Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux MEDIUM 6.5
CVE-2018-20184

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to c…

Patch available
Fix from $1,600 2018-12-17
Debian Linux HIGH 8.8
CVE-2018-20004

An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a do…

No fix yet
Fix from $1,950 2018-12-10
Debian Linux HIGH 8.8
CVE-2018-5808

An error within the "find_green()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.9 can be exploited to cause a stack-based bu…

Fix: 0.18.9+
Fix from $1,950 2018-12-07
Debian Linux HIGH 8.8
CVE-2018-19540

An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.1…

No fix yet
Fix from $1,950 2018-11-26
Debian Linux HIGH 7.8
CVE-2018-19490

An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amoun…

Patch available
Fix from $1,950 2018-11-23
Debian Linux CRITICAL 9.8
CVE-2018-19198

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function bec…

Fix: 0.9.0+
Fix from $2,300 2018-11-12
Debian Linux CRITICAL 9.8
CVE-2018-19115

keepalived before 2.0.7 has a heap-based buffer overflow when parsing HTTP status codes resulting in DoS or possibly unspecified other impact, becaus…

Fix: 2.0.7+
Fix from $2,300 2018-11-08
Debian Linux HIGH 7.8
CVE-2018-9516

In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local …

Patch available
Fix from $1,950 2018-11-06
Debian Linux MEDIUM 6.5
CVE-2018-18584

In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum bloc…

Fix: 1.8+
Fix from $1,600 2018-10-23
Debian Linux HIGH 8.8
CVE-2018-18557EPSS 15%

LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.…

No fix yet
Fix from $1,950 2018-10-22
Debian Linux CRITICAL 9.8
CVE-2018-4013EPSS 10%

An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specia…

No fix yet
Fix from $2,300 2018-10-19
Debian Linux CRITICAL 9.8
CVE-2018-17141EPSS 6%

HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit en…

No fix yet
Fix from $2,300 2018-09-21
Debian Linux HIGH 8.8
CVE-2018-17101

An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a deni…

Patch available
Fix from $1,950 2018-09-16
Debian Linux HIGH 7.5
CVE-2018-12086EPSS 12%

Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.

Fix: after 1.03.352.12
Fix from $1,950 2018-09-14
Debian Linux HIGH 8.8
CVE-2018-16981

stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

No fix yet
Fix from $1,950 2018-09-12
Debian Linux HIGH 8.8
CVE-2018-16335

newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-bas…

Patch available
Fix from $1,950 2018-09-02
Debian Linux HIGH 8.8
CVE-2018-15209

ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and …

No fix yet
Fix from $1,950 2018-08-08
Debian Linux MEDIUM 5.5
CVE-2018-10883

A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write in jbd2_journal_dirty_metadata(), a denial of s…

Fix: 4.9.110+
Fix from $1,600 2018-07-30
Debian Linux CRITICAL 9.8
CVE-2017-2640EPSS 6%

An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this fla…

Fix: 2.12.0+
Fix from $2,300 2018-07-27
Debian Linux MEDIUM 5.5
CVE-2018-10880

Linux kernel is vulnerable to a stack-out-of-bounds write in the ext4 filesystem code when mounting and writing to a crafted ext4 image in ext4_updat…

Fix: 4.17.6+
Fix from $1,600 2018-07-25
Debian Linux CRITICAL 9.8
CVE-2018-14350EPSS 5%

An issue was discovered in Mutt before 1.10.1 and NeoMutt before 2018-07-16. imap/message.c has a stack-based buffer overflow for a FETCH response wi…

Fix: 1.10.1 / 20180716+
Fix from $2,300 2018-07-17
Debian Linux CRITICAL 9.8
CVE-2018-14360

An issue was discovered in NeoMutt before 2018-07-16. nntp_add_group in newsrc.c has a stack-based buffer overflow because of incorrect sscanf usage.

Fix: 20180716+
Fix from $2,300 2018-07-17
Debian Linux HIGH 8.8
CVE-2018-14346

GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).

Fix: 1.7+
Fix from $1,950 2018-07-17
Debian Linux HIGH 8.8
CVE-2018-13139

A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash)…

Mitigation only
Fix from $1,950 2018-07-04
Debian Linux CRITICAL 9.8
CVE-2018-12601

There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other im…

Patch available
Fix from $2,300 2018-06-20
Debian Linux CRITICAL 9.8
CVE-2018-5159EPSS 21%

An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of…

Fix: 52.8.0 / 60.0+
Fix from $2,300 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2018-5147

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vu…

Fix: 52.7.2 / 59.0.1+
Fix from $2,300 2018-06-11
Debian Linux HIGH 8.6
CVE-2018-5129

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow …

Fix: 52.7.0 / 59.0+
Fix from $1,950 2018-06-11
Debian Linux CRITICAL 9.8
CVE-2017-5443

An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox …

Fix: 45.9.0 / 53.0+
Fix from $2,300 2018-06-11
Debian Linux HIGH 8.6
CVE-2017-5448

An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Ge…

Fix: 45.9.0 / 52.1.0+
Fix from $1,950 2018-06-11