Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Lame HIGH 7.8
CVE-2017-15019

LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of …

No fix yet
Fix from $1,950 2017-10-05
Binutils MEDIUM 5.5
CVE-2017-15022

dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, w…

Patch available
Fix from $1,600 2017-10-05
Binutils MEDIUM 5.5
CVE-2017-15023

read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly v…

Patch available
Fix from $1,600 2017-10-05
Ubuntu Linux HIGH 8.8
CVE-2017-15015

ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in PDFDelegateMessage in coders/pdf.c.

Patch available
Fix from $1,950 2017-10-05
Ubuntu Linux HIGH 8.8
CVE-2017-15016

ImageMagick 7.0.7-0 Q16 has a NULL pointer dereference vulnerability in ReadEnhMetaFile in coders/emf.c.

Patch available
Fix from $1,950 2017-10-05
Debian Linux MEDIUM 6.5
CVE-2017-14994

ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted D…

Patch available
Fix from $1,600 2017-10-04
Binutils MEDIUM 5.5
CVE-2017-14974

The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the fai…

Patch available
Fix from $1,600 2017-10-02
Debian Linux HIGH 7.5
CVE-2017-14975

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability because a data structure is n…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux HIGH 7.5
CVE-2017-14977

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of…

No fix yet
Fix from $1,950 2017-10-02
Debian Linux MEDIUM 5.5
CVE-2017-14926

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Poppler MEDIUM 5.5
CVE-2017-14927

In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 5.5
CVE-2017-14928

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Binutils MEDIUM 5.5
CVE-2017-14940

scan_unit_for_symbols in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attack…

Patch available
Fix from $1,600 2017-09-30
Exiv2 MEDIUM 5.5
CVE-2017-14863

A NULL pointer dereference was discovered in Exiv2::Image::printIFDStructure in image.cpp in Exiv2 0.26. The vulnerability causes a segmentation faul…

No fix yet
Fix from $1,600 2017-09-29
Imagemagick HIGH 7.5
CVE-2017-14739

The AcquireResampleFilterThreadSet function in magick/resample-private.h in ImageMagick 7.0.7-4 mishandles failed memory allocation, which allows rem…

Patch available
Fix from $1,950 2017-09-26
Bento4 MEDIUM 6.5
CVE-2017-14638

AP4_AtomFactory::CreateAtomFromStream in Core/Ap4AtomFactory.cpp in Bento4 version 1.5.0-617 has missing NULL checks, leading to a NULL pointer deref…

Patch available
Fix from $1,600 2017-09-21
Bento4 MEDIUM 6.5
CVE-2017-14640

A NULL pointer dereference was discovered in AP4_AtomSampleTable::GetSample in Core/Ap4AtomSampleTable.cpp in Bento4 version 1.5.0-617. The vulnerabi…

Patch available
Fix from $1,600 2017-09-21
Bento4 MEDIUM 6.5
CVE-2017-14641

A NULL pointer dereference was discovered in the AP4_DataAtom class in MetaData/Ap4MetaData.cpp in Bento4 version 1.5.0-617. The vulnerability causes…

Patch available
Fix from $1,600 2017-09-21
Bento4 MEDIUM 6.5
CVE-2017-14642

A NULL pointer dereference was discovered in the AP4_HdlrAtom class in Bento4 version 1.5.0-617. The vulnerability causes a segmentation fault and ap…

Patch available
Fix from $1,600 2017-09-21
Ubuntu Linux CRITICAL 9.8
CVE-2017-14626

ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_decode in coders/sixel.c.

Patch available
Fix from $2,300 2017-09-21
Ubuntu Linux CRITICAL 9.8
CVE-2017-14624

ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function PostscriptDelegateMessage in coders/ps.c.

Patch available
Fix from $2,300 2017-09-21
Ubuntu Linux CRITICAL 9.8
CVE-2017-14625

ImageMagick 7.0.7-0 Q16 has a NULL Pointer Dereference vulnerability in the function sixel_output_create in coders/sixel.c.

Patch available
Fix from $2,300 2017-09-21
Ubuntu Linux CRITICAL 9.8
CVE-2017-14532

ImageMagick 7.0.7-0 has a NULL Pointer Dereference in TIFFIgnoreTags in coders/tiff.c.

Patch available
Fix from $2,300 2017-09-18
Poppler MEDIUM 5.5
CVE-2017-14517

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

No fix yet
Fix from $1,600 2017-09-17
Debian Linux MEDIUM 6.5
CVE-2017-14504

ReadPNMImage in coders/pnm.c in GraphicsMagick 1.3.26 does not ensure the correct number of colors for the XV 332 format, leading to a NULL Pointer D…

Patch available
Fix from $1,600 2017-09-17
Imagemagick MEDIUM 6.5
CVE-2017-14505

DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Serv…

Patch available
Fix from $1,600 2017-09-17
Esxi MEDIUM 5.5
CVE-2017-4925

VMware ESXi 6.5 without patch ESXi650-201707101-SG, ESXi 6.0 without patch ESXi600-201706101-SG, ESXi 5.5 without patch ESXi550-201709101-SG, Worksta…

Fix: 8.5.4 / 12.5.3+
Fix from $1,600 2017-09-15
Linux Kernel MEDIUM 5.5
CVE-2017-14340

The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, whic…

Fix: after 4.13.1
Fix from $1,600 2017-09-15
Mp3gain MEDIUM 5.5
CVE-2017-14406

A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a se…

Mitigation only
Fix from $1,600 2017-09-13
Imagemagick MEDIUM 6.5
CVE-2017-14400

In ImageMagick 7.0.7-1 Q16, the PersistPixelCache function in magick/cache.c mishandles the pixel cache nexus, which allows remote attackers to cause…

No fix yet
Fix from $1,600 2017-09-12