Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Hhvm CRITICAL 9.8
CVE-2016-6871

Integer overflow in bcmath in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, which triggers a buffer ov…

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Hhvm CRITICAL 9.8
CVE-2016-6872

Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.

Fix: after 3.14.5
Fix from $2,300 2017-02-17
Libdwarf MEDIUM 5.5
CVE-2016-7511

Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.

Patch available
Fix from $1,600 2017-02-17
Shadow HIGH 7.8
CVE-2016-6252

Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap.

Patch available
Fix from $1,950 2017-02-17
Gpu Driver HIGH 8.8
CVE-2017-0309

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where multiple integer overflows may cause imprope…

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1889

Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local user…

Mitigation only
Fix from $1,950 2017-02-15
Musl CRITICAL 9.8
CVE-2016-8859

Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large number of (1) states or (2) tags, …

Fix: after 1.1.15
Fix from $2,300 2017-02-13
Vim CRITICAL 9.8
CVE-2017-5953

vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a …

Fix: after 8.0.0055
Fix from $2,300 2017-02-10
Debian Linux HIGH 7.5
CVE-2016-2147EPSS 8%

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RF…

Fix: after 1.24.2
Fix from $1,950 2017-02-09
Android HIGH 7.8
CVE-2017-0410

An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context…

Mitigation only
Fix from $1,950 2017-02-08
Vxworks HIGH 8.1
CVE-2015-7599EPSS 6%

Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol…

Fix: after 6.9.4.1
Fix from $1,950 2017-02-07
Linux Kernel HIGH 7.8
CVE-2017-5576

Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows loc…

Fix: 4.9.7+
Fix from $1,950 2017-02-06
Libavformat MEDIUM 5.5
CVE-2016-4352

Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large …

Fix: after 57.34.103
Fix from $1,600 2017-02-03
Cairo MEDIUM 5.5
CVE-2016-9082

Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a l…

Mitigation only
Fix from $1,600 2017-02-03
Fedora HIGH 7.5
CVE-2016-9108

Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows …

Fix: after 2016-10-31
Fix from $1,950 2017-02-03
Libxpm CRITICAL 9.8
CVE-2016-10164EPSS 8%

Multiple integer overflows in libXpm before 3.5.12, when a program requests parsing XPM extensions on a 64-bit platform, allow remote attackers to ca…

Fix: after 3.5.11
Fix from $2,300 2017-02-01
Libquicktime HIGH 7.8
CVE-2016-2399EPSS 7%

Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or poss…

Fix: after 1.2.4
Fix from $1,950 2017-01-30
Botan CRITICAL 9.8
CVE-2016-9132

In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. S…

Patch available
Fix from $2,300 2017-01-30
Mujs HIGH 7.8
CVE-2017-5627

An issue was discovered in Artifex Software, Inc. MuJS before 4006739a28367c708dea19aeb19b8a1a9326ce08. The jsR_setproperty function in jsrun.c lacks…

Fix: 2017-01-24+
Fix from $1,950 2017-01-30
Mujs HIGH 7.8
CVE-2017-5628

An issue was discovered in Artifex Software, Inc. MuJS before 8f62ea10a0af68e56d5c00720523ebcba13c2e6a. The MakeDay function in jsdate.c does not val…

Fix: 2017-01-24+
Fix from $1,950 2017-01-30
Tcpdump CRITICAL 9.8
CVE-2016-7938

The ZeroMQ parser in tcpdump before 4.9.0 has an integer overflow in print-zeromq.c:zmtp1_print_frame().

Fix: after 4.8.1
Fix from $2,300 2017-01-28
Wireshark HIGH 7.5
CVE-2017-5596

In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed ca…

Patch available
Fix from $1,950 2017-01-25
Wireshark HIGH 7.5
CVE-2017-5597

In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the DHCPv6 dissector could go into a large loop, triggered by packet injection or a malformed capture…

Patch available
Fix from $1,950 2017-01-25
PHP HIGH 7.5
CVE-2016-10159EPSS 8%

Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause…

Fix: 7.0.15+
Fix from $1,950 2017-01-24
Gstreamer HIGH 7.5
CVE-2016-9445

Integer overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and height values,…

Mitigation only
Fix from $1,950 2017-01-23
Ffmpeg CRITICAL 9.8
CVE-2016-6164

Integer overflow in the mov_build_index function in libavformat/mov.c in FFmpeg before 2.8.8, 3.0.x before 3.0.3 and 3.1.x before 3.1.1 allows remote…

Fix: after 2.8.7
Fix from $2,300 2017-01-23
Chrome MEDIUM 6.5
CVE-2016-5223

Integer overflow in PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker …

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.3
CVE-2016-5221

Type confusion in libGLESv2 in ANGLE in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android possibly allowed…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Imagemagick HIGH 7.5
CVE-2016-6823

Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and …

Fix: 6.9.10-50 / 7.0.2-10+
Fix from $1,950 2017-01-18
Mujs CRITICAL 9.8
CVE-2016-10141

An integer overflow vulnerability was observed in the regemit function in regexp.c in Artifex Software, Inc. MuJS before fa3d30fd18c348bb4b1f3858fb86…

Fix: 2017-01-12+
Fix from $2,300 2017-01-13