Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux CRITICAL 9.8
CVE-2017-5202

The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5203

The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5204EPSS 6%

The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2017-5205

The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().

Fix: 4.9.0+
Fix from $2,300 2017-01-28
Debian Linux CRITICAL 9.8
CVE-2016-9427

Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) an…

Fix: after 7.4.4
Fix from $2,300 2016-12-12
Debian Linux HIGH 7.5
CVE-2016-1246

Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors re…

Fix: after 4.036
Fix from $1,950 2016-10-05
Debian Linux CRITICAL 9.8
CVE-2016-1243EPSS 5%

Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.

Patch available
Fix from $2,300 2016-10-03
Debian Linux HIGH 7.5
CVE-2016-7045

The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corrupti…

Fix: after 0.8.19
Fix from $1,950 2016-09-27
Debian Linux HIGH 7.5
CVE-2016-7044

The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers t…

Fix: after 0.8.19
Fix from $1,950 2016-09-27
Debian Linux HIGH 8.8
CVE-2016-4738

libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a …

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Debian Linux CRITICAL 9.8
CVE-2016-6525

Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (cra…

Fix: after 1.9
Fix from $2,300 2016-09-22
Debian Linux CRITICAL 9.8
CVE-2016-6354EPSS 9%

Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of servi…

Fix: after 2.6.0
Fix from $2,300 2016-09-21
Debian Linux MEDIUM 5.9
CVE-2016-7179

Stack-based buffer overflow in epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 allows remot…

Patch available
Fix from $1,600 2016-09-09
Debian Linux MEDIUM 5.9
CVE-2016-7177

epan/dissectors/packet-catapult-dct2000.c in the Catapult DCT2000 dissector in Wireshark 2.x before 2.0.6 does not restrict the number of channels, w…

Patch available
Fix from $1,600 2016-09-09
Debian Linux CRITICAL 9.1
CVE-2016-6254EPSS 6%

Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a…

Fix: 5.4.3 / 5.5.2+
Fix from $2,300 2016-08-19
Debian Linux MEDIUM 6.5
CVE-2016-6207EPSS 6%

Integer overflow in the _gdContributionsAlloc function in gd_interpolation.c in GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers …

Fix: 5.5.38 / 5.6.24+
Fix from $1,600 2016-08-12
Debian Linux CRITICAL 9.1
CVE-2016-5116

gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers …

Fix: after 2.2.1
Fix from $2,300 2016-08-07
Debian Linux HIGH 7.8
CVE-2016-3822

exif.c in Matthias Wandel jhead 2.87, as used in libjhead in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08…

Patch available
Fix from $1,950 2016-08-05
Debian Linux HIGH 7.8
CVE-2016-5829

Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kernel through 4.6.3 allow local …

Fix: 3.2.82 / 3.10.103+
Fix from $1,950 2016-06-27
Debian Linux MEDIUM 6.3
CVE-2016-5728

Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local use…

Fix: after 4.6
Fix from $1,600 2016-06-27
Debian Linux HIGH 8.8
CVE-2016-3062

The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (mem…

Fix: after 11.6
Fix from $1,950 2016-06-16
Debian Linux HIGH 7.5
CVE-2016-4478

Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a …

Fix: after 7.2.6
Fix from $1,950 2016-06-13
Debian Linux CRITICAL 9.8
CVE-2016-0749EPSS 8%

The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $2,300 2016-06-09
Debian Linux CRITICAL 9.8
CVE-2016-5108EPSS 25%

Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause …

Fix: after 2.2.3
Fix from $2,300 2016-06-08
Debian Linux HIGH 8.8
CVE-2016-2335EPSS 10%

The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of servi…

No fix yet
Fix from $1,950 2016-06-07
Debian Linux HIGH 8.8
CVE-2016-1681

Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, all…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Debian Linux HIGH 7.8
CVE-2016-1840

Heap-based buffer overflow in the xmlFAParsePosCharGroup function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tv…

Patch available
Fix from $1,950 2016-05-20
Debian Linux HIGH 8.8
CVE-2016-1669

The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to e…

Fix: 0.10.46 / 0.12.15+
Fix from $1,950 2016-05-14
Debian Linux CRITICAL 9.8
CVE-2016-4024EPSS 6%

Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which…

Fix: after 1.4.8
Fix from $2,300 2016-05-13
Debian Linux HIGH 8.2
CVE-2016-3994

The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a …

Fix: after 1.4.8
Fix from $1,950 2016-05-13