Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux MEDIUM 5.5
CVE-2018-20360

An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (F…

Fix: 2.9.0+
Fix from $1,600 2018-12-22
Debian Linux MEDIUM 6.5
CVE-2018-20097

There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote…

Patch available
Fix from $1,600 2018-12-12
Debian Linux HIGH 7.8
CVE-2018-19491

An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in …

Patch available
Fix from $1,950 2018-11-23
Debian Linux HIGH 7.8
CVE-2018-19492

An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in…

Patch available
Fix from $1,950 2018-11-23
Debian Linux HIGH 8.1
CVE-2018-18820EPSS 49%

A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP cl…

Fix: 2.4.4+
Fix from $1,950 2018-11-05
Debian Linux MEDIUM 6.5
CVE-2018-18520

An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar…

Fix: after 0.174
Fix from $1,600 2018-10-19
Debian Linux CRITICAL 9.8
CVE-2018-5188

Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presum…

Fix: 52.9 / 60.1.0+
Fix from $2,300 2018-10-18
Debian Linux CRITICAL 9.8
CVE-2018-5187

Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough …

Fix: 60.0 / 60.1.0+
Fix from $2,300 2018-10-18
Debian Linux MEDIUM 5.5
CVE-2018-18310

An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows …

Fix: after 0.174
Fix from $1,600 2018-10-15
Debian Linux HIGH 7.5
CVE-2018-17540

The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate.

Fix: 5.7.1+
Fix from $1,950 2018-10-03
Debian Linux MEDIUM 6.5
CVE-2017-15415

Incorrect serialization in IPC in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the value of a pointer via a crafted HTML pag…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Debian Linux HIGH 8.8
CVE-2018-10858

A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use th…

Fix: 4.6.16 / 4.7.9+
Fix from $1,950 2018-08-22
Debian Linux HIGH 7.8
CVE-2018-1000637

zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary…

Fix: after 1.8
Fix from $1,950 2018-08-20
Debian Linux HIGH 8.8
CVE-2018-10873

A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds check…

Patch available
Fix from $1,950 2018-08-17
Debian Linux CRITICAL 9.8
CVE-2015-9262EPSS 6%

_XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a…

Fix: 1.1.15+
Fix from $2,300 2018-08-01
Debian Linux HIGH 7.8
CVE-2016-8654

A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before…

Fix: 2.0.0+
Fix from $1,950 2018-08-01
Debian Linux HIGH 8.8
CVE-2016-9577

A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to th…

Fix: 0.13.90+
Fix from $1,950 2018-07-27
Debian Linux HIGH 8.1
CVE-2018-5178

A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requi…

Fix: 52.8.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5145

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that som…

Fix: 52.7.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5150

Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and w…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7826

Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.5.0 / 57.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7810

Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.4.0 / 56.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7785

A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially e…

Fix: 52.3.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7786

A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. …

Fix: 52.1.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7792

A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). …

Fix: 52.3.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-7779

Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and w…

Fix: 52.3.0 / 55.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5464

During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory…

Fix: 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5469

Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox…

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5470

Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with…

Fix: 52.2.0 / 54.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 7.5
CVE-2017-5444EPSS 7%

A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This…

Fix: 45.9.0 / 53.0+
Fix from $1,950 2018-06-11