Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Chrome HIGH 7.5
CVE-2014-7927

The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in Google Chrome before 40.0.2214.91, does not…

Fix: after 40.0.2214.85
Fix from $1,950 2015-01-22
Libtiff MEDIUM 5.0
CVE-2014-9330

Integer overflow in tif_packbits.c in bmp2tif in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) via crafted BMP image, re…

Mitigation only
Fix from $1,600 2015-01-20
Ubuntu Linux HIGH 7.5
CVE-2014-9604

libavcodec/utvideodec.c in FFmpeg before 2.5.2 does not check for a zero value of a slice height, which allows remote attackers to cause a denial of …

Fix: after 2.5.1
Fix from $1,950 2015-01-16
Ffmpeg HIGH 7.5
CVE-2014-9602

libavcodec/xface.h in FFmpeg before 2.5.2 establishes certain digits and words array dimensions that do not satisfy a required mathematical relations…

Fix: after 2.5.1
Fix from $1,950 2015-01-16
Directshowdemuxfilter HIGH 7.5
CVE-2014-10024

Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers …

No fix yet
Fix from $1,950 2015-01-13
Documentum Wdk MEDIUM 5.0
CVE-2014-4639

EMC Documentum Web Development Kit (WDK) before 6.8 does not properly generate random numbers for a certain parameter related to Webtop components, w…

Fix: after 6.7
Fix from $1,600 2015-01-07
Hiphop Virtual Machine HIGH 7.5
CVE-2014-6228

Integer overflow in the string_chunk_split function in hphp/runtime/base/zend-string.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 allow…

Fix: after 3.2.0
Fix from $1,950 2014-12-28
Vlc Media Player HIGH 7.5
CVE-2010-2062

Integer underflow in the real_get_rdt_chunk function in real.c, as used in modules/access/rtsp/real.c in VideoLAN VLC media player before 1.0.1 and s…

Fix: after 1.0.0
Fix from $1,950 2014-12-26
Chrome HIGH 7.5
CVE-2011-1795

Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.69…

Fix: after 11.0.696.64
Fix from $1,950 2014-12-26
Chrome HIGH 7.5
CVE-2011-1794

Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCo…

Fix: after 11.0.696.64
Fix from $1,950 2014-12-26
Ettercap MEDIUM 5.0
CVE-2014-9381

Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2014-12-19
Rpm HIGH 10.0
CVE-2014-8118EPSS 8%

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM…

Fix: after 4.12.0
Fix from $1,950 2014-12-16
Vtscada MEDIUM 5.0
CVE-2014-9192

Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows r…

Fix: 9.1.20 / 10.2.22+
Fix from $1,600 2014-12-11
Acrobat Reader HIGH 10.0
CVE-2014-8449EPSS 14%

Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2014-12-10
Jasper HIGH 7.5
CVE-2014-9029EPSS 18%

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier al…

Fix: after 1.900.1
Fix from $1,950 2014-12-08
Wireshark MEDIUM 5.0
CVE-2014-8711

Multiple integer overflows in epan/dissectors/packet-amqp.c in the AMQP dissector in Wireshark 1.10.x before 1.10.11 and 1.12.x before 1.12.2 allow r…

Mitigation only
Fix from $1,600 2014-11-23
Tcpdump MEDIUM 5.0
CVE-2014-8767EPSS 5%

Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,600 2014-11-20
Chrome MEDIUM 5.0
CVE-2014-7909

effects/SkDashPathEffect.cpp in Skia, as used in Google Chrome before 39.0.2171.65, computes a hash key using uninitialized integer values, which mig…

Fix: after 39.0.2171.45
Fix from $1,600 2014-11-19
Chrome HIGH 7.5
CVE-2014-7908

Multiple integer overflows in the CheckMov function in media/base/container_names.cc in Google Chrome before 39.0.2171.65 allow remote attackers to c…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Chrome HIGH 7.5
CVE-2014-7901

Integer overflow in the opj_t2_read_packet_data function in fxcodec/fx_libopenjpeg/libopenjpeg20/t2.c in OpenJPEG in PDFium, as used in Google Chrome…

Fix: after 39.0.2171.45
Fix from $1,950 2014-11-19
Freerdp HIGH 7.5
CVE-2014-0250

Multiple integer overflows in client/X11/xf_graphics.c in FreeRDP allow remote attackers to have an unspecified impact via the width and height to th…

Patch available
Fix from $1,950 2014-11-16
Ffmpeg HIGH 7.5
CVE-2014-8545

libavcodec/pngdec.c in FFmpeg before 2.4.2 accepts the monochrome-black format without verifying that the bits-per-pixel value is 1, which allows rem…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ffmpeg HIGH 7.5
CVE-2014-8546

Integer underflow in libavcodec/cinepak.c in FFmpeg before 2.4.2 allows remote attackers to cause a denial of service (out-of-bounds access) or possi…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Ffmpeg HIGH 7.5
CVE-2014-8549

libavcodec/on2avc.c in FFmpeg before 2.4.2 does not constrain the number of channels to at most 2, which allows remote attackers to cause a denial of…

Fix: after 2.4.1
Fix from $1,950 2014-11-05
Linux Enterprise Server HIGH 7.5
CVE-2014-0222

Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a la…

Fix: after 1.7.1
Fix from $1,950 2014-11-04
Qemu HIGH 7.5
CVE-2013-4148

Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2014-11-04
Network Interface Router MEDIUM 5.0
CVE-2014-8589

Integer overflow in SAP Network Interface Router (SAProuter) 40.4 allows remote attackers to cause a denial of service (resource consumption) via cra…

Mitigation only
Fix from $1,600 2014-11-04
Rsyslog MEDIUM 5.0
CVE-2014-3683

Integer overflow in rsyslog before 7.6.7 and 8.x before 8.4.2 and sysklogd 1.5 and earlier allows remote attackers to cause a denial of service (cras…

Fix: after 7.6.6
Fix from $1,600 2014-11-02
Python MEDIUM 6.4
CVE-2014-7185EPSS 5%

Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via …

Fix: after 10.10.4
Fix from $1,600 2014-10-08
Enterprise Linux Server Aus HIGH 7.5
CVE-2014-6051EPSS 8%

Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of se…

Fix: after 0.9.9
Fix from $1,950 2014-09-30