Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Chrome MEDIUM 6.8
CVE-2009-1442

Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to exe…

Fix: after 1.0.154.53
Fix from $1,600 2009-05-07
Openview Network Node Manager HIGH 10.0
CVE-2008-2438EPSS 11%

Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary cod…

Patch available
Fix from $1,950 2009-04-28
Libmodplug HIGH 7.5
CVE-2009-1438

Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other…

Fix: after 0.8.5
Fix from $1,950 2009-04-27
Xpdf HIGH 10.0
CVE-2009-0165

Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified i…

Fix: after 3.02
Fix from $1,950 2009-04-23
Poppler MEDIUM 5.0
CVE-2009-1187EPSS 7%

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly exe…

Fix: after 0.10.5
Fix from $1,600 2009-04-23
Poppler MEDIUM 5.0
CVE-2009-1188EPSS 7%

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler b…

Fix: after 0.10.5
Fix from $1,600 2009-04-23
Cups MEDIUM 6.8
CVE-2009-0163

Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) an…

Fix: after 1.3.9
Fix from $1,600 2009-04-23
Xpdf MEDIUM 6.8
CVE-2009-1179EPSS 6%

Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote at…

Fix: after 3.02
Fix from $1,600 2009-04-23
Windows Media Player HIGH 9.3
CVE-2009-1331EPSS 18%

Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via …

No fix yet
Fix from $1,950 2009-04-17
Divx Web Player HIGH 9.3
CVE-2008-5259EPSS 6%

Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file…

Fix: after 1.4.2.7
Fix from $1,950 2009-04-16
Mpg123 HIGH 10.0
CVE-2009-1301EPSS 5%

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service…

Fix: after 1.7.1
Fix from $1,950 2009-04-16
Ghostscript HIGH 9.3
CVE-2009-0792

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier …

Fix: after 8.64
Fix from $1,950 2009-04-14
Openjdk MEDIUM 5.0
CVE-2009-0794

Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used…

Mitigation only
Fix from $1,600 2009-04-13
S.t.a.l.k.e.r.\ MEDIUM 5.0
CVE-2008-6704

Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to caus…

Fix: after 1.0006
Fix from $1,600 2009-04-10
Formats HIGH 9.3
CVE-2009-0197

Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (appl…

Fix: after 4.22
Fix from $1,950 2009-04-09
Afs HIGH 7.8
CVE-2009-1250

The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attack…

Fix: after 3.6
Fix from $1,950 2009-04-09
Clamav MEDIUM 5.0
CVE-2008-6680

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-ze…

Fix: after 0.94.2
Fix from $1,600 2009-04-08
Sunage MEDIUM 5.0
CVE-2008-6670

Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 2…

Fix: after 1.08.1
Fix from $1,600 2009-04-08
Sunage MEDIUM 5.0
CVE-2008-6671

Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted join packet to UDP port…

Fix: after 1.08.1
Fix from $1,600 2009-04-08
Sunage MEDIUM 5.0
CVE-2008-6672

Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service ("runtime error") via a crafted join packet to UDP port 27960,…

Fix: after 1.08.1
Fix from $1,600 2009-04-08
Linux Kernel MEDIUM 5.0
CVE-2009-1265

Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers…

No fix yet
Fix from $1,600 2009-04-08
Bitdefender Antivirus MEDIUM 5.0
CVE-2008-6661

Multiple integer overflows in the scanning engine in Bitdefender for Linux 7.60825 and earlier allow remote attackers to cause a denial of service (c…

Fix: after 7.60825
Fix from $1,600 2009-04-07
Java Runtime Environment HIGH 7.5
CVE-2009-1099EPSS 6%

Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, …

Patch available
Fix from $1,950 2009-03-25
Cms HIGH 9.3
CVE-2009-0584

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management Sy…

Fix: after 8.64
Fix from $1,950 2009-03-23
Libsoup HIGH 7.5
CVE-2009-0585

Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attac…

Patch available
Fix from $1,950 2009-03-14
Evolution Data Server HIGH 7.5
CVE-2009-0587

Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary …

Fix: after 2.24.4
Fix from $1,950 2009-03-14
Linux Pam MEDIUM 6.6
CVE-2009-0887

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contain…

Fix: after 1.0.3
Fix from $1,600 2009-03-12
Winamp HIGH 9.3
CVE-2009-0186

Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted…

Fix: after 1.0.18
Fix from $1,950 2009-03-05
Psi HIGH 10.0
CVE-2008-6393EPSS 18%

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer …

Fix: after 0.12
Fix from $1,950 2009-03-03
Xine Lib HIGH 7.5
CVE-2009-0698

Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and poss…

Patch available
Fix from $1,950 2009-02-23