Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Firefox MEDIUM 5.0
CVE-2009-2535EPSS 9%

Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpt…

Fix: after 2.0.0.18
Fix from $1,600 2009-07-20
Aigo Md P8860 HIGH 7.8
CVE-2009-2539

The Aigo P8860 allows remote attackers to cause a denial of service (memory consumption and browser hang) via a large integer value for the length pr…

No fix yet
Fix from $1,950 2009-07-20
Firefox MEDIUM 5.0
CVE-2009-2478EPSS 8%

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, re…

No fix yet
Fix from $1,600 2009-07-16
Edirectory MEDIUM 5.0
CVE-2009-0192EPSS 12%

Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute…

Mitigation only
Fix from $1,600 2009-07-14
Libtiff HIGH 9.3
CVE-2009-2347

Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to exe…

Patch available
Fix from $1,950 2009-07-14
Safari HIGH 9.3
CVE-2009-1725EPSS 6%

WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in…

Fix: after 4.0.1
Fix from $1,950 2009-07-09
Wxwidgets MEDIUM 6.8
CVE-2009-2369

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) an…

Mitigation only
Fix from $1,600 2009-07-08
Dillo HIGH 7.5
CVE-2009-2294

Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and poss…

Fix: after 2.1
Fix from $1,950 2009-07-05
Camlimages HIGH 7.5
CVE-2009-2295

Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image wi…

Fix: after 2.2
Fix from $1,950 2009-07-05
Foxit Reader HIGH 9.3
CVE-2009-0690EPSS 6%

The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the …

Patch available
Fix from $1,950 2009-06-23
Compress Raw Zlib Perl Module MEDIUM 6.8
CVE-2009-1391EPSS 7%

Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly ot…

Fix: after 2.015
Fix from $1,600 2009-06-16
Ruby MEDIUM 5.0
CVE-2009-1904EPSS 8%

The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application c…

Patch available
Fix from $1,600 2009-06-11
Acrobat HIGH 9.3
CVE-2009-1856EPSS 14%

Integer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1…

Patch available
Fix from $1,950 2009-06-11
Office HIGH 9.3
CVE-2009-0561EPSS 37%

Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Off…

Mitigation only
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1705EPSS 5%

CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote a…

Fix: after 3.2.3
Fix from $1,950 2009-06-10
Cups MEDIUM 6.8
CVE-2009-0791EPSS 6%

Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphic…

Patch available
Fix from $1,600 2009-06-09
Apr Util MEDIUM 6.4
CVE-2009-1956EPSS 12%

Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensit…

Fix: 2.2.12+
Fix from $1,600 2009-06-08
Irssi MEDIUM 5.0
CVE-2009-1959EPSS 8%

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (c…

No fix yet
Fix from $1,600 2009-06-08
Mac Os X MEDIUM 6.8
CVE-2009-1717

Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (mem…

Patch available
Fix from $1,600 2009-06-05
Good Plug Ins MEDIUM 6.8
CVE-2009-1932EPSS 5%

Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GSt…

No fix yet
Fix from $1,600 2009-06-04
Kernel HIGH 7.8
CVE-2009-1385EPSS 33%

Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the…

Fix: after 7.4.35
Fix from $1,950 2009-06-04
Imagemagick HIGH 9.3
CVE-2009-1882EPSS 7%

Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial…

Mitigation only
Fix from $1,950 2009-06-02
Winamp HIGH 9.3
CVE-2009-1831EPSS 36%

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted…

Fix: after 5.55
Fix from $1,950 2009-05-29
Solaris HIGH 10.0
CVE-2008-3870EPSS 8%

Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-b…

Patch available
Fix from $1,950 2009-05-26
Pidgin HIGH 9.3
CVE-2009-1376EPSS 13%

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libp…

Fix: after 2.5.5
Fix from $1,950 2009-05-26
Nsd MEDIUM 5.0
CVE-2009-1755

Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote…

Patch available
Fix from $1,600 2009-05-22
Mac Os X HIGH 9.3
CVE-2009-0010EPSS 8%

Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to…

Patch available
Fix from $1,950 2009-05-13
Mac Os X MEDIUM 6.8
CVE-2009-0155EPSS 6%

Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 a…

Patch available
Fix from $1,600 2009-05-13
Office Powerpoint HIGH 9.3
CVE-2009-0221EPSS 38%

Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file contain…

Mitigation only
Fix from $1,950 2009-05-12
Pango MEDIUM 6.8
CVE-2009-1194

Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause …

Fix: after 1.22
Fix from $1,600 2009-05-11