Vulnerability index

Browse CVEs

3,919 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Debian Linux HIGH 7.8
CVE-2017-6308

An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been identified in the functions tha…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6309

An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. These might lead to invalid rea…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Debian Linux HIGH 7.8
CVE-2017-6310

An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() function. These might lead to i…

Fix: after 1.4.12
Fix from $1,950 2017-02-24
Debian Linux MEDIUM 5.5
CVE-2017-6299

An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "2 of 9. Infinite Loop / DoS in the TNEFFillMapi function in l…

Fix: after 1.9
Fix from $1,600 2017-02-24
Debian Linux CRITICAL 9.8
CVE-2016-1245

It was discovered that the zebra daemon in Quagga before 1.0.20161017 suffered from a stack-based buffer overflow when processing IPv6 Neighbor Disco…

Fix: after 1.0.20160315
Fix from $2,300 2017-02-22
Debian Linux MEDIUM 5.5
CVE-2017-6188

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting…

Fix: 2.0.30.1 / 2.999.9+
Fix from $1,600 2017-02-22
Debian Linux HIGH 7.5
CVE-2016-9956

The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.

Fix: after 2016.4.3
Fix from $1,950 2017-02-22
Debian Linux MEDIUM 6.3
CVE-2016-9955

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses o…

Fix: 1.14.11+
Fix from $1,600 2017-02-17
Debian Linux MEDIUM 5.5
CVE-2017-6009

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. T…

No fix yet
Fix from $1,600 2017-02-16
Debian Linux MEDIUM 5.5
CVE-2017-6010

An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue…

No fix yet
Fix from $1,600 2017-02-16
Debian Linux MEDIUM 5.5
CVE-2017-6011

An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extr…

No fix yet
Fix from $1,600 2017-02-16
Debian Linux HIGH 8.8
CVE-2016-8677

The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a craf…

Fix: 6.9.5-10 / 7.0.3-1+
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.8
CVE-2016-9560

Stack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have unspecified im…

Fix: 1.900.30+
Fix from $1,950 2017-02-15
Debian Linux HIGH 8.8
CVE-2016-8862

The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick before 7.0.3.3 allows remote attackers to have unspecified impact via a crafte…

Fix: 6.9.4-0 / 7.0.3-3+
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.8
CVE-2016-8683

The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which trig…

Patch available
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.8
CVE-2016-8684

The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which t…

Patch available
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.5
CVE-2016-8682

The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a cr…

Patch available
Fix from $1,950 2017-02-15
Debian Linux MEDIUM 5.5
CVE-2016-8691

The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-…

Fix: after 1.900.3
Fix from $1,600 2017-02-15
Debian Linux HIGH 7.5
CVE-2015-8979

Stack-based buffer overflow in the parsePresentationContext function in storescp in DICOM dcmtk-3.6.0 and earlier allows remote attackers to cause a …

Fix: after 3.6.0
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.5
CVE-2017-5991EPSS 15%

An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a N…

Fix: 1.11+
Fix from $1,950 2017-02-15
Debian Linux HIGH 7.5
CVE-2017-5847

The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a…

Fix: 1.11.2+
Fix from $1,950 2017-02-09
Debian Linux HIGH 7.5
CVE-2017-5848

The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of serv…

Fix: 1.11.2+
Fix from $1,950 2017-02-09
Debian Linux CRITICAL 9.8
CVE-2016-2148EPSS 27%

Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involv…

Fix: after 1.24.2
Fix from $2,300 2017-02-09
Debian Linux HIGH 7.5
CVE-2016-2147EPSS 8%

Integer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a malformed RF…

Fix: after 1.24.2
Fix from $1,950 2017-02-09
Debian Linux CRITICAL 9.8
CVE-2016-7446

Buffer overflow in the MVG and SVG rendering code in GraphicsMagick 1.3.24 allows remote attackers to have unspecified impact via unknown vectors. No…

Mitigation only
Fix from $2,300 2017-02-06
Debian Linux CRITICAL 9.8
CVE-2016-7447

Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via u…

Fix: after 1.3.24
Fix from $2,300 2017-02-06
Debian Linux HIGH 7.5
CVE-2016-7448

The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations…

Fix: after 1.3.24
Fix from $1,950 2017-02-06
Debian Linux HIGH 7.5
CVE-2016-7449

The TIFFGetField function in coders/tiff.c in GraphicsMagick 1.3.24 allows remote attackers to cause a denial of service (out-of-bounds heap read) vi…

Mitigation only
Fix from $1,950 2017-02-06
Debian Linux HIGH 7.5
CVE-2016-7800

Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of servic…

Fix: after 1.3.25
Fix from $1,950 2017-02-06
Debian Linux MEDIUM 5.5
CVE-2016-9532

Integer overflow in the writeBufferToSeparateStrips function in tiffcrop.c in LibTIFF before 4.0.7 allows remote attackers to cause a denial of servi…

Fix: after 4.0.6
Fix from $1,600 2017-02-06