Vulnerability index

Browse CVEs

3,273 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
HIGH 7.1 CVE-2017-7976 Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c durin… Jbig2dec Mitigation only Fix from $1,9502017-04-19 HIGH 7.8 CVE-2017-7975 Artifex jbig2dec 0.13, as used in Ghostscript, allows out-of-bounds writes because of an integer overflow in the jbig2_build_huffman_table function i… Jbig2dec Mitigation only Fix from $1,9502017-04-19 HIGH 7.8 CVE-2017-7948 Integer overflow in the mark_curve function in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service (out-of-bounds write and… Ghostscript Patch available Fix from $1,9502017-04-19 HIGH 7.1 CVE-2017-7885 Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from … Jbig2dec Mitigation only Fix from $1,9502017-04-17 HIGH 7.8 CVE-2017-3011EPSS 8% Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable integer overflow vulnerabil… Acrobat after 15.023.20070 Fix from $1,9502017-04-12 HIGH 7.8 CVE-2017-7602 LibTIFF 4.0.7 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have uns… Libtiff Patch available Fix from $1,9502017-04-09 HIGH 7.8 CVE-2017-7603 au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (… Libaacplus No fix yet Fix from $1,9502017-04-09 HIGH 7.0 CVE-2017-0576 An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code wit… Linux Kernel Patch available Fix from $1,9502017-04-07 HIGH 7.0 CVE-2017-0553 An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi… Android Mitigation only Fix from $1,9502017-04-07 MEDIUM 5.9 CVE-2016-10319 In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of inte… Arm Trusted Firmware Patch available Fix from $1,6002017-04-06 MEDIUM 5.9 CVE-2016-8795 Huawei CloudEngine 12800 with software V100R002C00, V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00; CloudEngine 5800 with software V… Cloudengine 5800 Firmware Mitigation only Fix from $1,6002017-04-02 MEDIUM 6.5 CVE-2016-6177 The Huawei OceanStor 5800 V300R003C00 has an integer overflow vulnerability. An authenticated attacker may send massive abnormal Network File System … Oceanstor 5800 V3 Firmware Mitigation only Fix from $1,6002017-04-02 HIGH 7.8 CVE-2017-2440 An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch… Iphone Os after 10.12.3 Fix from $1,9502017-04-02 MEDIUM 6.5 CVE-2017-7395 In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server. Tigervnc Patch available Fix from $1,6002017-04-01 HIGH 7.8 CVE-2017-7294 The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of cer… Linux Kernel 3.2.89 / 3.10.107+ Fix from $1,9502017-03-29 HIGH 7.5 CVE-2016-9123 go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CB… Go Jose after 1.0.4 Fix from $1,9502017-03-28 HIGH 8.8 CVE-2017-5931 Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU … Qemu after 2.8.1.1 Fix from $1,9502017-03-27 MEDIUM 5.5 CVE-2016-9557 Integer overflow in jas_image.c in JasPer before 1.900.25 allows remote attackers to cause a denial of service (application crash) via a crafted file. Jasper after 1.900.24 Fix from $1,6002017-03-23 MEDIUM 5.5 CVE-2016-9262 Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.9… Jasper after 1.900.21 Fix from $1,6002017-03-23 HIGH 7.8 CVE-2016-9387 Integer overflow in the jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.13 allows remote attackers to have unspecified… Jasper after 1.900.12 Fix from $1,9502017-03-23 MEDIUM 5.5 CVE-2017-6838 Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) v… Audiofile Patch available Fix from $1,6002017-03-20 MEDIUM 5.5 CVE-2017-6839 Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via … Audiofile Patch available Fix from $1,6002017-03-20 HIGH 8.1 CVE-2015-8983 Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent … Glibc after 2.21 Fix from $1,9502017-03-20 MEDIUM 5.5 CVE-2015-4645 Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service… Fedora after 4.3 Fix from $1,6002017-03-17 HIGH 7.5 CVE-2017-6960 An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, related to the load_apng function a… Debian Linux Mitigation only Fix from $1,9502017-03-17 HIGH 7.5 CVE-2017-6962 An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer overflow. This is related to the read_chunk fu… Apng2gif Mitigation only Fix from $1,9502017-03-17 HIGH 8.1 CVE-2017-0104EPSS 14% The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers… Windows Server 2008 Patch available Fix from $1,9502017-03-17 HIGH 8.8 CVE-2017-6952 Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (h… Capstone after 3.0.4 Fix from $1,9502017-03-16 HIGH 7.5 CVE-2015-8895 Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a cra… Imagemagick Patch available Fix from $1,9502017-03-15 HIGH 8.1 CVE-2015-8982 Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial o… Glibc after 2.20 Fix from $1,9502017-03-15