Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 7.8
CVE-2017-11714

psi/ztoken.c in Artifex Ghostscript 9.21 mishandles references to the scanner state structure, which allows remote attackers to cause a denial of ser…

Patch available
Fix from $1,950 2017-07-28
Debian Linux HIGH 7.8
CVE-2017-9611

The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9726

The Ins_MDRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

Mitigation only
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9727

The gx_ttfReader__Read function in base/gxttfb.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-base…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9739

The Ins_JMPR function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux MEDIUM 5.5
CVE-2017-11434

The dhcp_decode function in slirp/bootp.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (out-of-bounds read a…

Fix: after 2.9.1
Fix from $1,600 2017-07-25
Debian Linux MEDIUM 5.5
CVE-2017-9865

The function GfxImageColorMap::getGray in GfxState.cc in Poppler 0.54.0 allows remote attackers to cause a denial of service (stack-based buffer over…

Mitigation only
Fix from $1,600 2017-06-25
Debian Linux MEDIUM 5.5
CVE-2017-8312

Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap uninitialized data via a craft…

Fix: 2.2.6+
Fix from $1,600 2017-05-23
Debian Linux HIGH 7.5
CVE-2017-7483

Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which results in a non-invertible i…

Patch available
Fix from $1,950 2017-05-02
Debian Linux MEDIUM 6.5
CVE-2017-8362

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash…

Patch available
Fix from $1,600 2017-04-30
Debian Linux MEDIUM 6.5
CVE-2017-8363

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and ap…

Patch available
Fix from $1,600 2017-04-30
Debian Linux MEDIUM 6.5
CVE-2017-8365

The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) …

Patch available
Fix from $1,600 2017-04-30
Debian Linux MEDIUM 5.5
CVE-2017-7718

hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and …

Fix: after 2.8.1.1
Fix from $1,600 2017-04-20
Debian Linux MEDIUM 5.5
CVE-2017-7697

In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.

Fix: after 0.1.8
Fix from $1,600 2017-04-11
Debian Linux MEDIUM 5.5
CVE-2016-5322

The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a c…

Fix: after 4.0.6
Fix from $1,600 2017-04-11
Debian Linux MEDIUM 5.5
CVE-2017-7608

The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buf…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7610

The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and applica…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7611

The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and …

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7612

The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and app…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 6.5
CVE-2017-5667

The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial …

Fix: after 2.8.1.1
Fix from $1,600 2017-03-16
Debian Linux CRITICAL 9.8
CVE-2016-10195EPSS 7%

The name_parse function in evdns.c in libevent before 2.1.6-beta allows remote attackers to have unspecified impact via vectors involving the label_l…

Fix: after 2.1.5
Fix from $2,300 2017-03-15
Debian Linux HIGH 7.5
CVE-2016-10197EPSS 5%

The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty…

Fix: after 2.1.5
Fix from $1,950 2017-03-15
Debian Linux HIGH 7.5
CVE-2017-6800

An issue was discovered in ytnef before 1.9.2. An invalid memory access (heap-based buffer over-read) can occur during handling of LONG data types, r…

Fix: after 1.9.1
Fix from $1,950 2017-03-10
Debian Linux HIGH 7.5
CVE-2017-6801

An issue was discovered in ytnef before 1.9.2. There is a potential out-of-bounds access with fields of Size 0 in TNEFParse() in libytnef.

Fix: after 1.9.1
Fix from $1,950 2017-03-10
Debian Linux HIGH 7.5
CVE-2017-6802

An issue was discovered in ytnef before 1.9.2. There is a potential heap-based buffer over-read on incoming Compressed RTF Streams, related to Decomp…

Fix: after 1.9.1
Fix from $1,950 2017-03-10
Debian Linux MEDIUM 5.5
CVE-2016-5315

The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a c…

Fix: after 4.0.6
Fix from $1,600 2017-03-07
Debian Linux HIGH 7.8
CVE-2016-10244

The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote atta…

Fix: 2.7.1+
Fix from $1,950 2017-03-06
Debian Linux MEDIUM 5.5
CVE-2017-6500

An issue was discovered in ImageMagick 6.9.7. A specially crafted sun file triggers a heap-based buffer over-read.

Patch available
Fix from $1,600 2017-03-06
Debian Linux HIGH 7.5
CVE-2017-5356

Irssi before 0.8.21 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a string containing a formatting sequence…

Fix: 0.8.21+
Fix from $1,950 2017-03-03
Debian Linux HIGH 7.8
CVE-2017-6301

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "4 of 9. Out of Bounds Reads."

Fix: after 1.9
Fix from $1,950 2017-02-24