Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Data Protection Advisor MEDIUM 5.0
CVE-2012-0407

Integer overflow in the DPA_Utilities library in EMC Data Protection Advisor (DPA) 5.5 through 5.8 SP1 allows remote attackers to cause a denial of s…

No fix yet
Fix from $1,600 2012-04-20
Acrobat Reader HIGH 10.0
CVE-2012-0774EPSS 15%

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code via a crafted TrueTyp…

Patch available
Fix from $1,950 2012-04-10
Samba HIGH 10.0
CVE-2012-1182EPSS 74%

The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array length in a …

Fix: after 3.4.15
Fix from $1,950 2012-04-10
Frontvue HIGH 9.3
CVE-2011-4043EPSS 7%

Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote at…

Fix: after 10.0
Fix from $1,950 2012-04-03
Gnutls MEDIUM 5.0
CVE-2012-1569

The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly han…

Fix: after 3.0.15
Fix from $1,600 2012-03-26
Db2 HIGH 7.5
CVE-2012-0711

Integer signedness error in the db2dasrrm process in the DB2 Administration Server (DAS) in IBM DB2 9.1 through FP11, 9.5 before FP9, and 9.7 through…

Mitigation only
Fix from $1,950 2012-03-20
Iphone Os HIGH 9.3
CVE-2012-0642

Integer underflow in Apple iOS before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (device crash) via a crafted…

Fix: 5.1+
Fix from $1,950 2012-03-08
Flash Player MEDIUM 5.0
CVE-2012-0769

Adobe Flash Player before 10.3.183.16 and 11.x before 11.1.102.63 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.7 on Android 2.x and 3.x;…

Fix: after 11.1.115.6
Fix from $1,600 2012-03-05
Hancom Office 2010 Se HIGH 9.3
CVE-2012-1206

Multiple integer overflows in Hancom Office 2010 SE 8.5.5 allow remote attackers to execute arbitrary code via large dimension values in a (1) JPG im…

Mitigation only
Fix from $1,950 2012-02-24
Acdsee HIGH 9.3
CVE-2012-1197

Integer overflow in the IDE_ACDStd.apl module for ACDSee 14.1 Build 137 allows remote attackers to execute arbitrary code via crafted "image dimensio…

Mitigation only
Fix from $1,950 2012-02-18
Opera Browser MEDIUM 5.0
CVE-2012-1003

Multiple integer overflows in Opera 11.60 and earlier allow remote attackers to cause a denial of service (application crash) via a large integer arg…

Fix: after 11.60
Fix from $1,600 2012-02-07
Mac Os X HIGH 7.5
CVE-2011-3453

Integer overflow in libresolv in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap me…

Fix: after 10.7.2
Fix from $1,950 2012-02-02
Mac Os X MEDIUM 6.8
CVE-2011-3459

Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (applica…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Renren Talk HIGH 9.3
CVE-2012-0915

Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a hea…

Mitigation only
Fix from $1,950 2012-01-24
Lotus Symphony HIGH 9.3
CVE-2012-0192EPSS 5%

Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute…

Fix: after 3.0.0.3
Fix from $1,950 2012-01-23
Messenger MEDIUM 5.1
CVE-2012-0268

Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remot…

Fix: after 11.5.0.152
Fix from $1,600 2012-01-19
Tomcat MEDIUM 5.0
CVE-2012-0022EPSS 11%

Apache Tomcat 5.5.x before 5.5.35, 6.x before 6.0.34, and 7.x before 7.0.23 uses an inefficient approach for handling parameters, which allows remote…

Mitigation only
Fix from $1,600 2012-01-19
Perl MEDIUM 5.1
CVE-2011-2939

Off-by-one error in the decode_xs function in Unicode/Unicode.xs in the Encode module before 2.44, as used in Perl before 5.15.6, might allow context…

Fix: after 5.14.2
Fix from $1,600 2012-01-13
Xtier Framework HIGH 7.5
CVE-2011-1710

Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash)…

Patch available
Fix from $1,950 2011-12-31
Codesys HIGH 7.5
CVE-2011-5008

Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size val…

No fix yet
Fix from $1,950 2011-12-25
Winamp HIGH 9.3
CVE-2011-3834EPSS 5%

Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a cr…

Fix: after 5.622
Fix from $1,950 2011-12-16
Realplayer HIGH 9.3
CVE-2011-4259

Integer underflow in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted width value in an MPG file.

Fix: after 14.0.7
Fix from $1,950 2011-11-24
Mac Os X MEDIUM 6.8
CVE-2011-3437

Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.7 before 10.7.2 allows remote attackers to execute arbitrary code via a cr…

Mitigation only
Fix from $1,600 2011-10-14
Groupwise HIGH 10.0
CVE-2011-2662

Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2011-10-08
Ffmpeg MEDIUM 6.8
CVE-2011-3362

Integer signedness error in the decode_residual_block function in cavsdec.c in libavcodec in FFmpeg before 0.7.3 and 0.8.x before 0.8.2, and libav th…

Fix: after 0.7.2
Fix from $1,600 2011-10-02
Ffmpeg MEDIUM 5.0
CVE-2011-3974

Integer signedness error in the decode_residual_inter function in cavsdec.c in libavcodec in FFmpeg before 0.7.4 and 0.8.x before 0.8.3 allows remote…

Fix: after 0.7.3
Fix from $1,600 2011-10-02
Firefox HIGH 10.0
CVE-2011-2998EPSS 5%

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute…

Mitigation only
Fix from $1,950 2011-09-30
Cogent Datahub MEDIUM 5.0
CVE-2011-3501

Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via a negative or large Content-…

No fix yet
Fix from $1,600 2011-09-16
Openttd HIGH 7.5
CVE-2011-3341

Multiple off-by-one errors in order_cmd.cpp in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly ex…

Fix: after 1.1.2
Fix from $1,950 2011-09-08
Libxml2 HIGH 9.3
CVE-2011-1944EPSS 13%

Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attacker…

Fix: after 1.8.16
Fix from $1,950 2011-09-02