Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Libxtst MEDIUM 6.8
CVE-2013-2063

Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors r…

Fix: after 1.2.1
Fix from $1,600 2013-06-15
Debian Linux MEDIUM 6.8
CVE-2013-2064

Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors rela…

Fix: after 1.9
Fix from $1,600 2013-06-15
Ubuntu Linux MEDIUM 6.8
CVE-2013-1981

Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer…

Fix: after 1.5.99.901
Fix from $1,600 2013-06-15
Libxext MEDIUM 6.8
CVE-2013-1982

Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via …

Fix: after 1.3.1
Fix from $1,600 2013-06-15
Libxfixes MEDIUM 6.8
CVE-2013-1983

Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors r…

Fix: after 5.0
Fix from $1,600 2013-06-15
Libxi MEDIUM 6.8
CVE-2013-1984

Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via ve…

Fix: after 1.7.1
Fix from $1,600 2013-06-15
Wireshark MEDIUM 5.0
CVE-2013-4074EPSS 61%

The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 i…

No fix yet
Fix from $1,600 2013-06-09
Wireshark MEDIUM 5.0
CVE-2013-3558

The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bi…

Mitigation only
Fix from $1,600 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3559

epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote at…

Patch available
Fix from $1,600 2013-05-25
Debian Linux HIGH 7.8
CVE-2013-3561

Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malf…

Patch available
Fix from $1,950 2013-05-25
Debian Linux MEDIUM 5.0
CVE-2013-3562

Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x b…

Patch available
Fix from $1,600 2013-05-25
Acrobat Reader HIGH 10.0
CVE-2013-2727EPSS 5%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code…

Patch available
Fix from $1,950 2013-05-16
Publisher HIGH 9.3
CVE-2013-1327EPSS 21%

Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers…

Mitigation only
Fix from $1,950 2013-05-15
Publisher HIGH 9.3
CVE-2013-1329EPSS 21%

Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers…

Mitigation only
Fix from $1,950 2013-05-15
Linux Kernel HIGH 8.4
CVE-2013-2094 KEVEPSS 48%

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users…

Fix: 3.0.75 / 3.2.45+
Fix from $1,950 2013-05-14
Ubuntu Linux MEDIUM 5.0
CVE-2013-2020

Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewe…

Fix: after 0.97.7
Fix from $1,600 2013-05-13
Lotus Notes MEDIUM 6.8
CVE-2013-2977

Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x be…

Mitigation only
Fix from $1,600 2013-05-10
Glibc MEDIUM 6.8
CVE-2012-0864

Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass th…

No fix yet
Fix from $1,600 2013-05-02
Django MEDIUM 5.0
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended reso…

Mitigation only
Fix from $1,600 2013-05-02
Glibc MEDIUM 6.8
CVE-2009-5029EPSS 8%

Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possi…

Fix: after 2.14
Fix from $1,600 2013-05-02
Factorytalk Services Platform HIGH 7.8
CVE-2012-4713

Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-S…

Mitigation only
Fix from $1,950 2013-04-18
Factorytalk Services Platform HIGH 7.8
CVE-2012-4714

Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9…

Mitigation only
Fix from $1,950 2013-04-18
PostgreSQL HIGH 8.5
CVE-2013-1900

PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random …

Mitigation only
Fix from $1,950 2013-04-04
Linux Kernel HIGH 7.2
CVE-2013-0913

Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel…

Fix: 3.0.71 / 3.2.42+
Fix from $1,950 2013-03-18
Openafs MEDIUM 5.0
CVE-2013-1795

Integer overflow in ptserver in OpenAFS before 1.6.2 allows remote attackers to cause a denial of service (crash) via a large list from the IdToName …

Fix: after 1.6.1
Fix from $1,600 2013-03-14
Qpid MEDIUM 5.0
CVE-2012-4458EPSS 7%

The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via …

Fix: after 0.20
Fix from $1,600 2013-03-14
Qpid MEDIUM 5.0
CVE-2012-4459EPSS 9%

Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of s…

Fix: after 0.20
Fix from $1,600 2013-03-14
389 Directory Server MEDIUM 5.0
CVE-2013-0312

389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.

Fix: after 1.3.0.3
Fix from $1,600 2013-03-13
Flash Player HIGH 10.0
CVE-2013-0646EPSS 7%

Integer overflow in Adobe Flash Player before 10.3.183.68 and 11.x before 11.6.602.180 on Windows and Mac OS X, before 10.3.183.68 and 11.x before 11…

Fix: after 11.6.602.171
Fix from $1,950 2013-03-13
Ffmpeg HIGH 7.5
CVE-2013-2495

The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) da…

Fix: after 1.1.3
Fix from $1,950 2013-03-09