…

Mitigation only
Fix from $1,600 2015-03-08
Debian Linux MEDIUM 5.0
CVE-2015-2191

Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x be…

Mitigation only
Fix from $1,600 2015-03-08
Wireshark MEDIUM 5.0
CVE-2015-2189

Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.…

Mitigation only
Fix from $1,600 2015-03-08
Android HIGH 10.0
CVE-2015-1474

Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 al…

Fix: after 5.0
Fix from $1,950 2015-02-16
Ubuntu Linux MEDIUM 6.8
CVE-2014-9666

The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count v…

Patch available
Fix from $1,600 2015-02-08
Libmspack MEDIUM 5.0
CVE-2014-9556

Integer overflow in the qtmd_decompress function in libmspack 0.4 allows remote attackers to cause a denial of service (hang) via a crafted CAB file,…

No fix yet
Fix from $1,600 2015-02-03
FreeBSD HIGH 7.2
CVE-2014-0998

Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denia…

No fix yet
Fix from $1,950 2015-02-02
Mac Os X HIGH 10.0
CVE-2014-4497

Integer signedness error in IOBluetoothFamily in the Bluetooth implementation in Apple OS X before 10.10 allows attackers to execute arbitrary code i…

Fix: after 10.9.5
Fix from $1,950 2015-01-30
Iphone Os MEDIUM 6.8
CVE-2014-4481EPSS 6%

Integer overflow in CoreGraphics in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 allows remote attackers to execute a…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Chrome MEDIUM 6.8
CVE-2015-1359

Multiple off-by-one errors in fpdfapi/fpdf_font/font_int.h in PDFium, as used in Google Chrome before 40.0.2214.91, allow remote attackers to cause a…

Fix: after 40.0.2214.85
Fix from $1,600 2015-01-27
Debian Linux HIGH 7.5
CVE-2014-8157EPSS 17%

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or po…

Fix: after 1.900.1
Fix from $1,950 2015-01-26