Vulnerability index

Browse CVEs

598 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2017-8105

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function i…

Fix: 2.7.1+
Fix from $2,300 2017-04-24
Debian Linux CRITICAL 9.8
CVE-2017-7863

FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/…

Fix: after 2.8.10
Fix from $2,300 2017-04-14
Debian Linux CRITICAL 9.8
CVE-2017-7865

FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in…

Fix: after 2.8.9
Fix from $2,300 2017-04-14
Debian Linux CRITICAL 9.8
CVE-2015-6674

Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This iss…

Fix: after 2.0.19
Fix from $2,300 2017-04-13
Debian Linux CRITICAL 9.8
CVE-2016-1908EPSS 14%

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr…

Patch available
Fix from $2,300 2017-04-11
Debian Linux CRITICAL 9.8
CVE-2017-5511EPSS 5%

coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer ove…

Fix: 6.9.7-3 / 7.0.4-3+
Fix from $2,300 2017-03-24
Debian Linux CRITICAL 9.8
CVE-2017-5522

Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to caus…

Fix: after 6.0.5
Fix from $2,300 2017-03-15
Debian Linux CRITICAL 9.8
CVE-2016-10195EPSS 7%

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_l…

Fix: after 2.1.5
Fix from $2,300 2017-03-15
Debian Linux CRITICAL 9.8
CVE-2016-8863EPSS 7%

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attac…

Fix: after 1.6.20
Fix from $2,300 2017-03-07
Debian Linux CRITICAL 9.8
CVE-2016-1245

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Disco…

Fix: after 1.0.20160315
Fix from $2,300 2017-02-22
Debian Linux CRITICAL 9.8
CVE-2016-2148EPSS 27%

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involv…

Fix: after 1.24.2
Fix from $2,300 2017-02-09
Debian Linux CRITICAL 9.8
CVE-2016-7446

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. No…

Mitigation only
Fix from $2,300 2017-02-06
Debian Linux CRITICAL 9.8
CVE-2016-7447

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via u…

Fix: after 1.3.24
Fix from $2,300 2017-02-06
Debian Linux CRITICAL 9.8
CVE-2017-5202

The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5203

The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5204EPSS 6%

The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5205

The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2013-1430

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd …

Fix: after 0.8.0
Fix from $2,300 2016-12-16
Debian Linux CRITICAL 9.8
CVE-2016-9427

Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) an…

Fix: after 7.4.4
Fix from $2,300 2016-12-12
Debian Linux CRITICAL 9.8
CVE-2016-7117EPSS 24%

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbit…

Fix: 3.2.80 / 3.4.113+
Fix from $2,300 2016-10-10
Debian Linux CRITICAL 9.8
CVE-2016-7161EPSS 6%

Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code …

Fix: after 2.6.2
Fix from $2,300 2016-10-05
Debian Linux CRITICAL 9.8
CVE-2016-1243

Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.

Patch available
Fix from $2,300 2016-10-03
Debian Linux CRITICAL 9.8
CVE-2016-5180EPSS 9%

Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of…

Fix: 0.10.48 / 0.12.17+
Fix from $2,300 2016-10-03
Debian Linux CRITICAL 9.8
CVE-2016-4303EPSS 7%

The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (cra…

Fix: 3.0.12 / 3.1.3+
Fix from $2,300 2016-09-26
Debian Linux CRITICAL 9.8
CVE-2016-6525

Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (cra…

Fix: after 1.9
Fix from $2,300 2016-09-22
Debian Linux CRITICAL 9.8
CVE-2016-6354EPSS 6%

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of servi…

Fix: after 2.6.0
Fix from $2,300 2016-09-21
Debian Linux CRITICAL 9.8
CVE-2015-8871

Use-after-free vulnerability in the opj_j2k_write_mco function in j2k.c in OpenJPEG before 2.1.1 allows remote attackers to have unspecified impact v…

Fix: after 2.1.0
Fix from $2,300 2016-09-21
Debian Linux CRITICAL 9.1
CVE-2016-6254EPSS 5%

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a…

Fix: 5.4.3 / 5.5.2+
Fix from $2,300 2016-08-19
Debian Linux CRITICAL 9.8
CVE-2015-8949

Use-after-free vulnerability in the my_login function in DBD::mysql before 4.033_01 allows attackers to have unspecified impact by leveraging a call …

Patch available
Fix from $2,300 2016-08-19
Debian Linux CRITICAL 9.8
CVE-2014-9906EPSS 6%

Use-after-free vulnerability in DBD::mysql before 4.029 allows attackers to cause a denial of service (program crash) or possibly execute arbitrary c…

Fix: after 4.028
Fix from $2,300 2016-08-19