Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Cups MEDIUM 6.8
CVE-2009-0577

Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbit…

Patch available
Fix from $1,600 2009-02-20
Android Sdk HIGH 7.2
CVE-2009-0607

Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1)…

Mitigation only
Fix from $1,950 2009-02-17
Android Sdk HIGH 7.2
CVE-2009-0608

Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer ove…

Mitigation only
Fix from $1,950 2009-02-17
Mac Os X HIGH 9.3
CVE-2009-0139

Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute ar…

Patch available
Fix from $1,950 2009-02-13
Opencore MEDIUM 6.8
CVE-2009-0475

Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2009-02-11
F Secure Anti Virus HIGH 7.6
CVE-2008-6085EPSS 6%

Integer overflow in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, w…

Fix: after 8.00
Fix from $1,950 2009-02-06
Tightvnc HIGH 10.0
CVE-2009-0388EPSS 13%

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap…

Patch available
Fix from $1,950 2009-02-04
Rt73 HIGH 9.3
CVE-2009-0282EPSS 6%

Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570,…

Mitigation only
Fix from $1,950 2009-01-27
Amarok HIGH 9.3
CVE-2009-0136EPSS 7%

Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote atta…

No fix yet
Fix from $1,950 2009-01-16
Xrdp HIGH 7.5
CVE-2008-5903

Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code vi…

Fix: after 0.4.1
Fix from $1,950 2009-01-15
Safari HIGH 9.3
CVE-2009-0070

Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (appli…

No fix yet
Fix from $1,950 2009-01-08
Zaptel HIGH 7.2
CVE-2008-5744

Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer…

Fix: after 1.4.11
Fix from $1,950 2008-12-26
Qemu HIGH 7.8
CVE-2008-5714

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters…

Mitigation only
Fix from $1,950 2008-12-24
Mac Os X HIGH 9.3
CVE-2008-4217EPSS 5%

Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO a…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 7.2
CVE-2008-4218

Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call t…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 10.0
CVE-2008-4220

Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code o…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Windows 2000 HIGH 9.3
CVE-2008-2249EPSS 31%

Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote att…

Mitigation only
Fix from $1,950 2008-12-10
Office Frontpage HIGH 8.5
CVE-2008-4254EPSS 22%

Multiple integer overflows in the Hierarchical FlexGrid ActiveX control (mshflxgd.ocx) in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.…

Mitigation only
Fix from $1,950 2008-12-10
Zaptel HIGH 7.2
CVE-2008-5396

Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group t…

Fix: after 1.4.11
Fix from $1,950 2008-12-09
Jre HIGH 9.3
CVE-2008-5357EPSS 10%

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.…

Patch available
Fix from $1,950 2008-12-05
Vlc Media Player HIGH 9.3
CVE-2008-5276EPSS 8%

Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote at…

No fix yet
Fix from $1,950 2008-12-03
Lcms HIGH 10.0
CVE-2008-5317

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have a…

Fix: after 1.16
Fix from $1,950 2008-12-03
Cups HIGH 7.5
CVE-2008-5286

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image wit…

Patch available
Fix from $1,950 2008-12-01
Air Marshal HIGH 10.0
CVE-2008-5284

The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Mar…

Fix: after 5.1.42
Fix from $1,950 2008-11-29
Xine HIGH 10.0
CVE-2008-5237EPSS 6%

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or …

Fix: after 1.1.5
Fix from $1,950 2008-11-26
Xine HIGH 7.1
CVE-2008-5238

Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, allows remote attackers to cau…

Fix: after 1.1.14
Fix from $1,950 2008-11-26
Libxml HIGH 7.8
CVE-2008-4225

Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via…

Patch available
Fix from $1,950 2008-11-25
Wincome Mpd Total HIGH 10.0
CVE-2008-5159EPSS 60%

Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers t…

Fix: after 3.0.2.623
Fix from $1,950 2008-11-18
Firefox HIGH 10.0
CVE-2008-5017

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x bef…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Vlc Media Player HIGH 9.3
CVE-2008-4686EPSS 10%

Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote att…

Mitigation only
Fix from $1,950 2008-10-22