Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Android HIGH 7.8
CVE-2017-0383

An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbitrary code within the context…

Mitigation only
Fix from $1,950 2017-01-12
Android HIGH 7.8
CVE-2017-0381

An information disclosure vulnerability in silk/NLSF_stabilize.c in libopus in Mediaserver could enable a local malicious application to access data …

Patch available
Fix from $1,950 2017-01-12
Linux Kernel CRITICAL 9.8
CVE-2016-8438

Integer overflow leading to a TOCTOU condition in hypervisor PIL. An integer overflow exposes a race condition that may be used to bypass (Peripheral…

Mitigation only
Fix from $2,300 2017-01-12
PHP CRITICAL 9.8
CVE-2017-5340EPSS 17%

Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attac…

Fix: 7.0.15 / 7.1.1+
Fix from $2,300 2017-01-11
Hancom Office 2014 HIGH 7.8
CVE-2016-4290

When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a b…

Fix: after 9.1.0.2176
Fix from $1,950 2017-01-06
Hancom Office 2014 HIGH 7.8
CVE-2016-4291

When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a field from the structure in…

Fix: after 9.1.0.2176
Fix from $1,950 2017-01-06
Hancom Office 2014 HIGH 7.8
CVE-2016-4298

When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate space for a l…

Fix: after 9.1.0.2176
Fix from $1,950 2017-01-06
Memcached CRITICAL 9.8
CVE-2016-8704EPSS 23%

An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binar…

Fix: after 1.4.31
Fix from $2,300 2017-01-06
Memcached CRITICAL 9.8
CVE-2016-8705EPSS 20%

Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary pro…

Fix: after 1.4.31
Fix from $2,300 2017-01-06
Memcached HIGH 8.1
CVE-2016-8706EPSS 46%

An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, ca…

Fix: after 1.4.31
Fix from $1,950 2017-01-06
Clustered Data Ontap HIGH 7.5
CVE-2015-7848EPSS 6%

An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode pa…

Fix: 4.2.8 / 4.3.77+
Fix from $1,950 2017-01-06
Linux Kernel HIGH 7.8
CVE-2016-9754

The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer …

Fix: 3.10.102 / 3.12.61+
Fix from $1,950 2017-01-05
Smartos HIGH 7.8
CVE-2016-9031

An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system …

No fix yet
Fix from $1,950 2016-12-14
Smartos HIGH 8.8
CVE-2016-8733

An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system …

Fix: after 20161110t013148z
Fix from $1,950 2016-12-14
Fedora CRITICAL 9.8
CVE-2016-7951

Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the l…

Fix: after 1.2.2
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7947

Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.

Fix: after 1.5.0
Fix from $2,300 2016-12-13
Fedora HIGH 7.5
CVE-2016-7945

Multiple integer overflows in X.org libXi before 1.7.7 allow remote X servers to cause a denial of service (out-of-bounds memory access or infinite l…

Fix: after 1.7.6
Fix from $1,950 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7944

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, w…

Fix: after 5.0.2
Fix from $2,300 2016-12-13
Imagemagick CRITICAL 9.8
CVE-2016-5841EPSS 13%

Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or p…

Fix: after 7.0.2-0
Fix from $2,300 2016-12-13
Debian Linux CRITICAL 9.8
CVE-2016-9427

Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) an…

Fix: after 7.4.4
Fix from $2,300 2016-12-12
W3m HIGH 8.8
CVE-2016-9426

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows r…

Fix: after 0.5.3-30
Fix from $1,950 2016-12-12
Libtiff HIGH 7.4
CVE-2015-8870

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or p…

Fix: after 4.0.3
Fix from $1,950 2016-12-06
Linux Kernel HIGH 7.8
CVE-2016-9084

drivers/vfio/pci/vfio_pci_intrs.c in the Linux kernel through 4.8.11 misuses the kzalloc function, which allows local users to cause a denial of serv…

Fix: after 4.8.11
Fix from $1,950 2016-11-28
Linux Kernel HIGH 7.8
CVE-2016-9083

drivers/vfio/pci/vfio_pci.c in the Linux kernel through 4.8.11 allows local users to bypass integer overflow checks, and cause a denial of service (m…

Fix: 3.10.107 / 3.12.70+
Fix from $1,950 2016-11-28
Libtiff CRITICAL 9.8
CVE-2016-9538

tools/tiffcrop.c in libtiff 4.0.6 reads an undefined buffer in readContigStripsIntoBuffer() because of a uint16 integer overflow. Reported as MSVR 35…

Patch available
Fix from $2,300 2016-11-22
Samsung Mobile HIGH 7.5
CVE-2016-9277

Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of service (UI restart) via vectors…

Mitigation only
Fix from $1,950 2016-11-11
Pillow MEDIUM 5.5
CVE-2016-9189

Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Int…

Fix: after 3.3.1
Fix from $1,600 2016-11-04
Android CRITICAL 9.8
CVE-2016-7990

On Samsung Galaxy S4 through S7 devices, an integer overflow condition exists within libomacp.so when parsing OMACP messages (within WAP Push SMS mes…

Mitigation only
Fix from $2,300 2016-10-31
Acrobat CRITICAL 9.8
CVE-2016-6999EPSS 6%

Integer overflow in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reade…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Android HIGH 7.8
CVE-2016-3935

Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus…

Fix: after 7.0
Fix from $1,950 2016-10-10