Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 8.8
CVE-2018-7437

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in a memcpy call of the parse_SST function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7438

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the parse_unicode_string function.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 8.8
CVE-2018-7439

An issue was discovered in FreeXL before 1.0.5. There is a heap-based buffer over-read in the function read_mini_biff_next_record.

Fix: 1.0.5+
Fix from $1,950 2018-02-23
Debian Linux HIGH 7.8
CVE-2018-7253

The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buff…

Patch available
Fix from $1,950 2018-02-19
Debian Linux HIGH 7.8
CVE-2018-7254EPSS 10%

The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-…

Patch available
Fix from $1,950 2018-02-19
Debian Linux HIGH 7.5
CVE-2018-7051

An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme str…

Fix: 1.0.7+
Fix from $1,950 2018-02-15
Debian Linux HIGH 7.8
CVE-2018-6767

A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-o…

Patch available
Fix from $1,950 2018-02-06
Debian Linux MEDIUM 6.5
CVE-2018-6621

The decode_frame function in libavcodec/utvideodec.c in FFmpeg through 3.2 allows remote attackers to cause a denial of service (out of array read) v…

Fix: after 3.2
Fix from $1,600 2018-02-05
Debian Linux MEDIUM 6.5
CVE-2018-6392

The filter_slice function in libavfilter/vf_transpose.c in FFmpeg through 3.4.1 allows remote attackers to cause a denial of service (out-of-array ac…

Fix: after 3.4.1
Fix from $1,600 2018-01-29
Debian Linux CRITICAL 9.8
CVE-2017-12377EPSS 12%

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $2,300 2018-01-26
Debian Linux MEDIUM 5.5
CVE-2017-12378

ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of…

Fix: after 0.99.2
Fix from $1,600 2018-01-26
Debian Linux HIGH 8.8
CVE-2018-6315

The outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant out-of-bounds re…

Fix: after 0.4.8
Fix from $1,950 2018-01-25
Debian Linux CRITICAL 9.1
CVE-2018-1000005

libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pu…

Fix: after 7.57.0
Fix from $2,300 2018-01-24
Debian Linux MEDIUM 6.0
CVE-2018-5683

The vga_draw_text function in Qemu allows local OS guest privileged users to cause a denial of service (out-of-bounds read and QEMU process crash) by…

Patch available
Fix from $1,600 2018-01-23
Debian Linux HIGH 8.8
CVE-2018-5248

In ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the sixel_decode fun…

No fix yet
Fix from $1,950 2018-01-05
Debian Linux HIGH 8.8
CVE-2017-17912

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17913

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 8.8
CVE-2017-17915

In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte bef…

Patch available
Fix from $1,950 2017-12-27
Debian Linux HIGH 7.8
CVE-2017-17786

In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17787

In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.

Patch available
Fix from $1,950 2017-12-20
Debian Linux MEDIUM 5.5
CVE-2017-17788

In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' character after the version string.

Mitigation only
Fix from $1,600 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17782

In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17784

In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling o…

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.5
CVE-2017-17783

In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux HIGH 8.8
CVE-2017-17500

ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux HIGH 8.8
CVE-2017-17501

WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux HIGH 8.8
CVE-2017-17502

ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux HIGH 8.8
CVE-2017-17503

ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.

Patch available
Fix from $1,950 2017-12-11
Debian Linux CRITICAL 9.8
CVE-2017-16840

The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorre…

Patch available
Fix from $2,300 2017-11-21
Debian Linux HIGH 8.8
CVE-2017-15672

The read_header function in libavcodec/ffv1dec.c in FFmpeg 2.4 and 3.3.4 and possibly earlier allows remote attackers to have unspecified impact via …

Fix: after 3.3.4
Fix from $1,950 2017-11-06