Vulnerability index

Browse CVEs

680 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Debian Linux MEDIUM 5.5
CVE-2017-14926

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 5.5
CVE-2017-14928

In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a crafted PDF document.

Mitigation only
Fix from $1,600 2017-09-30
Debian Linux MEDIUM 6.5
CVE-2017-14733

ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2017-09-25
Debian Linux HIGH 8.8
CVE-2017-14160

The bark_noise_hybridmp function in psy.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial of service (out-of-bounds access and …

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14245

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux HIGH 8.1
CVE-2017-14246

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, relate…

Mitigation only
Fix from $1,950 2017-09-21
Debian Linux CRITICAL 9.8
CVE-2017-14632EPSS 6%

Xiph.Org libvorbis 1.3.5 allows Remote Code Execution upon freeing uninitialized memory in the function vorbis_analysis_headerout() in info.c when vi…

Mitigation only
Fix from $2,300 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14633

In Xiph.Org libvorbis 1.3.5, an out-of-bounds array read vulnerability exists in the function mapping0_forward() in mapping0.c, which may lead to DoS…

Mitigation only
Fix from $1,600 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14634

In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio…

Mitigation only
Fix from $1,600 2017-09-21
Debian Linux MEDIUM 6.5
CVE-2017-14528

The TIFFSetProfiles function in coders/tiff.c in ImageMagick 7.0.6 has incorrect expectations about whether LibTIFF TIFFGetField return values imply …

No fix yet
Fix from $1,600 2017-09-18
Debian Linux HIGH 8.8
CVE-2017-2816

An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially crafted OFX file can cause a write…

No fix yet
Fix from $1,950 2017-09-13
Debian Linux HIGH 7.8
CVE-2017-2862

An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafte…

No fix yet
Fix from $1,950 2017-09-05
Debian Linux HIGH 7.8
CVE-2017-2870

An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially…

No fix yet
Fix from $1,950 2017-09-05
Debian Linux CRITICAL 9.1
CVE-2017-14122

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.

Mitigation only
Fix from $2,300 2017-09-03
Debian Linux HIGH 7.5
CVE-2017-14120

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] a…

Mitigation only
Fix from $1,950 2017-09-03
Debian Linux MEDIUM 5.5
CVE-2017-14121

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a craf…

Mitigation only
Fix from $1,600 2017-09-03
Debian Linux MEDIUM 5.5
CVE-2017-13760

In The Sleuth Kit (TSK) 4.4.2, fls hangs on a corrupt exfat image in tsk_img_read() in tsk/img/img_io.c in libtskimg.a.

No fix yet
Fix from $1,600 2017-08-29
Debian Linux MEDIUM 5.5
CVE-2017-13756

In The Sleuth Kit (TSK) 4.4.2, opening a crafted disk image triggers infinite recursion in dos_load_ext_table() in tsk/vs/dos.c in libtskvs.a, as dem…

Mitigation only
Fix from $1,600 2017-08-29
Xbindkeys Config CRITICAL 9.8
CVE-2014-9513

Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2017-08-28
Debian Linux MEDIUM 6.5
CVE-2017-13063

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux MEDIUM 6.5
CVE-2017-13064

GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux MEDIUM 6.5
CVE-2017-13065

GraphicsMagick 1.3.26 has a NULL pointer dereference vulnerability in the function SVGStartElement in coders/svg.c.

Mitigation only
Fix from $1,600 2017-08-22
Debian Linux HIGH 7.5
CVE-2015-7704EPSS 11%

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" …

Mitigation only
Fix from $1,950 2017-08-07
Debian Linux MEDIUM 5.5
CVE-2017-11358EPSS 7%

The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and appl…

No fix yet
Fix from $1,600 2017-07-31
Debian Linux MEDIUM 5.5
CVE-2017-11359EPSS 7%

The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and appli…

No fix yet
Fix from $1,600 2017-07-31
Debian Linux MEDIUM 5.5
CVE-2017-11332EPSS 7%

The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and applica…

No fix yet
Fix from $1,600 2017-07-31
Debian Linux MEDIUM 5.5
CVE-2017-11732

A heap-based buffer overflow vulnerability was found in the function dcputs (called from decompileIMPLEMENTS) in util/decompile.c in Ming 0.4.8, whic…

Mitigation only
Fix from $1,600 2017-07-29
Debian Linux MEDIUM 5.5
CVE-2017-11733

A null pointer dereference vulnerability was found in the function stackswap (called from decompileSTACKSWAP) in util/decompile.c in Ming 0.4.8, whic…

Mitigation only
Fix from $1,600 2017-07-29
Debian Linux HIGH 7.8
CVE-2017-9611

The Ins_MIRP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (heap-based buffer…

No fix yet
Fix from $1,950 2017-07-26
Debian Linux HIGH 7.8
CVE-2017-9612

The Ins_IP function in base/ttinterp.c in Artifex Ghostscript GhostXPS 9.21 allows remote attackers to cause a denial of service (use-after-free and …

No fix yet
Fix from $1,950 2017-07-26