Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Android HIGH 7.8
CVE-2016-3901

Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus…

Fix: after 7.0
Fix from $1,950 2016-10-10
Fedora CRITICAL 9.8
CVE-2016-7167EPSS 12%

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.…

Fix: after 7.50.2
Fix from $2,300 2016-10-07
PHP CRITICAL 9.8
CVE-2016-7568EPSS 5%

Integer overflow in the gdImageWebpCtx function in gd_webp.c in the GD Graphics Library (aka libgd) through 2.2.3, as used in PHP through 7.0.11, all…

Fix: after 7.0.11
Fix from $2,300 2016-09-28
Libtiff HIGH 7.8
CVE-2016-3945

Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is …

Fix: after 4.0.6
Fix from $1,950 2016-09-21
Debian Linux HIGH 7.8
CVE-2016-7163EPSS 7%

Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, w…

Patch available
Fix from $1,950 2016-09-21
Linux HIGH 8.6
CVE-2016-6250EPSS 6%

Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Enterprise Linux Desktop MEDIUM 6.5
CVE-2016-5844

Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted …

Patch available
Fix from $1,600 2016-09-21
Enterprise Linux Desktop HIGH 7.8
CVE-2016-4300

Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to exec…

Fix: after 3.2.0
Fix from $1,950 2016-09-21
Ubuntu Linux MEDIUM 5.5
CVE-2015-8933

Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.8
CVE-2015-8931

Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2…

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
PHP HIGH 8.1
CVE-2016-7133

Zend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote attackers to cause …

Patch available
Fix from $1,950 2016-09-12
Android MEDIUM 5.5
CVE-2016-3895

Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 al…

Patch available
Fix from $1,600 2016-09-11
Chrome HIGH 8.8
CVE-2016-5159

Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, …

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5158

Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows …

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Chrome HIGH 8.8
CVE-2016-5152

Integer overflow in the opj_tcd_get_decoded_tile_size function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Window…

Fix: after 52.0.2743.116
Fix from $1,950 2016-09-11
Python CRITICAL 9.8
CVE-2016-5636EPSS 25%

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remot…

Patch available
Fix from $2,300 2016-09-02
Linux Kernel CRITICAL 9.8
CVE-2016-5344

Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM de…

Fix: after 7.0
Fix from $2,300 2016-08-30
Debian Linux MEDIUM 6.5
CVE-2016-6207EPSS 6%

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers …

Fix: 5.5.38 / 5.6.24+
Fix from $1,600 2016-08-12
Netscape Portable Runtime HIGH 8.6
CVE-2016-1951

Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service …

Fix: after 4.11
Fix from $1,950 2016-08-07
PHP CRITICAL 9.8
CVE-2016-5770EPSS 7%

Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows rem…

Fix: 5.5.37 / 5.6.23+
Fix from $2,300 2016-08-07
Libgd HIGH 8.8
CVE-2016-5767EPSS 7%

Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37, 5.6.x b…

Fix: after 2.0.33
Fix from $1,950 2016-08-07
Openshift HIGH 8.8
CVE-2016-5766EPSS 7%

Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x b…

Patch available
Fix from $1,950 2016-08-07
PHP CRITICAL 9.8
CVE-2016-3078EPSS 56%

Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buff…

Fix: 7.0.6+
Fix from $2,300 2016-08-07
Android HIGH 7.8
CVE-2014-9863

Integer underflow in the diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Firefox HIGH 8.8
CVE-2016-5261

Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ESR < 45.4 allows remote attack…

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Chrome HIGH 8.8
CVE-2016-5138

Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attack…

Fix: after 52.0.2743.82
Fix from $1,950 2016-08-01
Mac Os X HIGH 7.8
CVE-2014-9862EPSS 7%

Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execu…

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Linux Kernel HIGH 7.8
CVE-2016-2068

The MSM QDSP6 audio driver (aka sound driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM de…

Fix: after 6.0.1
Fix from $1,950 2016-07-11
Linux Kernel HIGH 7.8
CVE-2012-6703

Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.6-rc6-…

Fix: 3.7+
Fix from $1,950 2016-06-29
OpenSSL CRITICAL 9.8
CVE-2016-2177EPSS 45%

OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of s…

Patch available
Fix from $2,300 2016-06-20