Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Solaris HIGH 7.8
CVE-2017-3629EPSS 5%

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 1…

Patch available
Fix from $1,950 2017-06-22
Solaris MEDIUM 5.3
CVE-2017-3631EPSS 6%

Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Eas…

Patch available
Fix from $1,600 2017-06-22
Solaris HIGH 8.1
CVE-2016-5688

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact v…

Fix: after 6.9.4-3
Fix from $1,950 2016-12-13
Vm Server HIGH 7.8
CVE-2016-3991

Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s…

Fix: after 4.0.6
Fix from $1,950 2016-09-21
Linux CRITICAL 9.8
CVE-2016-5408

Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linu…

Patch available
Fix from $2,300 2016-08-10
Linux HIGH 8.8
CVE-2016-5252

Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote …

Fix: after 47.0.1
Fix from $1,950 2016-08-05
Linux HIGH 8.8
CVE-2016-2801

The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux HIGH 8.8
CVE-2016-2799

Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ES…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux HIGH 8.8
CVE-2016-2797

The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux HIGH 8.8
CVE-2016-2796

Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux HIGH 8.8
CVE-2016-2793

CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux HIGH 8.8
CVE-2016-1977

The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux HIGH 8.8
CVE-2016-1952

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to …

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Linux MEDIUM 6.2
CVE-2013-4312

The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each …

Fix: after 4.4
Fix from $1,600 2016-02-08
Linux HIGH 8.8
CVE-2016-1935EPSS 5%

Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbi…

Fix: after 43.0.4
Fix from $1,950 2016-01-31
Linux HIGH 8.1
CVE-2016-0778EPSS 21%

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy …

Fix: after 15.07
Fix from $1,950 2016-01-14
Linux CRITICAL 9.8
CVE-2015-8391EPSS 6%

The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $2,300 2015-12-02
Linux HIGH 7.5
CVE-2015-8388EPSS 7%

PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote at…

Fix: after 8.37
Fix from $1,950 2015-12-02
Linux HIGH 7.5
CVE-2015-8385EPSS 6%

PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to…

Fix: after 8.37
Fix from $1,950 2015-12-02
Solaris HIGH 8.8
CVE-2015-0973

Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers t…

Fix: after 10.11.3
Fix from $1,950 2015-01-18
Solaris HIGH 10.0
CVE-2014-0397

Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vectors related to "Buffer errors."

Mitigation only
Fix from $1,950 2014-10-06
Javafx HIGH 10.0
CVE-2013-0402EPSS 10%

Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier all…

Fix: after 2.2.7
Fix from $1,950 2013-03-08
MySQL HIGH 7.5
CVE-2012-0882EPSS 5%

Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote at…

Mitigation only
Fix from $1,950 2012-12-21
Hyperion Interactive Reporting MEDIUM 6.8
CVE-2012-3133

Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11…

Mitigation only
Fix from $1,600 2012-12-21
Hyperion Strategic Finance HIGH 9.3
CVE-2011-5167EPSS 10%

Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strate…

Fix: after 12.0
Fix from $1,950 2012-09-15
Database Server HIGH 8.5
CVE-2007-5897

Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 up to 10.1.0.4 allows remote authenticated users …

Mitigation only
Fix from $1,950 2007-11-08
Database Server MEDIUM 6.0
CVE-2007-4517EPSS 5%

Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code …

Mitigation only
Fix from $1,600 2007-11-08
Database Server MEDIUM 6.4
CVE-2007-5507

The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows …

Mitigation only
Fix from $1,600 2007-10-17
Database Server HIGH 8.5
CVE-2007-0272EPSS 7%

Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial …

Patch available
Fix from $1,950 2007-01-17
Database Server MEDIUM 6.5
CVE-2007-0270EPSS 5%

Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or exe…

Patch available
Fix from $1,600 2007-01-17