Vulnerability index

Browse CVEs

198 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Integer OverflowCWE-190 × clear
Debian Linux MEDIUM 6.5
CVE-2020-14401

An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.

Fix: 0.9.13 / 3.2.1.0+
Fix from $1,600 2020-06-17
Debian Linux MEDIUM 6.8
CVE-2020-11039

In FreeRDP less than or equal to 2.0.0, when using a manipulated server with USB redirection enabled (nearly) arbitrary memory can be read and writte…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux MEDIUM 5.4
CVE-2020-11038

In FreeRDP less than or equal to 2.0.0, an Integer Overflow to Buffer Overflow exists. When using /video redirection, a manipulated server can instru…

Fix: 2.1.0+
Fix from $1,600 2020-05-29
Debian Linux CRITICAL 9.8
CVE-2020-11945EPSS 27%

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that ar…

Fix: 4.11 / 5.0.2+
Fix from $2,300 2020-04-23
Debian Linux HIGH 7.5
CVE-2020-6073

An exploitable denial-of-service vulnerability exists in the TXT record-parsing functionality of Videolabs libmicrodns 0.1.0. When parsing the RDATA …

No fix yet
Fix from $1,950 2020-03-24
Debian Linux CRITICAL 9.8
CVE-2020-10938EPSS 5%

GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

Fix: 1.3.35+
Fix from $2,300 2020-03-24
Debian Linux HIGH 8.8
CVE-2011-3631

Hardlink before 0.1.2 has multiple integer overflows leading to heap-based buffer overflows because of the way string lengths concatenation is done i…

Fix: 0.1.2+
Fix from $1,950 2019-11-26
Debian Linux HIGH 8.8
CVE-2019-5087

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools 1.0.7. An i…

No fix yet
Fix from $1,950 2019-11-21
Debian Linux HIGH 8.8
CVE-2019-5086

An exploitable integer overflow vulnerability exists in the flattenIncrementally function in the xcf2png and xcf2pnm binaries of xcftools, version 1.…

No fix yet
Fix from $1,950 2019-11-21
Debian Linux CRITICAL 9.8
CVE-2019-19012EPSS 11%

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offse…

Fix: after 6.9.3
Fix from $2,300 2019-11-17
Debian Linux MEDIUM 6.5
CVE-2010-4653

An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

Fix: 0.16.3+
Fix from $1,600 2019-11-13
Debian Linux MEDIUM 6.5
CVE-2019-14973

_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavio…

Fix: after 4.0.10
Fix from $1,600 2019-08-14
Debian Linux HIGH 7.5
CVE-2019-14459

nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order t…

Fix: after 1.6.17
Fix from $1,950 2019-07-31
Debian Linux MEDIUM 6.5
CVE-2019-9959

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereb…

Fix: after 0.78.0
Fix from $1,600 2019-07-22
Debian Linux HIGH 8.1
CVE-2019-13115EPSS 12%

In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-b…

Fix: 1.9.0+
Fix from $1,950 2019-07-16
Debian Linux HIGH 8.8
CVE-2019-5052

An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overf…

No fix yet
Fix from $1,950 2019-07-03
Debian Linux HIGH 8.8
CVE-2018-20847

An improper computation of p_tx0, p_tx1, p_ty0 and p_ty1 in the function opj_get_encoding_parameters in openjp2/pi.c in OpenJPEG through 2.3.0 can le…

Fix: after 2.3.0
Fix from $1,950 2019-06-26
Debian Linux HIGH 8.8
CVE-2019-3856EPSS 6%

An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are …

Patch available
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3857EPSS 6%

An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets…

Patch available
Fix from $1,950 2019-03-25
Debian Linux HIGH 8.8
CVE-2019-3863

A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive respons…

Fix: 1.8.1+
Fix from $1,950 2019-03-25
Debian Linux CRITICAL 9.8
CVE-2018-20177EPSS 8%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in the function rdp_in_unistr() a…

Fix: after 1.8.3
Fix from $2,300 2019-03-15
Debian Linux HIGH 7.8
CVE-2019-9210

In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted m…

No fix yet
Fix from $1,950 2019-02-27
Debian Linux MEDIUM 5.0
CVE-2019-8354

An issue was discovered in SoX 14.4.2. lsx_make_lpf in effect_i_dsp.c has an integer overflow on the result of multiplication fed into malloc. When t…

Mitigation only
Fix from $1,600 2019-02-15
Debian Linux CRITICAL 9.8
CVE-2018-8794EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to an Out-Of-Bounds Write in function process_bitmap_updates() an…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux CRITICAL 9.8
CVE-2018-8795EPSS 7%

rdesktop versions up to and including v1.8.3 contain an Integer Overflow that leads to a Heap-Based Buffer Overflow in function process_bitmap_update…

Fix: after 1.8.3
Fix from $2,300 2019-02-05
Debian Linux HIGH 8.8
CVE-2019-6250EPSS 9%

A pointer overflow, with code execution, was discovered in ZeroMQ libzmq (aka 0MQ) 4.2.x and 4.3.x before 4.3.1. A v2_decoder.cpp zmq::v2_decoder_t::…

Fix: 4.3.1+
Fix from $1,950 2019-01-13
Debian Linux CRITICAL 9.8
CVE-2018-19199

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function becaus…

Fix: 0.9.0+
Fix from $2,300 2018-11-12
Debian Linux MEDIUM 6.5
CVE-2018-19107

In Exiv2 0.26, Exiv2::IptcParser::decode in iptc.cpp (called from psdimage.cpp in the PSD image reader) may suffer from a denial of service (heap-bas…

Patch available
Fix from $1,600 2018-11-08
Debian Linux MEDIUM 6.5
CVE-2016-2120

An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server b…

Fix: after 4.0.1
Fix from $1,600 2018-11-01
Debian Linux CRITICAL 9.8
CVE-2018-17963

qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possib…

Fix: after 3.0.0
Fix from $2,300 2018-10-09