Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Gzip MEDIUM 6.8
CVE-2010-0001

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote at…

Fix: after 1.3.13
Fix from $1,600 2010-01-29
Libthai HIGH 10.0
CVE-2009-4012

Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger h…

Fix: after 0.1.12
Fix from $1,950 2010-01-19
Lib3ds HIGH 9.3
CVE-2010-0280EPSS 7%

Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of serv…

No fix yet
Fix from $1,950 2010-01-15
Google Sketchup HIGH 9.3
CVE-2010-0316

Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute a…

Mitigation only
Fix from $1,950 2010-01-15
Acrobat HIGH 10.0
CVE-2009-3959EPSS 11%

Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote atta…

Fix: after 9.2
Fix from $1,950 2010-01-13
Kerberos HIGH 10.0
CVE-2009-4212EPSS 7%

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3,…

Patch available
Fix from $1,950 2010-01-13
Windows 2000 HIGH 9.3
CVE-2010-0018EPSS 27%

Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 …

Mitigation only
Fix from $1,950 2010-01-13
Linux Kernel HIGH 7.8
CVE-2009-4536EPSS 5%

drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing…

Fix: after 2.6.32.3
Fix from $1,950 2010-01-12
Polipo MEDIUM 5.0
CVE-2009-4413EPSS 9%

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial…

No fix yet
Fix from $1,600 2009-12-24
Openview Storage Data Protector HIGH 10.0
CVE-2007-2281EPSS 9%

Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager compon…

Patch available
Fix from $1,950 2009-12-18
Winamp HIGH 9.3
CVE-2009-4356

Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (…

Fix: after 5.56
Fix from $1,950 2009-12-18
Winamp HIGH 9.3
CVE-2009-3997EPSS 6%

Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary code via an O…

Fix: after 5.56
Fix from $1,950 2009-12-18
Firefox HIGH 9.3
CVE-2009-3389

Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote at…

Fix: after 2.0
Fix from $1,950 2009-12-17
Linux Kernel HIGH 7.1
CVE-2009-4307

The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of…

Fix: after 2.6.32
Fix from $1,950 2009-12-13
Adobe Air HIGH 9.3
CVE-2009-3799EPSS 10%

Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote at…

Fix: after 10.0.32.18
Fix from $1,950 2009-12-10
Windows 2000 HIGH 9.3
CVE-2009-2506EPSS 31%

Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000…

Mitigation only
Fix from $1,950 2009-12-09
Corehttp HIGH 7.5
CVE-2009-3586EPSS 6%

Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary cod…

Patch available
Fix from $1,950 2009-12-08
Creator HIGH 9.3
CVE-2009-1566EPSS 7%

Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via a…

Fix: after 9.0.136
Fix from $1,950 2009-12-03
Edirectory HIGH 10.0
CVE-2009-0895EPSS 7%

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an …

Patch available
Fix from $1,950 2009-12-03
Mac Os X MEDIUM 6.8
CVE-2009-2826

Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (ap…

Patch available
Fix from $1,600 2009-11-10
Mac Os X MEDIUM 6.8
CVE-2009-2838

Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application cr…

Patch available
Fix from $1,600 2009-11-10
File HIGH 9.3
CVE-2009-3930

Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed com…

Fix: after 5.01
Fix from $1,950 2009-11-10
Jdk HIGH 9.3
CVE-2009-3874EPSS 10%

Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 be…

Patch available
Fix from $1,950 2009-11-05
Poppler MEDIUM 6.8
CVE-2009-3605

Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute …

Fix: after 0.10.5
Fix from $1,600 2009-11-02
Wireshark MEDIUM 5.0
CVE-2009-3551

Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attacke…

Patch available
Fix from $1,600 2009-10-30
Wireshark HIGH 9.3
CVE-2009-3829EPSS 6%

Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (applicati…

Fix: after 1.2.1
Fix from $1,950 2009-10-30
Linux Kernel HIGH 7.2
CVE-2009-3638

Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 all…

Fix: after 2.6.31.3
Fix from $1,950 2009-10-29
Xpdf HIGH 9.3
CVE-2009-3603EPSS 9%

Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to exec…

Fix: after 0.12.0
Fix from $1,950 2009-10-21
Xpdf HIGH 9.3
CVE-2009-3606EPSS 9%

Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphics KPDF, might allow remote a…

Patch available
Fix from $1,950 2009-10-21
Poppler HIGH 9.3
CVE-2009-3607EPSS 6%

Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial …

Mitigation only
Fix from $1,950 2009-10-21