Vulnerability index

Browse CVEs

2,053 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Allocation Without LimitsCWE-770 × clear
Onos HIGH 7.5
CVE-2017-13763

ONOS versions 1.8.0, 1.9.0, and 1.10.0 do not restrict the amount of memory allocated. The Netty payload size is not limited.

Mitigation only
Fix from $1,950 2017-08-30
Imagemagick MEDIUM 6.5
CVE-2017-12875

The WritePixelCachePixels function in ImageMagick 7.0.6-6 allows remote attackers to cause a denial of service (CPU consumption) via a crafted file.

Patch available
Fix from $1,600 2017-08-29
Binutils MEDIUM 5.5
CVE-2017-13716

The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of servi…

Patch available
Fix from $1,600 2017-08-28
Imagemagick MEDIUM 6.5
CVE-2017-13133

In ImageMagick 7.0.6-8, the load_level function in coders/xcf.c lacks offset validation, which allows attackers to cause a denial of service (load_ti…

Patch available
Fix from $1,600 2017-08-23
Android HIGH 7.8
CVE-2017-8253

In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid master is …

Patch available
Fix from $1,950 2017-08-18
Libtiff HIGH 7.5
CVE-2017-12944

The TIFFReadDirEntryArray function in tif_read.c in LibTIFF 4.0.8 mishandles memory allocation for short files, which allows remote attackers to caus…

Mitigation only
Fix from $1,950 2017-08-18
Android MEDIUM 5.5
CVE-2017-0725

A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.

Patch available
Fix from $1,600 2017-08-09
Debian Linux MEDIUM 6.5
CVE-2017-12643

ImageMagick 7.0.6-1 has a memory exhaustion vulnerability in ReadOneJNGImage in coders\png.c.

Patch available
Fix from $1,600 2017-08-07
Imagemagick MEDIUM 6.5
CVE-2017-12563

In ImageMagick 7.0.6-2, a memory exhaustion vulnerability was found in the function ReadPSDImage in coders/psd.c, which allows attackers to cause a d…

Patch available
Fix from $1,600 2017-08-05
Imagemagick HIGH 7.5
CVE-2017-12429

In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a…

Patch available
Fix from $1,950 2017-08-04
Imagemagick HIGH 7.5
CVE-2017-12430

In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadMPCImage in coders/mpc.c, which allows attackers to cause a d…

Patch available
Fix from $1,950 2017-08-04
Imagemagick MEDIUM 6.5
CVE-2017-12432

In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadPCXImage in coders/pcx.c, which allows attackers to cause a d…

Patch available
Fix from $1,600 2017-08-04
Imagemagick HIGH 7.5
CVE-2017-12435

In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadSUNImage in coders/sun.c, which allows attackers to cause a d…

Patch available
Fix from $1,950 2017-08-04
Ytnef MEDIUM 5.5
CVE-2017-12144

In ytnef 1.9.2, an allocation failure was found in the function TNEFFillMapi in ytnef.c, which allows attackers to cause a denial of service via a cr…

Mitigation only
Fix from $1,600 2017-08-02
Glibc MEDIUM 5.9
CVE-2017-12132

The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses f…

Fix: after 2.25
Fix from $1,600 2017-08-01
Bigfix Platform HIGH 7.5
CVE-2017-1227

IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.

Patch available
Fix from $1,950 2017-07-31
Imagemagick MEDIUM 6.5
CVE-2017-11525

The ReadCINImage function in coders/cin.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (…

Fix: after 6.9.9-0
Fix from $1,600 2017-07-23
Docker Registry HIGH 7.5
CVE-2017-11468

Docker Registry before 2.6.2 in Docker Distribution does not properly restrict the amount of content accepted from a user, which allows remote attack…

Fix: after 2.6.1
Fix from $1,950 2017-07-20
Elastic Services Controller CRITICAL 9.8
CVE-2017-6713

A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access …

Mitigation only
Fix from $2,300 2017-07-06
Gdb MEDIUM 5.5
CVE-2017-9778

GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file ca…

Fix: after 8.0
Fix from $1,600 2017-06-21
Prime Data Center Network Manager CRITICAL 9.8
CVE-2017-6640EPSS 11%

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administr…

Mitigation only
Fix from $2,300 2017-06-08
Wireshark HIGH 7.5
CVE-2017-9350

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors…

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Remote Expert Manager HIGH 7.5
CVE-2017-6641

A vulnerability in the TCP connection handling functionality of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote at…

Mitigation only
Fix from $1,950 2017-05-22
Identity Services Engine HIGH 7.5
CVE-2017-6653

A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2017-05-22
Binutils MEDIUM 5.5
CVE-2017-9039

GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related…

Patch available
Fix from $1,600 2017-05-18
Linux Kernel HIGH 7.0
CVE-2017-0612

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t…

Patch available
Fix from $1,950 2017-05-12
Rpcbind HIGH 7.5
CVE-2017-8779EPSS 81%

rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size duri…

Fix: after 1.4.3
Fix from $1,950 2017-05-04
Ireceivables HIGH 7.5
CVE-2017-3555

Vulnerability in the Oracle iReceivables component of Oracle E-Business Suite (subcomponent: Self Registration). Supported versions that are affected…

Mitigation only
Fix from $1,950 2017-04-24
PHP HIGH 7.5
CVE-2017-7963

The GNU Multiple Precision Arithmetic Library (GMP) interfaces for PHP through 7.1.4 allow attackers to cause a denial of service (memory consumption…

Fix: after 7.1.4
Fix from $1,950 2017-04-19
Sso Authentication Library HIGH 7.5
CVE-2017-7696EPSS 36%

SAP AS JAVA SSO Authentication Library 2.0 through 3.0 allow remote attackers to cause a denial of service (memory consumption) via large values in t…

Mitigation only
Fix from $1,950 2017-04-14