Vulnerability index

Browse CVEs

831 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Type ConfusionCWE-843 × clear
Debian Linux MEDIUM 6.5
CVE-2017-5094

Type confusion in extensions JavaScript bindings in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacke…

Fix: 60.0.3112.78+
Fix from $1,600 2017-10-27
Chrome HIGH 8.8
CVE-2017-5057

Type confusion in PDFium in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker …

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5059

Type confusion in Blink in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac, and 58.0.3029.83 for Android, allowed a remote attacker t…

Fix: 58.0.3029.81 / 58.0.3029.83+
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5070 KEVEPSS 31%

Type confusion in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac, and 59.0.3071.92 for Android, allowed a remote attacker to e…

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,950 2017-10-27
Enterprise Linux Desktop HIGH 8.8
CVE-2017-11292 KEVEPSS 12%

Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the…

Fix: after 27.0.0.159
Fix from $1,950 2017-10-22
Bento4 HIGH 8.8
CVE-2017-14639

AP4_VisualSampleEntry::ReadFields in Core/Ap4SampleEntry.cpp in Bento4 1.5.0-617 uses incorrect character data types, which causes a stack-based buff…

Patch available
Fix from $1,950 2017-09-21
Debian Linux HIGH 7.8
CVE-2017-8291 KEVEPSS 96%

Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile (%pipe%" …

Fix: 9.21+
Fix from $1,950 2017-04-27
Edge HIGH 8.1
CVE-2017-0037 KEVEPSS 80%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnS…

Patch available
Fix from $1,950 2017-02-26
Edge HIGH 8.8
CVE-2016-7201 KEVEPSS 80%

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corru…

Patch available
Fix from $1,950 2016-11-10
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4149

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11…

Fix: after 21.0.0.242
Fix from $1,950 2016-06-16
Flash Player HIGH 8.8
CVE-2016-1015EPSS 7%

Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to…

Fix: after 21.0.0.197
Fix from $1,950 2016-04-09
Flash Player HIGH 8.8
CVE-2016-0985EPSS 27%

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.…

Fix: after 20.0.0.286
Fix from $1,950 2016-02-10
Chrome HIGH 7.8
CVE-2014-1730

Google V8, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly store international…

Fix: 34.0.1847.131 / 34.0.1847.132+
Fix from $1,950 2014-04-26
Chrome HIGH 7.5
CVE-2014-1731

core/html/HTMLSelectElement.cpp in the DOM implementation in Blink, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0…

Fix: 34.0.1847.131 / 34.0.1847.132+
Fix from $1,950 2014-04-26
Chrome HIGH 7.5
CVE-2013-2882

Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impa…

Fix: 0.10.16+
Fix from $1,950 2013-07-31
Debian Linux CRITICAL 9.8
CVE-2012-0507 KEVEPSS 98%

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 …

Mitigation only
Fix from $2,300 2012-06-07
Chrome MEDIUM 6.8
CVE-2011-2875

Google V8, as used in Google Chrome before 14.0.835.163, does not properly perform object sealing, which allows remote attackers to cause a denial of…

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome HIGH 8.8
CVE-2011-0611 KEVEPSS 94%

Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; an…

Fix: 2.6.19140 / 9.4+
Fix from $1,950 2011-04-13
Chrome HIGH 7.5
CVE-2010-4577

The CSSParser::parseFontFaceSrc function in WebCore/css/CSSParser.cpp in WebKit, as used in Google Chrome before 8.0.552.224, Chrome OS before 8.0.55…

Fix: 1.2.6 / 8.0.552.224+
Fix from $1,950 2010-12-22
Chrome HIGH 10.0
CVE-2010-2299

The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-15
Excel HIGH 7.8
CVE-2010-0258EPSS 61%

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…

Patch available
Fix from $1,950 2010-03-10