Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Debian Linux HIGH 7.8
CVE-2013-2487

epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer …

Mitigation only
Fix from $1,950 2013-03-07
Debian Linux MEDIUM 6.1
CVE-2013-2486

The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark …

Mitigation only
Fix from $1,600 2013-03-07
Linux Kernel MEDIUM 6.2
CVE-2013-0228

The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an …

Fix: after 3.7.8
Fix from $1,600 2013-03-01
Codesys Gateway Server HIGH 7.8
CVE-2012-4706

Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that …

Fix: after 2.3.9.20
Fix from $1,950 2013-02-24
Encryption Desktop MEDIUM 6.9
CVE-2012-4351

Integer overflow in pgpwded.sys in Symantec PGP Desktop 10.x and Encryption Desktop 10.3.0 before MP1 allows local users to gain privileges via a cra…

Mitigation only
Fix from $1,600 2013-02-18
Flash Player HIGH 10.0
CVE-2013-0639EPSS 13%

Integer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on…

Fix: 3.6.0.597 / 3.6.0.599+
Fix from $1,950 2013-02-12
Miniupnpd HIGH 7.8
CVE-2013-1462

Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote atta…

Mitigation only
Fix from $1,950 2013-01-31
Chrome HIGH 7.5
CVE-2012-5149

Integer overflow in the audio IPC layer in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have un…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome MEDIUM 6.8
CVE-2012-5151

Integer overflow in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact …

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome HIGH 7.5
CVE-2012-5154

Integer overflow in Google Chrome before 24.0.1312.52 on Windows allows attackers to cause a denial of service or possibly have unspecified other imp…

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Acrobat HIGH 10.0
CVE-2013-0613EPSS 10%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2013-01-10
Acrobat HIGH 10.0
CVE-2013-0609EPSS 7%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2013-01-10
Xml Core Services HIGH 8.8
CVE-2013-0006EPSS 28%

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2013-01-09
Twiki MEDIUM 5.0
CVE-2012-6330EPSS 36%

The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a de…

Fix: after 5.1.2
Fix from $1,600 2013-01-04
Flash Player HIGH 10.0
CVE-2012-5677EPSS 7%

Integer overflow in Adobe Flash Player before 10.3.183.48 and 11.x before 11.5.502.135 on Windows, before 10.3.183.48 and 11.x before 11.5.502.136 on…

Fix: 3.5.0.880 / 3.5.0.890+
Fix from $1,950 2012-12-12
Wireshark MEDIUM 5.0
CVE-2012-6056

Integer overflow in the dissect_sack_chunk function in epan/dissectors/packet-sctp.c in the SCTP dissector in Wireshark 1.8.x before 1.8.4 allows rem…

Patch available
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6057

The dissect_eigrp_metric_comm function in epan/dissectors/packet-eigrp.c in the EIGRP dissector in Wireshark 1.8.x before 1.8.4 uses the wrong data t…

Patch available
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6058

Integer overflow in the dissect_icmpv6 function in epan/dissectors/packet-icmpv6.c in the ICMPv6 dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x…

No fix yet
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6060

Integer overflow in the dissect_iscsi_pdu function in epan/dissectors/packet-iscsi.c in the iSCSI dissector in Wireshark 1.6.x before 1.6.12 and 1.8.…

No fix yet
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6061

The dissect_wtp_common function in epan/dissectors/packet-wtp.c in the WTP dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 uses an …

No fix yet
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6053

epan/dissectors/packet-usb.c in the USB dissector in Wireshark 1.6.x before 1.6.12 and 1.8.x before 1.8.4 relies on a length field to calculate an of…

Patch available
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6054

The dissect_sflow_245_address_type function in epan/dissectors/packet-sflow.c in the sFlow dissector in Wireshark 1.8.x before 1.8.4 does not properl…

Patch available
Fix from $1,600 2012-12-05
Wireshark MEDIUM 5.0
CVE-2012-6055

epan/dissectors/packet-3g-a11.c in the 3GPP2 A11 dissector in Wireshark 1.8.x before 1.8.4 allows remote attackers to cause a denial of service (infi…

Patch available
Fix from $1,600 2012-12-05
Libssh HIGH 7.5
CVE-2012-4562EPSS 13%

Multiple integer overflows in libssh before 0.5.3 allow remote attackers to cause a denial of service (infinite loop or crash) and possibly execute a…

Fix: after 0.5.2
Fix from $1,950 2012-11-30
Android MEDIUM 6.8
CVE-2012-4221

Integer overflow in diagchar_core.c in the Qualcomm Innovation Center (QuIC) Diagnostics (aka DIAG) kernel-mode driver for Android 2.3 through 4.2 al…

Mitigation only
Fix from $1,600 2012-11-30
Evince MEDIUM 6.8
CVE-2011-5244

Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME ev…

Mitigation only
Fix from $1,600 2012-11-19
Gegl HIGH 7.5
CVE-2012-4433EPSS 13%

Multiple integer overflows in operations/external/ppm-load.c in GEGL (Generic Graphics Library) 0.2.0 allow remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,950 2012-11-18
Icedtea Web MEDIUM 6.8
CVE-2012-4540

Off-by-one error in the invoke function in IcedTeaScriptablePluginObject.cc in IcedTea-Web 1.1.x before 1.1.7, 1.2.x before 1.2.2, 1.3.x before 1.3.1…

Mitigation only
Fix from $1,600 2012-11-11
Chrome HIGH 7.5
CVE-2012-5127

Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unsp…

Fix: after 23.0.1271.62
Fix from $1,950 2012-11-07
Bind HIGH 7.8
CVE-2012-5166EPSS 34%

ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to c…

Mitigation only
Fix from $1,950 2012-10-10