Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux HIGH 7.8
CVE-2017-17866

pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allow…

Fix: 1.12.0+
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.5
CVE-2016-1254

Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.

Fix: 0.2.8.12+
Fix from $1,950 2017-12-05
Debian Linux HIGH 7.5
CVE-2017-8821

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, an attacker can …

Fix: 0.2.5.16 / 0.2.8.17+
Fix from $1,950 2017-12-03
Debian Linux HIGH 8.4
CVE-2017-16927

The scp_v0s_accept function in sesman/libscp/libscp_v0.c in the session manager in xrdp through 0.9.4 uses an untrusted integer as a write length, wh…

Fix: after 0.9.4
Fix from $1,950 2017-11-23
Debian Linux CRITICAL 9.8
CVE-2017-16872

An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. Parsing the numeric header fields in a SIP message (like cse…

Fix: 2.7.1+
Fix from $2,300 2017-11-17
Debian Linux CRITICAL 9.1
CVE-2017-8807

vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sen…

Fix: 4.1.9 / 5.2.1+
Fix from $2,300 2017-11-16
Debian Linux HIGH 8.8
CVE-2017-16669

coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or poss…

Patch available
Fix from $1,950 2017-11-09
Debian Linux HIGH 8.8
CVE-2017-16352EPSS 15%

GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image directory" feature of the Descri…

No fix yet
Fix from $1,950 2017-11-01
Debian Linux CRITICAL 9.1
CVE-2017-1000257EPSS 6%

An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl woul…

Fix: after 7.56.0
Fix from $2,300 2017-10-31
Debian Linux MEDIUM 5.5
CVE-2017-15953

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow and crash when processing a malformed CUE (.cue) file.

Patch available
Fix from $1,600 2017-10-28
Debian Linux MEDIUM 5.5
CVE-2017-15954

bchunk (related to BinChunker) 1.2.0 and 1.2.1 is vulnerable to a heap-based buffer overflow (with a resultant invalid free) and crash when processin…

Patch available
Fix from $1,600 2017-10-28
Debian Linux HIGH 8.8
CVE-2017-13089EPSS 80%

The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget b…

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Debian Linux HIGH 8.8
CVE-2017-13090EPSS 37%

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser …

Fix: after 1.19.1
Fix from $1,950 2017-10-27
Debian Linux MEDIUM 5.5
CVE-2017-15370

There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux MEDIUM 5.5
CVE-2017-15372

There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will le…

No fix yet
Fix from $1,600 2017-10-16
Debian Linux HIGH 7.8
CVE-2017-13723

In X.Org Server (aka xserver and xorg-server) before 1.19.4, a local attacker authenticated to the X server could overflow a global buffer, causing c…

Fix: after 1.19.3
Fix from $1,950 2017-10-10
Debian Linux HIGH 8.8
CVE-2017-14160

The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux CRITICAL 9.8
CVE-2017-14632EPSS 6%

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…

Mitigation only
Fix from $2,300 2017-09-21
Debian Linux HIGH 8.8
CVE-2017-2816

An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write…

No fix yet
Fix from $1,950 2017-09-13
Debian Linux HIGH 8.8
CVE-2017-14151EPSS 5%

An off-by-one error was discovered in opj_tcd_code_block_enc_allocate_data in lib/openjp2/tcd.c in OpenJPEG 2.2.0. The vulnerability causes an out-of…

Patch available
Fix from $1,950 2017-09-05
Debian Linux MEDIUM 5.5
CVE-2017-13760

In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.

No fix yet
Fix from $1,600 2017-08-29
Debian Linux CRITICAL 9.8
CVE-2017-12865EPSS 6%

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbit…

Fix: after 1.34
Fix from $2,300 2017-08-29
Debian Linux MEDIUM 6.5
CVE-2017-13063

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux MEDIUM 6.5
CVE-2017-13064

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux CRITICAL 9.8
CVE-2017-12562

Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of…

Patch available
Fix from $2,300 2017-08-05
Debian Linux CRITICAL 9.8
CVE-2017-12424

In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may l…

Fix: 4.5+
Fix from $2,300 2017-08-04
Debian Linux MEDIUM 5.5
CVE-2017-11732

A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, whic…

Mitigation only
Fix from $1,600 2017-07-29
Debian Linux HIGH 7.5
CVE-2017-10978

An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.

Fix: 2.2.10 / 3.0.15+
Fix from $1,950 2017-07-17
Debian Linux HIGH 8.8
CVE-2017-9992

Heap-based buffer overflow in the decode_dds1 function in libavcodec/dfa.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x bef…

Fix: 2.8.12 / 3.0.8+
Fix from $1,950 2017-06-28
Debian Linux HIGH 7.8
CVE-2017-9994

libavcodec/webp.c in FFmpeg before 2.8.12, 3.0.x before 3.0.8, 3.1.x before 3.1.8, 3.2.x before 3.2.5, and 3.3.x before 3.3.1 does not ensure that pi…

Fix: 2.8.12 / 3.0.8+
Fix from $1,950 2017-06-28