Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux MEDIUM 6.5
CVE-2017-16353EPSS 14%

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…

No fix yet
Fix from $1,600 2017-11-01
Debian Linux MEDIUM 5.9
CVE-2017-15722

In certain cases, Irssi before 1.0.5 may fail to verify that a Safe channel ID is long enough, causing reads beyond the end of the string.

Fix: after 1.0.4
Fix from $1,600 2017-10-22
Debian Linux HIGH 7.5
CVE-2017-14976

The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font d…

Patch available
Fix from $1,950 2017-10-02
Debian Linux MEDIUM 6.5
CVE-2017-14733

ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2017-09-25
Debian Linux HIGH 8.1
CVE-2017-14245

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14246

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14633

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…

Mitigation only
Fix from $1,600 2017-09-21
Debian Linux CRITICAL 9.8
CVE-2017-13687

The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13725

The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13024

The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13028

The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13004

The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-13020

The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12896

The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12899

The DECnet parser in tcpdump before 4.9.2 has a buffer over-read in print-decnet.c:decnet_print().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12902

The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions.

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux CRITICAL 9.8
CVE-2017-12987

The IEEE 802.11 parser in tcpdump before 4.9.2 has a buffer over-read in print-802_11.c:parse_elements().

Fix: after 4.9.1
Fix from $2,300 2017-09-14
Debian Linux MEDIUM 6.5
CVE-2017-14314

Off-by-one error in the DrawImage function in magick/render.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (DrawDash…

Patch available
Fix from $1,600 2017-09-12
Debian Linux MEDIUM 6.5
CVE-2017-14166

libarchive 3.3.2 allows remote attackers to cause a denial of service (xml_data heap-based buffer over-read and application crash) via a crafted xar …

Patch available
Fix from $1,600 2017-09-06
Debian Linux MEDIUM 6.5
CVE-2017-14132

JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.90…

Patch available
Fix from $1,600 2017-09-04
Debian Linux CRITICAL 9.1
CVE-2017-14122

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.

Mitigation only
Fix from $2,300 2017-09-03
Debian Linux MEDIUM 5.5
CVE-2017-13672

QEMU (aka Quick Emulator), when built with the VGA display emulator support, allows local guest OS privileged users to cause a denial of service (out…

Fix: after 2.10.2
Fix from $1,600 2017-09-01
Debian Linux MEDIUM 5.5
CVE-2017-13755

In The Sleuth Kit (TSK) 4.4.2, opening a crafted ISO 9660 image triggers an out-of-bounds read in iso9660_proc_dir() in tsk/fs/iso9660_dent.c in libt…

Patch available
Fix from $1,600 2017-08-29
Debian Linux CRITICAL 9.8
CVE-2017-13139

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds read with the MNG CLIP chunk.

Fix: after 6.9.9-0
Fix from $2,300 2017-08-23
Debian Linux HIGH 8.8
CVE-2017-12935

The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColo…

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12937

The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.

Patch available
Fix from $1,950 2017-08-18
Debian Linux HIGH 8.8
CVE-2017-12640

ImageMagick 7.0.6-1 has an out-of-bounds read vulnerability in ReadOneMNGImage in coders/png.c.

Patch available
Fix from $1,950 2017-08-07
Debian Linux HIGH 8.8
CVE-2017-12598

OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the cv::RBaseStream::readBlock function in modules/imgcod…

Fix: after 3.3.0
Fix from $1,950 2017-08-07
Debian Linux HIGH 8.8
CVE-2017-12599

OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds read error in the function icvCvt_BGRA2BGR_8u_C4C3R when reading an ima…

Fix: after 3.3.0
Fix from $1,950 2017-08-07
Debian Linux MEDIUM 5.5
CVE-2017-11358EPSS 7%

The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and appl…

No fix yet
Fix from $1,600 2017-07-31