Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Jbig2dec HIGH 7.1
CVE-2017-7976

Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c durin…

Mitigation only
Fix from $1,950 2017-04-19
Jbig2dec HIGH 7.8
CVE-2017-7975

Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function i…

Mitigation only
Fix from $1,950 2017-04-19
Ghostscript HIGH 7.8
CVE-2017-7948

Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and…

Patch available
Fix from $1,950 2017-04-19
Jbig2dec HIGH 7.1
CVE-2017-7885

Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from …

Mitigation only
Fix from $1,950 2017-04-17
Acrobat HIGH 7.8
CVE-2017-3011EPSS 8%

Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerabil…

Fix: after 15.023.20070
Fix from $1,950 2017-04-12
Libtiff HIGH 7.8
CVE-2017-7602

LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have uns…

Patch available
Fix from $1,950 2017-04-09
Libaacplus HIGH 7.8
CVE-2017-7603

au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (…

No fix yet
Fix from $1,950 2017-04-09
Linux Kernel HIGH 7.0
CVE-2017-0576

An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code wit…

Patch available
Fix from $1,950 2017-04-07
Android HIGH 7.0
CVE-2017-0553

An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi…

Mitigation only
Fix from $1,950 2017-04-07
Arm Trusted Firmware MEDIUM 5.9
CVE-2016-10319

In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of inte…

Patch available
Fix from $1,600 2017-04-06
Cloudengine 5800 Firmware MEDIUM 5.9
CVE-2016-8795

Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V…

Mitigation only
Fix from $1,600 2017-04-02
Oceanstor 5800 V3 Firmware MEDIUM 6.5
CVE-2016-6177

The Huawei OceanStor 5800 V300R003C00 has an integer overflow vulnerability. An authenticated attacker may send massive abnormal Network File System …

Mitigation only
Fix from $1,600 2017-04-02
Iphone Os HIGH 7.8
CVE-2017-2440

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch…

Fix: after 10.12.3
Fix from $1,950 2017-04-02
Tigervnc MEDIUM 6.5
CVE-2017-7395

In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.

Patch available
Fix from $1,600 2017-04-01
Linux Kernel HIGH 7.8
CVE-2017-7294

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of cer…

Fix: 3.2.89 / 3.10.107+
Fix from $1,950 2017-03-29
Go Jose HIGH 7.5
CVE-2016-9123

go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CB…

Fix: after 1.0.4
Fix from $1,950 2017-03-28
Qemu HIGH 8.8
CVE-2017-5931

Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU …

Fix: after 2.8.1.1
Fix from $1,950 2017-03-27
Jasper MEDIUM 5.5
CVE-2016-9557

Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file.

Fix: after 1.900.24
Fix from $1,600 2017-03-23
Jasper MEDIUM 5.5
CVE-2016-9262

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.9…

Fix: after 1.900.21
Fix from $1,600 2017-03-23
Jasper HIGH 7.8
CVE-2016-9387

Integer overflow in the jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers to have unspecified…

Fix: after 1.900.12
Fix from $1,950 2017-03-23
Audiofile MEDIUM 5.5
CVE-2017-6838

Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) v…

Patch available
Fix from $1,600 2017-03-20
Audiofile MEDIUM 5.5
CVE-2017-6839

Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via …

Patch available
Fix from $1,600 2017-03-20
Glibc HIGH 8.1
CVE-2015-8983

Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent …

Fix: after 2.21
Fix from $1,950 2017-03-20
Fedora MEDIUM 5.5
CVE-2015-4645

Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service…

Fix: after 4.3
Fix from $1,600 2017-03-17
Debian Linux HIGH 7.5
CVE-2017-6960

An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function a…

Mitigation only
Fix from $1,950 2017-03-17
Apng2gif HIGH 7.5
CVE-2017-6962

An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer overflow. This is related to the read_chunk fu…

Mitigation only
Fix from $1,950 2017-03-17
Windows Server 2008 HIGH 8.1
CVE-2017-0104EPSS 14%

The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers…

Patch available
Fix from $1,950 2017-03-17
Capstone HIGH 8.8
CVE-2017-6952

Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (h…

Fix: after 3.0.4
Fix from $1,950 2017-03-16
Imagemagick HIGH 7.5
CVE-2015-8895

Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a cra…

Patch available
Fix from $1,950 2017-03-15
Glibc HIGH 8.1
CVE-2015-8982

Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial o…

Fix: after 2.20
Fix from $1,950 2017-03-15