Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux MEDIUM 5.5
CVE-2017-9928

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:979, which allows attackers to cause a denial of service vi…

Patch available
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9929

In lrzip 0.631, a stack buffer overflow was found in the function get_fileinfo in lrzip.c:1074, which allows attackers to cause a denial of service v…

Patch available
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 6.5
CVE-2017-9775

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) vi…

Fix: after 0.55.0
Fix from $1,600 2017-06-22
Debian Linux HIGH 7.5
CVE-2017-9469EPSS 6%

In Irssi before 1.0.3, when receiving certain incorrectly quoted DCC files, it tries to find the terminating quote one byte before the allocated memo…

Fix: after 1.0.2
Fix from $1,950 2017-06-07
Debian Linux HIGH 7.8
CVE-2017-8844

The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (heap-based buffer overflow and a…

Patch available
Fix from $1,950 2017-05-08
Debian Linux HIGH 8.8
CVE-2017-8361

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application cr…

Patch available
Fix from $1,950 2017-04-30
Debian Linux HIGH 7.5
CVE-2017-8073

WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes f…

Fix: 1.7.1+
Fix from $1,950 2017-04-23
Debian Linux CRITICAL 9.8
CVE-2015-6674

Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This iss…

Fix: after 2.0.19
Fix from $2,300 2017-04-13
Debian Linux CRITICAL 9.8
CVE-2017-5511EPSS 5%

coders/psd.c in ImageMagick allows remote attackers to have unspecified impact by leveraging an improper cast, which triggers a heap-based buffer ove…

Fix: 6.9.7-3 / 7.0.4-3+
Fix from $2,300 2017-03-24
Debian Linux MEDIUM 5.5
CVE-2016-9556

The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds he…

Patch available
Fix from $1,600 2017-03-23
Debian Linux MEDIUM 5.5
CVE-2017-6831

Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1,…

Patch available
Fix from $1,600 2017-03-20
Debian Linux MEDIUM 5.5
CVE-2017-6832

Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0…

Patch available
Fix from $1,600 2017-03-20
Debian Linux MEDIUM 5.5
CVE-2017-6834

Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1…

Patch available
Fix from $1,600 2017-03-20
Debian Linux MEDIUM 5.5
CVE-2017-6836

Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, …

Patch available
Fix from $1,600 2017-03-20
Debian Linux CRITICAL 9.8
CVE-2017-5522

Stack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4, 6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to caus…

Fix: after 6.0.5
Fix from $2,300 2017-03-15
Debian Linux CRITICAL 9.8
CVE-2016-8863EPSS 8%

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attac…

Fix: after 1.6.20
Fix from $2,300 2017-03-07
Debian Linux MEDIUM 5.5
CVE-2017-5974

Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows re…

No fix yet
Fix from $1,600 2017-03-01
Debian Linux HIGH 7.8
CVE-2017-6300

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "3 of 9. Buffer Overflow in version field in lib/tnef-types.h."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux CRITICAL 9.8
CVE-2016-1245

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Disco…

Fix: after 1.0.20160315
Fix from $2,300 2017-02-22
Debian Linux MEDIUM 5.5
CVE-2017-6009

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. T…

No fix yet
Fix from $1,600 2017-02-16
Debian Linux MEDIUM 5.5
CVE-2017-6010

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue…

No fix yet
Fix from $1,600 2017-02-16
Debian Linux HIGH 8.8
CVE-2016-8862

The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafte…

Fix: 6.9.4-0 / 7.0.3-3+
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.8
CVE-2016-8683

The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which trig…

Patch available
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.8
CVE-2016-8684

The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which t…

Patch available
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.5
CVE-2015-8979

Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers to cause a …

Fix: after 3.6.0
Fix from $1,950 2017-02-15
Debian Linux CRITICAL 9.8
CVE-2016-2148EPSS 27%

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involv…

Fix: after 1.24.2
Fix from $2,300 2017-02-09
Debian Linux CRITICAL 9.8
CVE-2016-7446

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. No…

Mitigation only
Fix from $2,300 2017-02-06
Debian Linux CRITICAL 9.8
CVE-2016-7447

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via u…

Fix: after 1.3.24
Fix from $2,300 2017-02-06
Debian Linux HIGH 7.5
CVE-2016-7800

Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of servic…

Fix: after 1.3.25
Fix from $1,950 2017-02-06
Debian Linux MEDIUM 5.5
CVE-2016-2317

Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the…

Mitigation only
Fix from $1,600 2017-02-03