Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux HIGH 8.8
CVE-2017-5436

An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash.…

Fix: 45.9.0 / 53.0+
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 6.5
CVE-2018-5388

In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion an…

Fix: 5.6.3+
Fix from $1,600 2018-05-31
Debian Linux CRITICAL 9.8
CVE-2018-11531

Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.

No fix yet
Fix from $2,300 2018-05-29
Debian Linux HIGH 8.8
CVE-2018-11490

The DGifDecompressLine function in dgif_lib.c in GIFLIB (possibly version 3.0.x), as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer…

Fix: after 3.1.1
Fix from $1,950 2018-05-26
Debian Linux CRITICAL 9.8
CVE-2018-1000178

A heap corruption of type CWE-120 exists in quassel version 0.12.4 in quasselcore in void DataStreamPeer::processMessage(const QByteArray &msg) datas…

Patch available
Fix from $2,300 2018-05-08
Debian Linux CRITICAL 9.8
CVE-2018-10771

Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (appli…

Fix: after 8.13.20
Fix from $2,300 2018-05-07
Debian Linux CRITICAL 9.8
CVE-2018-10753

Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service…

Fix: after 8.13.20
Fix from $2,300 2018-05-05
Debian Linux HIGH 7.8
CVE-2018-10536

An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRi…

Fix: after 5.1.0
Fix from $1,950 2018-04-29
Debian Linux MEDIUM 5.5
CVE-2018-10538

An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not v…

Fix: after 5.1.0
Fix from $1,600 2018-04-29
Debian Linux MEDIUM 5.5
CVE-2018-10539

An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c doe…

Fix: after 5.1.0
Fix from $1,600 2018-04-29
Debian Linux MEDIUM 5.5
CVE-2018-10540

An issue was discovered in WavPack 5.1.0 and earlier for W64 input. Out-of-bounds writes can occur because ParseWave64HeaderConfig in wave64.c does n…

Fix: after 5.1.0
Fix from $1,600 2018-04-29
Debian Linux MEDIUM 6.5
CVE-2018-10471

An issue was discovered in Xen through 4.10.x allowing x86 PV guest OS users to cause a denial of service (out-of-bounds zero write and hypervisor cr…

Fix: after 4.10.1
Fix from $1,600 2018-04-27
Debian Linux HIGH 8.8
CVE-2018-10392

mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial …

No fix yet
Fix from $1,950 2018-04-26
Debian Linux HIGH 8.8
CVE-2017-2923

An exploitable heap based buffer overflow vulnerability exists in the 'read_biff_next_record function' of FreeXL 1.0.3. A specially crafted XLS file …

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 8.8
CVE-2017-2924

An exploitable heap-based buffer overflow vulnerability exists in the read_legacy_biff function of FreeXL 1.0.3. A specially crafted XLS file can cau…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux CRITICAL 9.8
CVE-2017-2885EPSS 24%

An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflo…

No fix yet
Fix from $2,300 2018-04-24
Debian Linux HIGH 8.1
CVE-2017-2835

An exploitable code execution vulnerability exists in the RDP receive functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server resp…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 7.0
CVE-2017-2834

An exploitable code execution vulnerability exists in the authentication functionality of FreeRDP 2.0.0-beta1+android11. A specially crafted server r…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 8.8
CVE-2017-12122

An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can …

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 8.8
CVE-2017-14440

An exploitable code execution vulnerability exists in the ILBM image rendering functionality of SDL2_image-2.0.2. A specially crafted ILBM image can …

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux HIGH 8.8
CVE-2017-14448

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.2. A specially crafted XCF image can ca…

Mitigation only
Fix from $1,950 2018-04-24
Debian Linux CRITICAL 9.8
CVE-2018-6797EPSS 7%

An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes w…

Fix: after 5.26
Fix from $2,300 2018-04-17
Debian Linux CRITICAL 9.8
CVE-2018-6913EPSS 11%

Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item c…

Fix: 5.26.2+
Fix from $2,300 2018-04-17
Debian Linux HIGH 7.8
CVE-2018-10120

The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a custo…

Fix: 5.4.6.1 / 6.0.2.1+
Fix from $1,950 2018-04-16
Debian Linux HIGH 8.8
CVE-2018-3839

An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially…

No fix yet
Fix from $1,950 2018-04-10
Debian Linux CRITICAL 9.8
CVE-2018-1000140EPSS 10%

rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result …

Patch available
Fix from $2,300 2018-03-23
Debian Linux HIGH 8.8
CVE-2018-8905

In LibTIFF 4.0.9, a heap-based buffer overflow occurs in the function LZWDecodeCompat in tif_lzw.c via a crafted TIFF file, as demonstrated by tiff2p…

Patch available
Fix from $1,950 2018-03-22
Debian Linux CRITICAL 9.8
CVE-2018-8828EPSS 31%

A Buffer Overflow issue was discovered in Kamailio before 4.4.7, 5.0.x before 5.0.6, and 5.1.x before 5.1.2. A specially crafted REGISTER message wit…

Fix: 4.4.7 / 5.0.6+
Fix from $2,300 2018-03-20
Debian Linux CRITICAL 9.8
CVE-2018-1000120EPSS 12%

A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or …

Fix: 7.2+
Fix from $2,300 2018-03-14
Debian Linux HIGH 8.8
CVE-2014-8129

LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted TIFF…

Patch available
Fix from $1,950 2018-03-12