Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux CRITICAL 9.8
CVE-2017-5410

Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is mana…

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5398

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …

Fix: 45.8.0 / 52.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2016-9893

Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …

Fix: 45.6.0 / 50.1+
Fix from $2,300 2018-06-11
Debian Linux MEDIUM 5.5
CVE-2018-1000199

The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory …

Patch available
Fix from $1,600 2018-05-24
Debian Linux MEDIUM 6.5
CVE-2018-10958

In types.cpp in Exiv2 0.26, a large size value may lead to a SIGABRT during an attempt at memory allocation for an Exiv2::Internal::PngChunk::zlibUnc…

No fix yet
Fix from $1,600 2018-05-10
Debian Linux HIGH 7.8
CVE-2018-10537

An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWa…

Fix: after 5.1.0
Fix from $1,950 2018-04-29
Debian Linux HIGH 8.8
CVE-2017-14442

An exploitable code execution vulnerability exists in the BMP image rendering functionality of SDL2_image-2.0.2. A specially crafted BMP image can ca…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.1
CVE-2017-14450

A buffer overflow vulnerability exists in the GIF image parsing functionality of SDL2_image-2.0.2. A specially crafted GIF image can lead to a buffer…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux MEDIUM 5.5
CVE-2016-9601

ghostscript before version 9.21 is vulnerable to a heap based buffer overflow that was found in the ghostscript jbig2_decode_gray_scale_image functio…

Fix: 9.21+
Fix from $1,600 2018-04-24
Debian Linux CRITICAL 9.8
CVE-2017-17833

OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or …

Patch available
Fix from $2,300 2018-04-23
Debian Linux CRITICAL 9.8
CVE-2017-0357

A heap-overflow flaw exists in the -tr loader of iucode-tool starting with v1.4 and before v2.1.1, potentially leading to SIGSEGV, or heap corruption.

Fix: 2.1.1+
Fix from $2,300 2018-04-13
Debian Linux HIGH 8.8
CVE-2017-7000

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "SQLite" c…

Fix: 10.3.2 / 10.12.5+
Fix from $1,950 2018-04-03
Debian Linux MEDIUM 6.5
CVE-2018-7874

An invalid memory address dereference was discovered in strlenext in util/decompile.c in libming 0.4.8. The vulnerability causes a segmentation fault…

No fix yet
Fix from $1,600 2018-03-08
Debian Linux HIGH 7.8
CVE-2018-7752

GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1…

Fix: after 0.7.1
Fix from $1,950 2018-03-07
Debian Linux CRITICAL 9.8
CVE-2018-7552

There is an invalid free in Mapping::DoubleHash::clear in mapping.cpp that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead t…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux HIGH 7.5
CVE-2018-7284EPSS 58%

A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asterisk through 13.1…

Fix: after 15.2.1
Fix from $1,950 2018-02-22
Debian Linux MEDIUM 5.9
CVE-2015-5314

The eap_pwd_process function in eap_server/eap_server_pwd.c in hostapd 2.x before 2.6 does not validate that the reassembly buffer is large enough fo…

Fix: 2.6+
Fix from $1,600 2018-02-21
Debian Linux MEDIUM 5.9
CVE-2015-5315

The eap_pwd_process function in eap_peer/eap_pwd.c in wpa_supplicant 2.x before 2.6 does not validate that the reassembly buffer is large enough for …

Fix: 2.6+
Fix from $1,600 2018-02-21
Debian Linux CRITICAL 9.8
CVE-2017-7376EPSS 23%

Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.

Fix: 2.9.5+
Fix from $2,300 2018-02-19
Debian Linux MEDIUM 5.9
CVE-2018-5378EPSS 74%

The Quagga BGP daemon (bgpd) prior to version 1.2.3 does not properly bounds check the data sent with a NOTIFY to a peer, if an attribute length is i…

Fix: after 1.2.2
Fix from $1,600 2018-02-19
Debian Linux CRITICAL 9.8
CVE-2018-0487

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer ov…

Fix: 1.3.22 / 2.1.10+
Fix from $2,300 2018-02-13
Debian Linux HIGH 8.8
CVE-2018-6799

The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap ove…

Fix: 1.3.28+
Fix from $1,950 2018-02-07
Debian Linux HIGH 7.8
CVE-2018-5996

Insufficient exception handling in the method NCompress::NRar3::CDecoder::Code of 7-Zip before 18.00 and p7zip can lead to multiple memory corruption…

Fix: 18.00 / 18.0+
Fix from $1,950 2018-01-31
Debian Linux CRITICAL 9.8
CVE-2017-12379EPSS 13%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $2,300 2018-01-26
Debian Linux HIGH 7.8
CVE-2017-12376EPSS 7%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $1,950 2018-01-26
Debian Linux HIGH 7.5
CVE-2017-12375EPSS 6%

The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denia…

Fix: after 0.99.2
Fix from $1,950 2018-01-26
Debian Linux MEDIUM 5.5
CVE-2018-6192

In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violatio…

No fix yet
Fix from $1,600 2018-01-24
Debian Linux CRITICAL 9.8
CVE-2018-5208

In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.

Fix: 1.0.6+
Fix from $2,300 2018-01-06
Debian Linux HIGH 8.8
CVE-2017-1000456

freedesktop.org libpoppler 0.60.1 fails to validate boundaries in TextPool::addWord, leading to overflow in subsequent calculations.

Patch available
Fix from $1,950 2018-01-02
Debian Linux MEDIUM 6.5
CVE-2017-17760

OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size value is used.

Patch available
Fix from $1,600 2017-12-29