Vulnerability index

Browse CVEs

460 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Out-of-bounds WriteCWE-787 × clear
Debian Linux MEDIUM 5.5
CVE-2018-1071

zsh through version 5.4.2 is vulnerable to a stack-based buffer overflow in the exec.c:hashcmd() function. A local attacker could exploit this to cau…

Fix: after 5.4.2
Fix from $1,600 2018-03-09
Debian Linux MEDIUM 6.5
CVE-2018-7877

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for DOUBLE data. A Crafted input will lead to a …

No fix yet
Fix from $1,600 2018-03-08
Debian Linux MEDIUM 6.5
CVE-2018-7873

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 for INTEGER data. A Crafted input will lead to a…

No fix yet
Fix from $1,600 2018-03-08
Debian Linux MEDIUM 6.5
CVE-2018-7867

There is a heap-based buffer overflow in the getString function of util/decompile.c in libming 0.4.8 during a RegisterNumber sprintf. A Crafted input…

No fix yet
Fix from $1,600 2018-03-08
Debian Linux CRITICAL 9.8
CVE-2018-1000116EPSS 6%

NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.

No fix yet
Fix from $2,300 2018-03-07
Debian Linux HIGH 8.8
CVE-2018-7550

The load_multiboot function in hw/i386/multiboot.c in Quick Emulator (aka QEMU) allows local guest OS users to execute arbitrary code on the QEMU hos…

Patch available
Fix from $1,950 2018-03-01
Debian Linux CRITICAL 9.8
CVE-2018-7553

There is a heap-based buffer overflow in the pcxLoadRaster function of in_pcx.cpp in sam2p 0.49.4. A crafted input will lead to a denial of service o…

No fix yet
Fix from $2,300 2018-02-28
Debian Linux HIGH 7.8
CVE-2018-7487

There is a heap-based buffer overflow in the LoadPCX function of in_pcx.cpp in sam2p 0.49.4. A Crafted input will lead to a denial of service or poss…

No fix yet
Fix from $1,950 2018-02-26
Debian Linux CRITICAL 9.8
CVE-2018-7186

Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a…

Fix: 1.75.3+
Fix from $2,300 2018-02-16
Debian Linux CRITICAL 9.8
CVE-2018-0488

ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute a…

Fix: 1.3.22 / 2.1.10+
Fix from $2,300 2018-02-13
Debian Linux HIGH 7.8
CVE-2017-17969

Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a de…

Fix: 18.00 / 18.0+
Fix from $1,950 2018-01-30
Debian Linux HIGH 8.8
CVE-2018-6358

The printDefineFont2 function (util/listfdb.c) in libming through 0.4.8 is vulnerable to a heap-based buffer overflow, which may allow attackers to c…

Fix: after 0.4.8
Fix from $1,950 2018-01-27
Debian Linux MEDIUM 5.5
CVE-2018-6187

In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote…

No fix yet
Fix from $1,600 2018-01-24
Debian Linux MEDIUM 5.5
CVE-2018-5268

In OpenCV 3.3.1, a heap-based buffer overflow happens in cv::Jpeg2KDecoder::readComponent8u in modules/imgcodecs/src/grfmt_jpeg2000.cpp when parsing …

No fix yet
Fix from $1,600 2018-01-08
Debian Linux HIGH 7.8
CVE-2017-17789

In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c.

Patch available
Fix from $1,950 2017-12-20
Debian Linux HIGH 7.8
CVE-2017-17785

In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.

Mitigation only
Fix from $1,950 2017-12-20
Debian Linux CRITICAL 9.8
CVE-2017-17480EPSS 5%

In OpenJPEG 2.3.0, a stack-based buffer overflow was discovered in the pgxtovolume function in jp3d/convert.c. The vulnerability causes an out-of-bou…

Mitigation only
Fix from $2,300 2017-12-08
Debian Linux HIGH 7.8
CVE-2017-2896

An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially crafted XLS file can cause a mem…

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 7.8
CVE-2017-2919

An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A specially crafted XLS file can cause …

Mitigation only
Fix from $1,950 2017-11-20
Debian Linux HIGH 8.8
CVE-2015-7504

Heap-based buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU allows guest OS administrators to cause a denial of service (insta…

Fix: after 2.4.1
Fix from $1,950 2017-10-16
Debian Linux HIGH 8.8
CVE-2017-2887

An exploitable buffer overflow vulnerability exists in the XCF property handling functionality of SDL_image 2.0.1. A specially crafted xcf file can c…

Mitigation only
Fix from $1,950 2017-10-11
Debian Linux HIGH 7.8
CVE-2017-2862

An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafte…

No fix yet
Fix from $1,950 2017-09-05
Debian Linux HIGH 8.8
CVE-2017-14152EPSS 5%

A mishandled zero case was discovered in opj_j2k_set_cinema_parameters in lib/openjp2/j2k.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bou…

Patch available
Fix from $1,950 2017-09-05
Debian Linux MEDIUM 6.5
CVE-2017-14136

OpenCV (Open Source Computer Vision Library) 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an image fi…

Patch available
Fix from $1,600 2017-09-04
Debian Linux HIGH 8.8
CVE-2017-14039

A heap-based buffer overflow was discovered in the opj_t2_encode_packet function in lib/openjp2/t2.c in OpenJPEG 2.2.0. The vulnerability causes an o…

Fix: 2.3.0+
Fix from $1,950 2017-08-30
Debian Linux HIGH 8.8
CVE-2017-14040

An invalid write access was discovered in bin/jp2/convert.c in OpenJPEG 2.2.0, triggering a crash in the tgatoimage function. The vulnerability may l…

Patch available
Fix from $1,950 2017-08-30
Debian Linux HIGH 8.8
CVE-2017-14041EPSS 6%

A stack-based buffer overflow was discovered in the pgxtoimage function in bin/jp2/convert.c in OpenJPEG 2.2.0. The vulnerability causes an out-of-bo…

Patch available
Fix from $1,950 2017-08-30
Debian Linux HIGH 8.8
CVE-2017-12862

In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause copy buffer overflow later. If …

Fix: after 3.3.0
Fix from $1,950 2017-08-15
Debian Linux HIGH 8.8
CVE-2017-12597

OpenCV (Open Source Computer Vision Library) through 3.3 has an out-of-bounds write error in the function FillColorRow1 in utils.cpp when reading an …

Fix: after 3.3.0
Fix from $1,950 2017-08-07
Debian Linux HIGH 8.8
CVE-2017-12603

OpenCV (Open Source Computer Vision Library) through 3.3 has an invalid write in the cv::RLByteStream::getBytes function in modules/imgcodecs/src/bit…

Fix: after 3.3.0
Fix from $1,950 2017-08-07