Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Qpdf HIGH 7.8
CVE-2017-12595

The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack co…

Patch available
Fix from $1,950 2017-08-27
Tidy HIGH 7.5
CVE-2017-13692

In Tidy 5.5.31, the IsURLCodePoint function in attrs.c allows attackers to cause a denial of service (Segmentation Fault), as demonstrated by an inva…

Patch available
Fix from $1,950 2017-08-25
Fedora MEDIUM 5.3
CVE-2015-5146

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and acces…

Fix: after 4.2.8
Fix from $1,600 2017-08-24
Graphicsmagick HIGH 8.8
CVE-2017-13147

In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND…

Patch available
Fix from $1,950 2017-08-23
Imagemagick MEDIUM 6.5
CVE-2017-13144

In ImageMagick before 6.9.7-10, there is a crash (rather than a "width or height exceeds limit" error report) if the image dimensions are too large, …

Fix: after 6.9.7-9
Fix from $1,600 2017-08-23
Debian Linux MEDIUM 6.5
CVE-2017-13145

In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, lead…

Fix: after 6.9.8-7
Fix from $1,600 2017-08-23
Fedora MEDIUM 6.5
CVE-2017-12843

Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE com…

Fix: after 3.0.2
Fix from $1,600 2017-08-22
Imagemagick MEDIUM 6.5
CVE-2017-13061

In ImageMagick 7.0.6-5, a length-validation vulnerability was found in the function ReadPSDLayersInternal in coders/psd.c, which allows attackers to …

Mitigation only
Fix from $1,600 2017-08-22
Cc File Transfer HIGH 7.5
CVE-2017-12784

In Youngzsoft CCFile (aka CC File Transfer) 3.6, by sending a crafted HTTP request, it is possible for a malicious user to remotely crash the affecte…

No fix yet
Fix from $1,950 2017-08-21
Git Annex HIGH 8.8
CVE-2017-12976

git-annex before 6.20170818 allows remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname, as d…

Fix: after 6.20170520
Fix from $1,950 2017-08-20
Pspp HIGH 7.5
CVE-2017-12961

There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will le…

Mitigation only
Fix from $1,950 2017-08-18
Android CRITICAL 9.8
CVE-2016-10391

In all Qualcomm products with Android releases from CAF using the Linux kernel, the length in an HCI command is not properly checked for validity.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-5872

In all Qualcomm products with Android releases from CAF using the Linux kernel, arguments to several QTEE syscalls are not properly validated.

Mitigation only
Fix from $2,300 2017-08-18
Android HIGH 7.8
CVE-2017-8260

In all Qualcomm products with Android releases from CAF using the Linux kernel, due to a type downcast, a value may improperly pass validation and ca…

Patch available
Fix from $1,950 2017-08-18
Android CRITICAL 9.8
CVE-2015-9055

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a memory management routine.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9060

In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a QTEE system call.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9061

In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unautho…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9068

In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a mink syscall is not properly validated.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9069

In all Qualcomm products with Android releases from CAF using the Linux kernel, the Secure File System can become corrupted.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10347

In all Qualcomm products with Android releases from CAF using the Linux kernel, an argument to a hypervisor function is not properly validated.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10384

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a WLAN driver ioctl.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10387

In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9039

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in eMBMS where an assertion can be reached by …

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9044

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due t…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9046

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due t…

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9048

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of lost RTP packets.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9049

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of certain responses from th…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9051

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due t…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9052

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached while…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2014-9971

In all Qualcomm products with Android releases from CAF using the Linux kernel, disabling asserts causes an instruction inside of an assert to not be…

No fix yet
Fix from $2,300 2017-08-18