Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Xpdf HIGH 9.3
CVE-2009-3608EPSS 10%

Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegrap…

Fix: after 0.12.0
Fix from $1,950 2009-10-21
Camimages HIGH 7.5
CVE-2009-3296

Multiple integer overflows in tiffread.c in CamlImages 2.2 might allow remote attackers to execute arbitrary code via TIFF images containing large wi…

Patch available
Fix from $1,950 2009-10-20
Acrobat HIGH 9.3
CVE-2009-2980EPSS 8%

Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or …

Fix: after 9.1.3
Fix from $1,950 2009-10-19
Acrobat HIGH 9.3
CVE-2009-2989EPSS 9%

Integer overflow in Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code vi…

Fix: after 9.1.3
Fix from $1,950 2009-10-19
Acrobat HIGH 9.3
CVE-2009-2990EPSS 69%

Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbit…

Fix: after 9.1.3
Fix from $1,950 2009-10-19
Fusion HIGH 7.8
CVE-2009-3282

Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the ho…

Fix: after 2.0.5
Fix from $1,950 2009-10-16
Windows 2003 Server HIGH 9.3
CVE-2009-2500EPSS 24%

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 9.3
CVE-2009-2504EPSS 21%

Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, W…

Mitigation only
Fix from $1,950 2009-10-14
Office HIGH 9.3
CVE-2009-2518EPSS 23%

Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) …

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 7.8
CVE-2009-2524EPSS 28%

Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, W…

Mitigation only
Fix from $1,950 2009-10-14
Windows 2003 Server HIGH 9.3
CVE-2009-3126EPSS 23%

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System S…

Mitigation only
Fix from $1,950 2009-10-14
Informix Client Sdk HIGH 9.3
CVE-2009-3691EPSS 7%

Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attacke…

No fix yet
Fix from $1,950 2009-10-13
Safari MEDIUM 6.8
CVE-2009-2804

Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary …

Fix: after 4.0.3
Fix from $1,600 2009-09-14
Mac Os X MEDIUM 6.8
CVE-2009-2805

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service …

Patch available
Fix from $1,600 2009-09-14
Openoffice.org HIGH 9.3
CVE-2009-0200EPSS 7%

Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code vi…

Fix: after 3.1
Fix from $1,950 2009-09-02
Visibroker HIGH 10.0
CVE-2008-7126EPSS 10%

Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (cr…

Fix: after 08.00.00.c1.03
Fix from $1,950 2009-08-31
Baidu Hi Im MEDIUM 5.0
CVE-2008-7013

NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-b…

Mitigation only
Fix from $1,600 2009-08-19
Windows 2003 Server HIGH 8.5
CVE-2009-1546EPSS 22%

Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary c…

Patch available
Fix from $1,950 2009-08-12
Windows 2000 HIGH 9.3
CVE-2009-1924EPSS 9%

Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to exec…

Mitigation only
Fix from $1,950 2009-08-12
Memcached HIGH 10.0
CVE-2009-2415EPSS 7%

Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes tha…

Mitigation only
Fix from $1,950 2009-08-10
Subversion HIGH 8.5
CVE-2009-2411EPSS 5%

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remot…

Fix: after 1.5.6
Fix from $1,950 2009-08-07
Apr Util HIGH 10.0
CVE-2009-2412EPSS 14%

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow …

Patch available
Fix from $1,950 2009-08-06
Xemacs HIGH 10.0
CVE-2009-2688EPSS 9%

Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash)…

Mitigation only
Fix from $1,950 2009-08-05
Camlimages MEDIUM 6.8
CVE-2009-2660

Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and …

No fix yet
Fix from $1,600 2009-08-04
Air HIGH 9.3
CVE-2009-1869EPSS 20%

Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and A…

Fix: after 10.0.22.87
Fix from $1,950 2009-07-31
Openexr HIGH 7.5
CVE-2009-1720EPSS 6%

Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly …

Patch available
Fix from $1,950 2009-07-31
Linux Kernel HIGH 7.2
CVE-2009-2584

Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on …

Fix: after 2.6.30.2
Fix from $1,950 2009-07-23
Firefox HIGH 10.0
CVE-2009-2463EPSS 6%

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.…

Patch available
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2468EPSS 6%

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Arma MEDIUM 5.0
CVE-2009-2547

Integer underflow in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause…

Fix: after 1.16_beta
Fix from $1,600 2009-07-20