Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Cabextract MEDIUM 5.1
CVE-2010-2801

Integer signedness error in the Quantum decompressor in cabextract before 1.3, when archive test mode is used, allows user-assisted remote attackers …

Fix: after 1.2
Fix from $1,600 2010-08-09
Acrobat Reader HIGH 9.3
CVE-2010-2862EPSS 16%

Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType…

Mitigation only
Fix from $1,950 2010-08-05
Safari HIGH 9.3
CVE-2010-1791EPSS 6%

Integer signedness error in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows …

Fix: after 5.0
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-2752EPSS 10%

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Firefox HIGH 9.3
CVE-2010-1214EPSS 8%

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitr…

Fix: after 2.0.5
Fix from $1,950 2010-07-30
Qt HIGH 7.5
CVE-2010-1766

Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as …

Fix: after 4.6.2
Fix from $1,950 2010-07-22
Acrobat HIGH 9.3
CVE-2010-2206EPSS 7%

Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers…

Patch available
Fix from $1,950 2010-06-30
Imanager MEDIUM 5.0
CVE-2010-1930EPSS 8%

Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree pa…

No fix yet
Fix from $1,600 2010-06-28
Firefox HIGH 9.3
CVE-2010-1196

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird bef…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Firefox HIGH 9.3
CVE-2010-1199EPSS 11%

Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and…

Fix: after 3.0.4
Fix from $1,950 2010-06-24
Libtiff MEDIUM 6.8
CVE-2010-2065EPSS 6%

Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibl…

Fix: after 3.9.2
Fix from $1,600 2010-06-24
Mac Os X HIGH 7.5
CVE-2010-1380

Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to execute arbitrary code or …

Patch available
Fix from $1,950 2010-06-17
Mac Os X MEDIUM 6.8
CVE-2010-1411EPSS 13%

Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac …

Patch available
Fix from $1,600 2010-06-17
Flash Player HIGH 9.3
CVE-2010-2170EPSS 7%

Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execut…

Fix: after 1.5.3.9130
Fix from $1,950 2010-06-15
Flash Player HIGH 9.3
CVE-2010-2181EPSS 7%

Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execut…

Fix: after 1.5.3.9130
Fix from $1,950 2010-06-15
Flash Player HIGH 9.3
CVE-2010-2183EPSS 7%

Integer overflow in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execut…

Fix: after 1.5.3.9130
Fix from $1,950 2010-06-15
Sblim Sfcb HIGH 10.0
CVE-2010-2054EPSS 5%

Integer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB 1.3.4 through 1.3.7, when the configuration sets httpMaxContentLength to a zero value,…

Mitigation only
Fix from $1,950 2010-06-15
Dhcp MEDIUM 5.0
CVE-2010-2156EPSS 76%

ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

No fix yet
Fix from $1,600 2010-06-07
Glibc MEDIUM 5.0
CVE-2009-4880EPSS 11%

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attacke…

Fix: after 2.10.1
Fix from $1,600 2010-06-01
Glibc MEDIUM 5.0
CVE-2009-4881

Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.…

Fix: after 2.9
Fix from $1,600 2010-06-01
Glibc MEDIUM 5.1
CVE-2010-0830

Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through …

Patch available
Fix from $1,600 2010-06-01
FreeBSD HIGH 9.3
CVE-2010-1938EPSS 22%

Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE…

Fix: after 2.4.1
Fix from $1,950 2010-05-28
Ziproxy MEDIUM 6.8
CVE-2010-1513

Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related…

Fix: after 3.0.0
Fix from $1,600 2010-05-26
Java 1.5 MEDIUM 6.8
CVE-2010-0539

Integer signedness error in the window drawing implementation in Apple Java for Mac OS X 10.5 before Update 7 and Java for Mac OS X 10.6 before Updat…

Patch available
Fix from $1,600 2010-05-21
Outlook Express HIGH 9.3
CVE-2010-0816EPSS 20%

Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 a…

No fix yet
Fix from $1,950 2010-05-12
Gnustep Base HIGH 7.2
CVE-2010-1620

Integer overflow in the load_iface function in Tools/gdomap.c in gdomap in GNUstep Base before 1.20.0 might allow context-dependent attackers to exec…

Fix: after 1.19.3
Fix from $1,950 2010-05-12
Tex Live MEDIUM 6.8
CVE-2010-0827

Integer overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possib…

Fix: after 2009
Fix from $1,600 2010-05-07
Tetex MEDIUM 6.8
CVE-2010-1440

Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of servic…

Fix: after 2009
Fix from $1,600 2010-05-07
X.org HIGH 7.1
CVE-2010-1166EPSS 5%

The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of …

Patch available
Fix from $1,950 2010-04-29
Perl MEDIUM 5.0
CVE-2010-1158

Integer overflow in the regular expression engine in Perl 5.8.x allows context-dependent attackers to cause a denial of service (stack consumption an…

No fix yet
Fix from $1,600 2010-04-20