Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux HIGH 7.5
CVE-2016-3993

Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (ou…

Fix: after 1.4.8
Fix from $1,950 2016-05-13
Debian Linux CRITICAL 9.8
CVE-2016-2195EPSS 7%

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possib…

Fix: after 1.10.10
Fix from $2,300 2016-05-13
Debian Linux HIGH 8.8
CVE-2016-3710

The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute ar…

Fix: after 7.0
Fix from $1,950 2016-05-11
Debian Linux HIGH 8.8
CVE-2016-2806

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to …

Fix: after 45.0.2
Fix from $1,950 2016-04-30
Debian Linux MEDIUM 5.9
CVE-2016-4079

epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which …

Mitigation only
Fix from $1,600 2016-04-25
Debian Linux HIGH 8.8
CVE-2016-1653

The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cau…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Debian Linux MEDIUM 5.5
CVE-2015-8683

The putcontig8bitCIELab function in tif_getimage.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a p…

Mitigation only
Fix from $1,600 2016-04-13
Debian Linux MEDIUM 6.5
CVE-2015-1547

The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted TIF…

Fix: after 4.0.6
Fix from $1,600 2016-04-13
Debian Linux MEDIUM 6.5
CVE-2014-9655

The (1) putcontig8bitYCbCr21tile function in tif_getimage.c or (2) NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a de…

Fix: after 4.0.6
Fix from $1,600 2016-04-13
Debian Linux HIGH 8.8
CVE-2016-3982

Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bo…

Fix: after 0.7.5
Fix from $1,950 2016-04-13
Debian Linux CRITICAL 9.8
CVE-2016-2054EPSS 6%

Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary cod…

Patch available
Fix from $2,300 2016-04-13
Debian Linux CRITICAL 9.8
CVE-2015-8710

The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds h…

Fix: 2.9.3+
Fix from $2,300 2016-04-11
Debian Linux CRITICAL 9.8
CVE-2016-2385EPSS 31%

Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows r…

Fix: after 4.3.4
Fix from $2,300 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6700

The decode_search function in dhcp.c in dhcpcd 3.x does not properly free allocated memory, which allows remote DHCP servers to cause a denial of ser…

Patch available
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6699

The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds read) via a crafted respons…

Patch available
Fix from $1,950 2016-04-11
Debian Linux HIGH 7.5
CVE-2012-6698

The decode_search function in dhcp.c in dhcpcd 3.x allows remote DHCP servers to cause a denial of service (out-of-bounds write) via a crafted respon…

Patch available
Fix from $1,950 2016-04-11
Debian Linux CRITICAL 9.8
CVE-2016-2851EPSS 25%

Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and ap…

Fix: after 4.1.0
Fix from $2,300 2016-04-07
Debian Linux HIGH 7.3
CVE-2015-8837

Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (a…

Fix: after 20070708
Fix from $1,950 2016-03-30
Debian Linux HIGH 8.8
CVE-2016-1649

The Program::getUniformInternal function in Program.cpp in libANGLE, as used in Google Chrome before 49.0.2623.108, does not properly handle a certai…

Fix: after 49.0.2623.95
Fix from $1,950 2016-03-29
Debian Linux HIGH 8.1
CVE-2016-2342EPSS 12%

The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when a certain VPNv4 configuration…

Mitigation only
Fix from $1,950 2016-03-17
Debian Linux MEDIUM 6.5
CVE-2016-2037EPSS 5%

The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted c…

Mitigation only
Fix from $1,600 2016-02-22
Debian Linux HIGH 8.1
CVE-2015-7547EPSS 90%

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6)…

Patch available
Fix from $1,950 2016-02-18
Debian Linux HIGH 8.1
CVE-2016-1526

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before…

Fix: after 38.5.1
Fix from $1,950 2016-02-13
Debian Linux HIGH 8.8
CVE-2016-1521

The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38…

Fix: after 42.0
Fix from $1,950 2016-02-13
Debian Linux MEDIUM 6.5
CVE-2016-2073

The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML doc…

Fix: 2.9.4+
Fix from $1,600 2016-02-12
Debian Linux MEDIUM 5.0
CVE-2015-8317EPSS 6%

The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterm…

Fix: after 2.9.2
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 6.4
CVE-2015-8241EPSS 5%

The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (h…

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 5.0
CVE-2015-7500EPSS 6%

The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap rea…

Mitigation only
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 5.0
CVE-2015-7497EPSS 7%

Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a den…

Fix: after 2.9.2
Fix from $1,600 2015-12-15
Debian Linux MEDIUM 6.8
CVE-2015-7942

The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, whi…

Fix: after 10.11.3
Fix from $1,600 2015-11-18