Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Debian Linux CRITICAL 9.8
CVE-2018-7225EPSS 6%

An issue was discovered in LibVNCServer through 0.9.11. rfbProcessClientNormalMessage() in rfbserver.c does not sanitize msg.cct.length, leading to a…

No fix yet
Fix from $2,300 2018-02-19
Intelligent Management Center CRITICAL 9.8
CVE-2017-5804EPSS 22%

A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.2 was found.

Mitigation only
Fix from $2,300 2018-02-15
Dp300 Firmware MEDIUM 5.3
CVE-2017-17288

Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00…

Mitigation only
Fix from $1,600 2018-02-15
Ar120 S Firmware HIGH 7.5
CVE-2017-15343

Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has a…

Mitigation only
Fix from $1,950 2018-02-15
Ar120 S Firmware HIGH 7.5
CVE-2017-15344

Huawei AR3200 with software V200R006C10, V200R006C11, V200R007C00, V200R007C01, V200R007C02, V200R008C00, V200R008C10, V200R008C20, V200R008C30 has a…

Mitigation only
Fix from $1,950 2018-02-15
Debian Linux CRITICAL 9.8
CVE-2017-18187

In ARM mbed TLS before 2.7.0, there is a bounds-check bypass through an integer overflow in PSK identity parsing in the ssl_parse_client_psk_identity…

Fix: 2.7.0+
Fix from $2,300 2018-02-14
Exiv2 MEDIUM 6.5
CVE-2017-17725

In Exiv2 0.26, there is an integer overflow leading to a heap-based buffer over-read in the Exiv2::getULong function in types.cpp. Remote attackers c…

No fix yet
Fix from $1,600 2018-02-12
Linux Kernel HIGH 7.8
CVE-2018-6927

The futex_requeue function in kernel/futex.c in the Linux kernel before 4.14.15 might allow attackers to cause a denial of service (integer overflow)…

Fix: 4.14.15+
Fix from $1,950 2018-02-12
Chrome HIGH 8.8
CVE-2017-5130

An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other products, allowed a remote attac…

Fix: 2.9.5 / 62.0.3202.62+
Fix from $1,950 2018-02-07
Chrome HIGH 8.8
CVE-2017-5131

An integer overflow in Skia in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTM…

Fix: 62.0.3202.62+
Fix from $1,950 2018-02-07
Ccn Lite CRITICAL 9.8
CVE-2017-12465

Multiple integer overflows in CCN-lite before 2.00 allow context-dependent attackers to have unspecified impact via vectors involving the (1) vallen …

Fix: 2.0.0+
Fix from $2,300 2018-02-07
Ccn Lite CRITICAL 9.8
CVE-2017-12470

Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors…

Fix: 2.0.0+
Fix from $2,300 2018-02-07
Glibc CRITICAL 9.8
CVE-2018-6551

The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not …

Fix: after 2.26
Fix from $2,300 2018-02-02
Binutils HIGH 7.8
CVE-2018-6543

In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size…

No fix yet
Fix from $1,950 2018-02-02
Virtualization Host CRITICAL 9.8
CVE-2018-6485

An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier coul…

Fix: after 2.26
Fix from $2,300 2018-02-01
Debian Linux MEDIUM 5.5
CVE-2017-18043

Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu process crash).

Fix: after 2.10.1
Fix from $1,600 2018-01-31
Binutils HIGH 7.8
CVE-2018-6323EPSS 6%

The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsign…

No fix yet
Fix from $1,950 2018-01-26
Debian Linux HIGH 8.8
CVE-2018-6315

The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds re…

Fix: after 0.4.8
Fix from $1,950 2018-01-25
Mujs MEDIUM 5.5
CVE-2018-6191EPSS 5%

The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.

Fix: after 1.0.2
Fix from $1,600 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12177

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X client to cause X server to cr…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2017-12179

xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing malicious X client to cause X s…

Fix: 1.19.5+
Fix from $2,300 2018-01-24
Debian Linux MEDIUM 6.5
CVE-2018-5785

In OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function (openjp2/j2k.c). Remote a…

No fix yet
Fix from $1,600 2018-01-19
Openjpeg MEDIUM 6.5
CVE-2018-5727

In OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could leverage thi…

No fix yet
Fix from $1,600 2018-01-16
Kerberos HIGH 7.5
CVE-2018-5709

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 1…

Fix: after 5-1.16
Fix from $1,950 2018-01-16
Android HIGH 7.8
CVE-2017-13182

In the sendFormatChange function of ACodec, there is a possible integer overflow which could lead to an out-of-bounds write. This could lead to a loc…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-0869

NVIDIA driver contains an integer overflow vulnerability which could cause a use after free and possibly lead to an elevation of privilege enabling c…

Patch available
Fix from $1,950 2018-01-12
Fusion HIGH 7.0
CVE-2017-4950

VMware Workstation and Fusion contain an integer overflow vulnerability in VMware NAT service when IPv6 mode is enabled. This issue may lead to an ou…

Fix: 8.5.10 / 10.1.1+
Fix from $1,950 2018-01-11
Podofo MEDIUM 5.5
CVE-2018-5309

In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cp…

No fix yet
Fix from $1,600 2018-01-09
Debian Linux MEDIUM 6.5
CVE-2018-5294

In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers coul…

Mitigation only
Fix from $1,600 2018-01-08
Podofo MEDIUM 5.5
CVE-2018-5295

In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote att…

No fix yet
Fix from $1,600 2018-01-08