Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
PHP CRITICAL 9.8
CVE-2016-4346EPSS 6%

Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl…

Fix: 7.0.4+
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4345EPSS 5%

Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a deni…

Fix: 7.0.4+
Fix from $2,300 2016-05-22
PHP CRITICAL 9.8
CVE-2016-4344EPSS 5%

Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibl…

Fix: 7.0.4+
Fix from $2,300 2016-05-22
Ubuntu Linux MEDIUM 5.5
CVE-2016-3712

Integer overflow in the VGA module in QEMU allows local guest OS users to cause a denial of service (out-of-bounds read and QEMU process crash) by ed…

Patch available
Fix from $1,600 2016-05-11
Linux Kernel HIGH 7.8
CVE-2016-2062

The adreno_perfcounter_query_group function in drivers/gpu/msm/adreno_perfcounter.c in the Adreno GPU driver for the Linux kernel 3.x, as used in Qua…

Fix: after 3.19.8
Fix from $1,950 2016-05-05
Enterprise Linux Desktop HIGH 7.5
CVE-2016-2105EPSS 40%

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to …

Fix: after 5.7.12
Fix from $1,950 2016-05-05
Linux Kernel HIGH 7.8
CVE-2012-6701

Integer overflow in fs/aio.c in the Linux kernel before 3.4.1 allows local users to cause a denial of service or possibly have unspecified other impa…

Fix: 3.0.33 / 3.2.19+
Fix from $1,950 2016-05-02
Redis HIGH 7.5
CVE-2015-8080

Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with p…

Fix: 2.8.24 / 3.0.6+
Fix from $1,950 2016-04-13
Iphone Os HIGH 7.8
CVE-2016-1753

Multiple integer overflows in the kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allow attackers to exe…

Fix: 2.2 / 9.2+
Fix from $1,950 2016-03-24
Flash Player HIGH 8.8
CVE-2016-1010 KEVEPSS 20%

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux…

Fix: after 20.2.2.306
Fix from $1,950 2016-03-12
Flash Player HIGH 8.8
CVE-2016-0993EPSS 6%

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux…

Fix: after 20.2.2.306
Fix from $1,950 2016-03-12
Flash Player HIGH 8.8
CVE-2016-0963EPSS 6%

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux…

Fix: after 20.2.2.306
Fix from $1,950 2016-03-12
Debian Linux HIGH 8.8
CVE-2016-2326

Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service…

Fix: after 2.8.4
Fix from $1,950 2016-02-12
Enterprise Linux Desktop HIGH 8.8
CVE-2015-8651 KEVEPSS 68%

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ad…

Fix: 11.2.202.559 / 18.0.0.324+
Fix from $1,950 2015-12-28
PHP CRITICAL 9.8
CVE-2015-8394

PCRE before 8.38 mishandles the (?(<digits>) and (?(R<digits>) conditions, which allows remote attackers to cause a denial of service (integer overfl…

Fix: 5.5.32 / 5.6.18+
Fix from $2,300 2015-12-02
Fedora HIGH 7.3
CVE-2015-8387

PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer…

Fix: 5.5.32 / 5.6.18+
Fix from $1,950 2015-12-02
Windows 10 HIGH 9.3
CVE-2015-2519EPSS 14%

Integer overflow in Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Window…

Patch available
Fix from $1,950 2015-09-09
Net Snmp HIGH 7.5
CVE-2015-5621EPSS 40%

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when par…

Fix: after 5.7.2
Fix from $1,950 2015-08-19
Chrome MEDIUM 6.8
CVE-2015-1283EPSS 19%

Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, all…

Fix: 2.7.12 / 3.3.7+
Fix from $1,600 2015-07-23
Acrobat MEDIUM 6.8
CVE-2015-5109EPSS 6%

Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Acrobat HIGH 10.0
CVE-2015-5108EPSS 7%

Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060…

Fix: 10.1.15 / 11.0.12+
Fix from $1,950 2015-07-15
Acrobat HIGH 10.0
CVE-2015-5097EPSS 19%

Integer overflow in Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060…

Fix: 15.006.30060 / 15.008.20082+
Fix from $1,950 2015-07-15
Ubuntu Linux HIGH 7.5
CVE-2015-3416EPSS 6%

The sqlite3VXPrintf function in printf.c in SQLite before 3.8.9 does not properly handle precision and width values during floating-point conversions…

Fix: 5.4.42 / 5.5.26+
Fix from $1,950 2015-04-24
Ubuntu Linux MEDIUM 6.8
CVE-2015-2305EPSS 8%

Integer overflow in the regcomp implementation in the Henry Spencer BSD regex library (aka rxspencer) alpha3.8.g5 on 32-bit platforms, as used in Net…

Fix: 5.4.39 / 5.5.23+
Fix from $1,600 2015-03-30
Potrace MEDIUM 5.0
CVE-2013-7437

Multiple integer overflows in potrace 1.11 allow remote attackers to cause a denial of service (crash) via large dimensions in a BMP image, which tri…

No fix yet
Fix from $1,600 2015-03-29
Enterprise Linux Desktop Supplementary HIGH 7.5
CVE-2015-1214

Integer overflow in the SkAutoSTArray implementation in include/core/SkTemplates.h in the filters implementation in Skia, as used in Google Chrome be…

Fix: after 40.0.2214.115
Fix from $1,950 2015-03-09
Fedora MEDIUM 5.0
CVE-2015-0886

Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine…

Fix: 0.4+
Fix from $1,600 2015-02-28
Vtscada MEDIUM 5.0
CVE-2014-9192

Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows r…

Fix: 9.1.20 / 10.2.22+
Fix from $1,600 2014-12-11
Debian Linux MEDIUM 6.5
CVE-2014-8094

Integer overflow in the ProcDRI2GetBuffers function in the DRI2 extension in X.Org Server (aka xserver and xorg-server) 1.7.0 through 1.16.x before 1…

Patch available
Fix from $1,600 2014-12-10
Flash Player HIGH 9.3
CVE-2014-0569EPSS 92%

Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Ad…

Fix: after 15.0.0.252
Fix from $1,950 2014-10-15