Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Edirectory HIGH 10.0
CVE-2008-4478EPSS 10%

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbit…

Fix: after 8.7.3.10
Fix from $1,950 2008-10-14
Cups MEDIUM 6.8
CVE-2008-3640

Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScr…

Fix: after 1.3.8
Fix from $1,600 2008-10-14
Mac Os X HIGH 10.0
CVE-2008-4211EPSS 7%

Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod to…

Patch available
Fix from $1,950 2008-10-10
Jasper HIGH 9.3
CVE-2008-3520

Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to i…

Patch available
Fix from $1,950 2008-10-02
Mplayer HIGH 9.3
CVE-2008-3827EPSS 11%

Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (pr…

Fix: after 1.0_rc2
Fix from $1,950 2008-09-29
Internet Authentication Service Helper Com Component MEDIUM 5.0
CVE-2008-4299EPSS 16%

A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll allows remote attackers to cause…

Mitigation only
Fix from $1,600 2008-09-29
Firefox HIGH 10.0
CVE-2008-4061

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Joomla HIGH 7.5
CVE-2008-4102

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by P…

Mitigation only
Fix from $1,950 2008-09-18
Mac Os X HIGH 10.0
CVE-2008-3616

Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial…

Patch available
Fix from $1,950 2008-09-16
Safari MEDIUM 5.0
CVE-2008-3950EPSS 7%

Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod t…

Patch available
Fix from $1,600 2008-09-16
Itunes HIGH 7.2
CVE-2008-3636

Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attacker…

Fix: after 7.6.1
Fix from $1,950 2008-09-11
Digital Image Suite HIGH 9.3
CVE-2008-3015EPSS 39%

Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP…

No fix yet
Fix from $1,950 2008-09-11
FreeBSD HIGH 7.1
CVE-2008-2464

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause…

No fix yet
Fix from $1,950 2008-09-11
Digital Image Suite HIGH 9.3
CVE-2007-5348EPSS 53%

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Offi…

Mitigation only
Fix from $1,950 2008-09-11
Dns2tcp HIGH 10.0
CVE-2008-3910

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns…

Fix: after 0.4
Fix from $1,950 2008-09-04
Linux Kernel HIGH 7.8
CVE-2008-3526

Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in t…

Mitigation only
Fix from $1,950 2008-08-27
Vlc Media Player MEDIUM 6.8
CVE-2008-3794EPSS 11%

Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execu…

No fix yet
Fix from $1,600 2008-08-26
Vlc Media Player HIGH 9.3
CVE-2008-3732EPSS 13%

Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (applica…

No fix yet
Fix from $1,950 2008-08-20
Linux Kernel HIGH 7.1
CVE-2008-3276

Integer overflow in the dccp_setsockopt_change function in net/dccp/proto.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux…

Mitigation only
Fix from $1,950 2008-08-18
Php Nuke MEDIUM 5.0
CVE-2008-3573

The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) w…

No fix yet
Fix from $1,600 2008-08-10
Coregraphics HIGH 9.3
CVE-2008-2322EPSS 6%

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $1,950 2008-08-04
Brightstor Arcserve Backup HIGH 10.0
CVE-2008-3175EPSS 14%

Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote a…

Patch available
Fix from $1,950 2008-08-01
Avg Antivirus MEDIUM 5.0
CVE-2008-3373

The files parsing engine in Grisoft AVG Anti-Virus before 8.0.156 allows remote attackers to cause a denial of service (engine crash) via a crafted U…

Mitigation only
Fix from $1,600 2008-07-30
Probe Builder HIGH 7.8
CVE-2008-1667

The Probe Builder Service (aka PBOVISServer.exe) in European Performance Systems (EPS) Probe Builder 2.2 before A.02.20.901, as used in HP OpenView I…

Patch available
Fix from $1,950 2008-07-29
Recursor MEDIUM 6.8
CVE-2008-3217

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote …

Fix: after 3.1.5
Fix from $1,600 2008-07-18
Safari HIGH 10.0
CVE-2008-2303EPSS 13%

Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a …

Mitigation only
Fix from $1,950 2008-07-14
Edirectory HIGH 10.0
CVE-2008-3159EPSS 9%

Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers …

Mitigation only
Fix from $1,950 2008-07-14
Soldner Secret Wars HIGH 7.8
CVE-2008-3135

Soldner Secret Wars 33724 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a large numeric value …

Mitigation only
Fix from $1,950 2008-07-10
Ruby HIGH 7.5
CVE-2008-2376

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2008-07-09
Data Engine HIGH 9.0
CVE-2008-0107EPSS 35%

Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 …

Mitigation only
Fix from $1,950 2008-07-08