Vulnerability index

Browse CVEs

4,225 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Classic Buffer OverflowCWE-120 × clear
Debian Linux HIGH 7.2
CVE-2004-0455

Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.

Fix: 0.5.7+
Fix from $1,950 2004-12-06
Interix HIGH 7.8
CVE-2004-0210 KEVEPSS 7%

The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifyi…

Patch available
Fix from $1,950 2004-08-06
Mathopd HIGH 7.5
CVE-2003-1228EPSS 14%

Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to …

Fix: 1.5+
Fix from $1,950 2003-12-31
Opera Browser HIGH 7.5
CVE-2003-1387EPSS 15%

Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code via a URL with a long username.

Patch available
Fix from $1,950 2003-12-31
Opera Browser HIGH 9.3
CVE-2003-1388

Buffer overflow in Opera 7.02 Build 2668 allows remote attackers to crash Opera via a long HTTP request ending in a .ZIP extension.

Mitigation only
Fix from $1,950 2003-12-31
Wireless Tools HIGH 7.2
CVE-2003-0947

Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.

No fix yet
Fix from $1,950 2003-12-15
Wintango Application Server HIGH 7.5
CVE-2003-0595EPSS 8%

Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a long cookie to Witango_UserRefer…

Fix: 5.0.1.062+
Fix from $1,950 2003-08-27
Linux HIGH 10.0
CVE-2002-1337EPSS 72%

Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender …

Fix: 8.9.3 / 8.11.6+
Fix from $1,950 2003-03-07
MySQL HIGH 7.8
CVE-2002-0969

Buffer overflow in MySQL daemon (mysqld) before 3.23.50, and 4.0 beta before 4.02, on the Win32 platform, allows local users to execute arbitrary cod…

Fix: 3.23.50+
Fix from $1,950 2002-10-11
Exchange Server HIGH 7.5
CVE-2002-0698EPSS 20%

Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO requ…

Patch available
Fix from $1,950 2002-08-12
Debian Linux HIGH 7.2
CVE-2002-0062

Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "r…

Fix: 5.0+
Fix from $1,950 2002-03-08
FreeBSD HIGH 10.0
CVE-2001-0554EPSS 38%

Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of op…

Patch available
Fix from $1,950 2001-08-14
Kerberos 5 HIGH 7.5
CVE-2001-1323

Buffer overflow in MIT Kerberos 5 (krb5) 1.2.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code v…

Fix: 1.2.2+
Fix from $1,950 2001-05-16
Gnuserv HIGH 10.0
CVE-2001-0191EPSS 5%

gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remot…

Fix: 3.12+
Fix from $1,950 2001-05-03
Exchange Server MEDIUM 5.0
CVE-1999-0945EPSS 20%

Buffer overflow in Internet Mail Service (IMS) for Microsoft Exchange 5.5 and 5.0 allows remote attackers to conduct a denial of service via AUTH or …

Patch available
Fix from $1,600 2001-03-12
Aim HIGH 7.5
CVE-2000-1094

Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via a "buddyicon" command with a…

Fix: 4.3.2229+
Fix from $1,950 2001-01-09
Cygnus Network Security MEDIUM 5.0
CVE-2000-0546

Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.

Fix: 4.0+
Fix from $1,600 2000-06-09
Cygnus Network Security MEDIUM 5.0
CVE-2000-0547

Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.

Fix: 4.0+
Fix from $1,600 2000-06-09
Cygnus Network Security MEDIUM 5.0
CVE-2000-0548

Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.

Fix: 4.0+
Fix from $1,600 2000-06-09
Aix HIGH 7.2
CVE-2000-1216

Buffer overflow in portmir for AIX 4.3.0 allows local users to corrupt lock files and gain root privileges via the echo_error routine.

Mitigation only
Fix from $1,950 2000-01-27
HTTP Server HIGH 10.0
CVE-1999-1237EPSS 8%

Multiple buffer overflows in smbvalid/smbval SMB authentication library, as used in Apache::AuthenSmb and possibly other modules, allows remote attac…

Mitigation only
Fix from $1,950 1999-06-06
Exchange Server HIGH 10.0
CVE-1999-0385EPSS 18%

The LDAP bind function in Exchange 5.5 has a buffer overflow that allows a remote attacker to conduct a denial of service or execute commands.

Patch available
Fix from $1,950 1998-12-01
Lotus Domino Mail Server HIGH 7.5
CVE-1999-0284EPSS 12%

Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.

Mitigation only
Fix from $1,950 1998-01-01
Debian Linux HIGH 8.4
CVE-1999-0038

Buffer overflow in xlock program allows local users to execute commands as root.

Mitigation only
Fix from $1,950 1997-04-26
Debian Linux HIGH 10.0
CVE-1999-0046EPSS 52%

Buffer overflow of rlogin program using TERM environmental variable.

Mitigation only
Fix from $1,950 1997-02-06