Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Goahead Web Server HIGH 7.5
CVE-2017-1000470EPSS 8%

EmbedThis GoAhead Webserver versions 4.0.0 and earlier is vulnerable to an integer overflow in the HTTP listener resulting in denial of service.

Patch available
Fix from $1,950 2018-01-03
Debian Linux HIGH 8.8
CVE-2017-1000422

Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential …

Fix: after 2.36.8
Fix from $1,950 2018-01-02
Debian Linux HIGH 8.8
CVE-2017-1000450

In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which can lead to integer overflow. …

Fix: after 3.3.0
Fix from $1,950 2018-01-02
Linux Kernel HIGH 7.8
CVE-2017-17854

kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overflow and memory corruption) or …

Fix: 4.14.9+
Fix from $1,950 2017-12-27
Linux Kernel HIGH 7.8
CVE-2017-17863

kernel/bpf/verifier.c in the Linux kernel 4.9.x through 4.9.71 does not check the relationship between pointer values and the BPF stack, which allows…

Fix: after 4.9.71
Fix from $1,950 2017-12-27
Internet Security 2018 HIGH 8.8
CVE-2017-17408EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interact…

Fix: after 73447
Fix from $1,950 2017-12-21
Internet Security 2018 HIGH 8.8
CVE-2017-17409

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interact…

Fix: 73456+
Fix from $1,950 2017-12-21
Android HIGH 7.8
CVE-2017-11043

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a WiFI driver function, an integer…

Patch available
Fix from $1,950 2017-12-05
Glibc HIGH 8.1
CVE-2017-17426

The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an…

No fix yet
Fix from $1,950 2017-12-05
Binutils HIGH 7.8
CVE-2017-17122

The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attacke…

Patch available
Fix from $1,950 2017-12-04
Debian Linux HIGH 7.5
CVE-2017-16612EPSS 5%

libXcursor before 1.1.15 has various integer overflows that could lead to heap buffer overflows when processing malicious cursors, e.g., with program…

Fix: after 1.1.14
Fix from $1,950 2017-12-01
Curl CRITICAL 9.8
CVE-2017-8816EPSS 9%

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow…

Fix: after 7.56.1
Fix from $2,300 2017-11-29
Honor 9 Firmware HIGH 7.8
CVE-2017-8205

The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has integer overflow vulnerability due t…

Mitigation only
Fix from $1,950 2017-11-22
Honor 8 Pro Firmware MEDIUM 6.5
CVE-2017-2717

honor 8 Pro with software Duke-L09C10B120 and earlier versions,Duke-L09C432B120 and earlier versions,Duke-L09C636B120 and earlier versions has an int…

Mitigation only
Fix from $1,600 2017-11-22
Libxls HIGH 7.8
CVE-2017-12110

An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS file can cause memory corrup…

Mitigation only
Fix from $1,950 2017-11-20
Python CRITICAL 9.8
CVE-2017-1000158EPSS 8%

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-bas…

Fix: 2.7.15 / 3.4.8+
Fix from $2,300 2017-11-17
Debian Linux HIGH 7.8
CVE-2017-1000229

Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.

No fix yet
Fix from $1,950 2017-11-17
Android HIGH 7.8
CVE-2017-0841

A remote code execution vulnerability in the Android system (libutils). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0.…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11085

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an integer overflow leading to a buff…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-9690

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a qbt1000 ioctl handler, an incorr…

Patch available
Fix from $1,950 2017-11-16
Libbpg HIGH 8.8
CVE-2017-13136

The image_alloc function in bpgenc.c in libbpg 0.9.7 has an integer overflow, with a resultant invalid malloc and NULL pointer dereference.

No fix yet
Fix from $1,950 2017-11-16
Binutils HIGH 7.8
CVE-2017-16828

The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-b…

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16830

The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows …

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16831

coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which …

Patch available
Fix from $1,950 2017-11-15
Binutils HIGH 7.8
CVE-2017-16832

The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does n…

Patch available
Fix from $1,950 2017-11-15
Swftools HIGH 7.8
CVE-2017-16797

In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, which allo…

Mitigation only
Fix from $1,950 2017-11-12
Sam2p MEDIUM 5.5
CVE-2017-16663

In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the function ReadImage, because "width *…

Mitigation only
Fix from $1,600 2017-11-08
Mongoose CRITICAL 9.8
CVE-2017-2921

An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket…

No fix yet
Fix from $2,300 2017-11-07
Mongoose CRITICAL 9.8
CVE-2017-2892

An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT …

Mitigation only
Fix from $2,300 2017-11-07
Webkitgtk\+ CRITICAL 9.8
CVE-2017-1000121

The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, allowing a compromised secondar…

Fix: 2.16.3+
Fix from $2,300 2017-11-01