Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux CRITICAL 9.8
CVE-2017-8105

FreeType 2 before 2017-03-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_decoder_parse_charstrings function i…

Fix: 2.7.1+
Fix from $2,300 2017-04-24
Debian Linux HIGH 7.5
CVE-2017-8073

WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes f…

Fix: 1.7.1+
Fix from $1,950 2017-04-23
Debian Linux HIGH 7.8
CVE-2016-2347

Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute arbitrary co…

Fix: after 0.3.0
Fix from $1,950 2017-04-21
Debian Linux MEDIUM 5.5
CVE-2017-7718

hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds read and …

Fix: after 2.8.1.1
Fix from $1,600 2017-04-20
Debian Linux MEDIUM 6.5
CVE-2017-7941

The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

Patch available
Fix from $1,600 2017-04-18
Debian Linux MEDIUM 6.5
CVE-2017-7943

The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.

Patch available
Fix from $1,600 2017-04-18
Debian Linux HIGH 7.5
CVE-2016-7551EPSS 5%

chain_sip in Asterisk Open Source 11.x before 11.23.1 and 13.x 13.11.1 and Certified Asterisk 11.6 before 11.6-cert15 and 13.8 before 13.8-cert3 allo…

Patch available
Fix from $1,950 2017-04-17
Debian Linux CRITICAL 9.8
CVE-2017-7863

FFmpeg before 2017-02-04 has an out-of-bounds write caused by a heap-based buffer overflow related to the decode_frame_common function in libavcodec/…

Fix: after 2.8.10
Fix from $2,300 2017-04-14
Debian Linux CRITICAL 9.8
CVE-2017-7865

FFmpeg before 2017-01-24 has an out-of-bounds write caused by a heap-based buffer overflow related to the ipvideo_decode_block_opcode_0xA function in…

Fix: after 2.8.9
Fix from $2,300 2017-04-14
Debian Linux HIGH 7.5
CVE-2017-7867

International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to t…

Fix: after 58.2
Fix from $1,950 2017-04-14
Debian Linux HIGH 7.5
CVE-2017-7868

International Components for Unicode (ICU) for C/C++ before 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to t…

Fix: after 58.2
Fix from $1,950 2017-04-14
Debian Linux HIGH 7.5
CVE-2015-8619

The Human Monitor Interface support in QEMU allows remote attackers to cause a denial of service (out-of-bounds write and application crash).

Fix: after 2.5.1.1
Fix from $1,950 2017-04-13
Debian Linux MEDIUM 6.5
CVE-2015-8345

The eepro100 emulator in QEMU qemu-kvm blank allows local guest users to cause a denial of service (application crash and infinite loop) via vectors …

Fix: after 2.4.1
Fix from $1,600 2017-04-13
Debian Linux CRITICAL 9.8
CVE-2015-6674

Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This iss…

Fix: after 2.0.19
Fix from $2,300 2017-04-13
Debian Linux HIGH 7.5
CVE-2012-6697

InspIRCd before 2.0.7 allows remote attackers to cause a denial of service (infinite loop).

Fix: after 2.0.6
Fix from $1,950 2017-04-13
Debian Linux MEDIUM 5.5
CVE-2017-7697

In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted audio file.

Fix: after 0.1.8
Fix from $1,600 2017-04-11
Debian Linux HIGH 7.9
CVE-2015-8666

Heap-based buffer overflow in QEMU, when built with the Q35-chipset-based PC system emulator.

Fix: after 2.4.1
Fix from $1,950 2017-04-11
Debian Linux MEDIUM 6.5
CVE-2015-8504

Qemu, when built with VNC display driver support, allows remote attackers to cause a denial of service (arithmetic exception and application crash) v…

Fix: after 2.4.1
Fix from $1,600 2017-04-11
Debian Linux MEDIUM 6.5
CVE-2015-8568

Memory leak in QEMU, when built with a VMWARE VMXNET3 paravirtual NIC emulator support, allows local guest users to cause a denial of service (host m…

Fix: after 2.5.1
Fix from $1,600 2017-04-11
Debian Linux MEDIUM 6.5
CVE-2015-8613

Stack-based buffer overflow in the megasas_ctrl_get_info function in QEMU, when built with SCSI MegaRAID SAS HBA emulation support, allows local gues…

Fix: after 2.5.1
Fix from $1,600 2017-04-11
Debian Linux CRITICAL 9.8
CVE-2016-1908EPSS 14%

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr…

Patch available
Fix from $2,300 2017-04-11
Debian Linux MEDIUM 5.5
CVE-2016-5322

The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a c…

Fix: after 4.0.6
Fix from $1,600 2017-04-11
Debian Linux HIGH 7.5
CVE-2016-4483EPSS 6%

The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds rea…

Fix: 2.9.4+
Fix from $1,950 2017-04-11
Debian Linux MEDIUM 6.0
CVE-2017-7377

The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a deni…

Fix: after 2.8.1
Fix from $1,600 2017-04-10
Debian Linux HIGH 8.8
CVE-2016-1516

OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.

Patch available
Fix from $1,950 2017-04-10
Debian Linux MEDIUM 5.5
CVE-2017-7608

The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buf…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7610

The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and applica…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7611

The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and …

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7612

The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and app…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7613

elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2017-04-09