Vulnerability index

Browse CVEs

411 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds ReadCWE-125 × clear
Debian Linux HIGH 7.8
CVE-2017-6304

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "7 of 9. Out of Bounds read."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6305

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and write."

Fix: after 1.9
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6309

An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid rea…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6310

An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to i…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Debian Linux MEDIUM 5.5
CVE-2017-6011

An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extr…

No fix yet
Fix from $1,600 2017-02-16
Debian Linux HIGH 7.5
CVE-2016-8682

The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a cr…

Patch available
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.5
CVE-2017-5847

The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a…

Fix: 1.11.2+
Fix from $1,950 2017-02-09
Debian Linux HIGH 7.5
CVE-2017-5848

The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of serv…

Fix: 1.11.2+
Fix from $1,950 2017-02-09
Debian Linux HIGH 7.5
CVE-2016-7449

The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) vi…

Mitigation only
Fix from $1,950 2017-02-06
Debian Linux MEDIUM 5.5
CVE-2016-9532

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of servi…

Fix: after 4.0.6
Fix from $1,600 2017-02-06
Debian Linux MEDIUM 5.3
CVE-2016-2518EPSS 15%

The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an add…

Patch available
Fix from $1,600 2017-01-30
Debian Linux MEDIUM 6.5
CVE-2016-7799

MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

Fix: 6.9.6-0 / 7.0.3-2+
Fix from $1,600 2017-01-18
Debian Linux HIGH 7.1
CVE-2015-8743

QEMU (aka Quick Emulator) built with the NE2000 device emulation support is vulnerable to an OOB r/w access issue. It could occur while performing 'i…

Fix: after 2.5.1
Fix from $1,950 2016-12-29
Debian Linux MEDIUM 6.5
CVE-2016-6214

gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted …

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 6.5
CVE-2016-6161

The output function in gd_gif_out.c in the GD Graphics Library (aka libgd) allows remote attackers to cause a denial of service (out-of-bounds read) …

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 6.5
CVE-2016-6132

The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of…

Fix: after 2.2.2
Fix from $1,600 2016-08-12
Debian Linux MEDIUM 5.5
CVE-2016-1833

The htmlCurrentChar function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2…

Patch available
Fix from $1,600 2016-05-20
Debian Linux HIGH 8.8
CVE-2016-1646 KEVEPSS 48%

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider elem…

Fix: 49.0.2623.108+
Fix from $1,950 2016-03-29
Debian Linux MEDIUM 6.5
CVE-2015-8783

tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.

Fix: 4.0.7+
Fix from $1,600 2016-02-01
Debian Linux MEDIUM 6.5
CVE-2012-1798

The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds…

Patch available
Fix from $1,600 2012-06-05
Debian Linux MEDIUM 6.5
CVE-2012-0259

The GetEXIFProperty function in magick/property.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (crash) via a ze…

Fix: 6.7.6-3+
Fix from $1,600 2012-06-05