Vulnerability index

Browse CVEs

37 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
HIGH 7.8 CVE-2017-3629EPSS 5% Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 1… Solaris Patch available Fix from $1,9502017-06-22 MEDIUM 5.3 CVE-2017-3631EPSS 6% Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11. Eas… Solaris Patch available Fix from $1,6002017-06-22 HIGH 8.1 CVE-2016-5688 The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact v… Solaris after 6.9.4-3 Fix from $1,9502016-12-13 HIGH 7.8 CVE-2016-3991 Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s… Vm Server after 4.0.6 Fix from $1,9502016-09-21 CRITICAL 9.8 CVE-2016-5408 Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linu… Linux Patch available Fix from $2,3002016-08-10 HIGH 8.8 CVE-2016-5252 Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote … Linux after 47.0.1 Fix from $1,9502016-08-05 HIGH 8.8 CVE-2016-2801 The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox E… Linux after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2799 Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ES… Linux after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2797 The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before … Linux after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2796 Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and … Linux after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-2793 CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause … Linux after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1977 The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before… Linux after 44.0.2 Fix from $1,9502016-03-13 HIGH 8.8 CVE-2016-1952 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to … Linux after 44.0.2 Fix from $1,9502016-03-13 MEDIUM 6.2 CVE-2013-4312 The Linux kernel before 4.4.1 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by sending each … Linux after 4.4 Fix from $1,6002016-02-08 HIGH 8.8 CVE-2016-1935EPSS 5% Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbi… Linux after 43.0.4 Fix from $1,9502016-01-31 HIGH 8.1 CVE-2016-0778EPSS 21% The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy … Linux after 15.07 Fix from $1,9502016-01-14 CRITICAL 9.8 CVE-2015-8391EPSS 6% The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of ser… Linux Mitigation only Fix from $2,3002015-12-02 HIGH 7.5 CVE-2015-8388EPSS 7% PCRE before 8.38 mishandles the /(?=di(?<=(?1))|(?=(.))))/ pattern and related patterns with an unmatched closing parenthesis, which allows remote at… Linux after 8.37 Fix from $1,9502015-12-02 HIGH 7.5 CVE-2015-8385EPSS 6% PCRE before 8.38 mishandles the /(?|(\k'Pm')|(?'Pm'))/ pattern and related patterns with certain forward references, which allows remote attackers to… Linux after 8.37 Fix from $1,9502015-12-02 HIGH 8.8 CVE-2015-0973 Buffer overflow in the png_read_IDAT_data function in pngrutil.c in libpng before 1.5.21 and 1.6.x before 1.6.16 allows context-dependent attackers t… Solaris after 10.11.3 Fix from $1,9502015-01-18 HIGH 10.0 CVE-2014-0397 Multiple unspecified vulnerabilities in libXtsol in Oracle Solaris 10 and 11.1 have unspecified impact and attack vectors related to "Buffer errors." Solaris Mitigation only Fix from $1,9502014-10-06 HIGH 10.0 CVE-2013-0402EPSS 10% Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier all… Javafx after 2.2.7 Fix from $1,9502013-03-08 HIGH 7.5 CVE-2012-0882EPSS 5% Buffer overflow in yaSSL, as used in MySQL 5.5.20 and possibly other versions including 5.5.x before 5.5.22 and 5.1.x before 5.1.62, allows remote at… MySQL Mitigation only Fix from $1,9502012-12-21 MEDIUM 6.8 CVE-2012-3133 Buffer overflow in the DataDirect ODBC driver, as used in Oracle Hyperion Interactive Reporting 11.1.2.1 and 11.1.2.2, Essbase Server 11.1.2.1 and 11… Hyperion Interactive Reporting Mitigation only Fix from $1,6002012-12-21 HIGH 9.3 CVE-2011-5167EPSS 10% Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strate… Hyperion Strategic Finance after 12.0 Fix from $1,9502012-09-15 HIGH 8.5 CVE-2007-5897 Buffer overflow in MDSYS.SDO_CS in Oracle Database Server 8iR3, 9iR1, 9iR2 up to 9.2.0.6, and 10gR1 up to 10.1.0.4 allows remote authenticated users … Database Server Mitigation only Fix from $1,9502007-11-08 MEDIUM 6.0 CVE-2007-4517EPSS 5% Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated users to execute arbitrary code … Database Server Mitigation only Fix from $1,6002007-11-08 MEDIUM 6.4 CVE-2007-5507 The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows … Database Server Mitigation only Fix from $1,6002007-10-17 HIGH 8.5 CVE-2007-0272EPSS 7% Multiple buffer overflows in MDSYS.MD in Oracle Database 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 allows remote authenticated users to cause a denial … Database Server Patch available Fix from $1,9502007-01-17 MEDIUM 6.5 CVE-2007-0270EPSS 5% Buffer overflow in SYS.DBMS_DRS in Oracle Database 9.2.0.7 and 10.1.0.4 allows remote authenticated users to cause a denial of service (crash) or exe… Database Server Patch available Fix from $1,6002007-01-17