Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux CRITICAL 9.8
CVE-2007-0899

There is a possible heap overflow in libclamav/fsg.c before 0.100.0.

Fix: 0.100.0+
Fix from $2,300 2019-11-06
Debian Linux CRITICAL 9.8
CVE-2013-2739

MiniDLNA has heap-based buffer overflow

Fix: 1.1.0+
Fix from $2,300 2019-11-01
Debian Linux HIGH 7.8
CVE-2019-18218

cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (…

Fix: after 5.37
Fix from $1,950 2019-10-21
Debian Linux HIGH 8.8
CVE-2019-17540

ImageMagick before 7.0.8-54 has a heap-based buffer overflow in ReadPSInfo in coders/ps.c.

Fix: 6.9.10-55 / 7.0.8-54+
Fix from $1,950 2019-10-14
Debian Linux CRITICAL 9.8
CVE-2019-17041

An issue was discovered in Rsyslog v8.1908.0. contrib/pmaixforwardedfrom/pmaixforwardedfrom.c has a heap overflow in the parser for AIX log messages.…

Patch available
Fix from $2,300 2019-10-07
Debian Linux HIGH 7.5
CVE-2019-5094

An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause …

Fix: after 1.45.3
Fix from $1,950 2019-09-24
Debian Linux HIGH 8.8
CVE-2018-21010

OpenJPEG before 2.3.1 has a heap buffer overflow in color_apply_icc_profile in bin/common/color.c.

Fix: 2.3.1+
Fix from $1,950 2019-09-05
Debian Linux HIGH 7.8
CVE-2019-14970

A vulnerability in mkv::event_thread_t in VideoLAN VLC media player 3.0.7.1 allows remote attackers to trigger a heap-based buffer overflow via a cra…

Patch available
Fix from $1,950 2019-08-29
Debian Linux CRITICAL 9.8
CVE-2019-11500EPSS 63%

In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs bec…

Fix: 0.5.7.2 / 2.2.36.4+
Fix from $2,300 2019-08-29
Debian Linux CRITICAL 9.8
CVE-2019-13273

In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET req…

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13455

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of   expansion in ackno…

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13485

In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the history viewer component via a long hostname or service parameter …

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux CRITICAL 9.8
CVE-2019-13486

In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of   expansion in svcstatus.c.

Fix: after 4.3.28
Fix from $2,300 2019-08-27
Debian Linux HIGH 7.8
CVE-2019-13221

A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux HIGH 7.8
CVE-2019-13217

A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbi…

Fix: after 2019-03-04
Fix from $1,950 2019-08-15
Debian Linux MEDIUM 5.5
CVE-2019-14275

Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.

No fix yet
Fix from $1,600 2019-07-26
Debian Linux HIGH 7.8
CVE-2019-13602

An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause…

Fix: after 3.0.7.1
Fix from $1,950 2019-07-14
Debian Linux HIGH 7.8
CVE-2019-0053

Insufficient validation of environment variables in the telnet client supplied in Junos OS can lead to stack-based buffer overflows, which can be exp…

No fix yet
Fix from $1,950 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-12525EPSS 24%

An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the heade…

Fix: after 4.7
Fix from $2,300 2019-07-11
Debian Linux CRITICAL 9.8
CVE-2019-13132EPSS 42%

In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, runni…

Fix: 4.0.9 / 4.1.7+
Fix from $2,300 2019-07-10
Debian Linux HIGH 8.8
CVE-2019-13300

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling columns.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13304

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13305

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced strncpy and an off-by-one error.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13306

ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 7.8
CVE-2019-13307

ImageMagick 7.0.8-50 Q16 has a heap-based buffer overflow at MagickCore/statistic.c in EvaluateImages because of mishandling rows.

Patch available
Fix from $1,950 2019-07-05
Debian Linux HIGH 8.8
CVE-2019-5051

An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead…

No fix yet
Fix from $1,950 2019-07-03
Debian Linux CRITICAL 9.8
CVE-2019-12900EPSS 8%

BZ2_decompress in decompress.c in bzip2 through 1.0.6 has an out-of-bounds write when there are many selectors.

Fix: 3.7.13 / 3.8.13+
Fix from $2,300 2019-06-19
Debian Linux HIGH 7.8
CVE-2019-12483

An issue was discovered in GPAC 0.7.1. There is a heap-based buffer overflow in the function ReadGF_IPMPX_RemoveToolNotificationListener in odf/ipmpx…

Fix: after 0.7.1
Fix from $1,950 2019-05-30
Debian Linux HIGH 8.8
CVE-2019-11506

In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/m…

Patch available
Fix from $1,950 2019-04-24
Debian Linux HIGH 8.8
CVE-2019-11505

In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c…

Fix: after 1.3.31
Fix from $1,950 2019-04-24