Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Simple Machines Forum HIGH 7.5
CVE-2008-3072

Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number ge…

Fix: after 1.1.4
Fix from $1,950 2008-07-08
Vlc Media Player HIGH 9.3
CVE-2008-2430EPSS 6%

Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2008-07-07
Pidgin MEDIUM 6.8
CVE-2008-2927

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libp…

Fix: after 2.4.2
Fix from $1,600 2008-07-07
Ruby HIGH 10.0
CVE-2008-2662

Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 befor…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby HIGH 7.8
CVE-2008-2725

Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Ruby HIGH 7.8
CVE-2008-2726

Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p2…

Fix: 1.8.5.231 / 1.8.6.230+
Fix from $1,950 2008-06-24
Firefox HIGH 9.3
CVE-2008-2785EPSS 5%

Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as …

Fix: after 2.0.0.15
Fix from $1,950 2008-06-19
Netwide Assembler MEDIUM 6.8
CVE-2008-2719EPSS 10%

Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service …

Mitigation only
Fix from $1,600 2008-06-16
Opensolaris HIGH 7.2
CVE-2008-2710

Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10…

Fix: after 10
Fix from $1,950 2008-06-16
X11 HIGH 9.0
CVE-2008-1377

The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization …

Patch available
Fix from $1,950 2008-06-16
X11 MEDIUM 6.8
CVE-2008-1379

Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to re…

Patch available
Fix from $1,600 2008-06-16
Freetype HIGH 7.5
CVE-2008-1806

Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values wit…

Patch available
Fix from $1,950 2008-06-16
Freetype HIGH 7.5
CVE-2008-1807

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PF…

Mitigation only
Fix from $1,950 2008-06-16
Freetype HIGH 7.5
CVE-2008-1808

Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer…

Patch available
Fix from $1,950 2008-06-16
X11 HIGH 9.0
CVE-2008-2360

Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to exe…

Patch available
Fix from $1,950 2008-06-16
X11 MEDIUM 6.8
CVE-2008-2361

Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attacke…

Patch available
Fix from $1,600 2008-06-16
X11 HIGH 10.0
CVE-2008-2362

Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code v…

Patch available
Fix from $1,950 2008-06-16
Motion HIGH 10.0
CVE-2008-2654EPSS 8%

Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a …

Fix: after 3.2.10
Fix from $1,950 2008-06-13
Openoffice.org HIGH 9.3
CVE-2008-2152EPSS 6%

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers …

Mitigation only
Fix from $1,950 2008-06-10
Linux Kernel HIGH 7.2
CVE-2008-2358

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel…

Mitigation only
Fix from $1,950 2008-06-10
Opensuse HIGH 10.0
CVE-2008-2388

Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors. NOTE: the vendor states that these "can …

No fix yet
Fix from $1,950 2008-06-06
Borland Interbase HIGH 7.5
CVE-2008-2559

Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050,…

No fix yet
Fix from $1,950 2008-06-05
Mac Os X HIGH 9.3
CVE-2008-1034EPSS 8%

Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (applic…

Fix: after 10.4
Fix from $1,950 2008-06-02
Gnutls HIGH 10.0
CVE-2008-1948EPSS 12%

The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate …

Patch available
Fix from $1,950 2008-05-21
Gnutls MEDIUM 5.0
CVE-2008-1950

Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attac…

Patch available
Fix from $1,600 2008-05-21
Libvorbis MEDIUM 6.8
CVE-2008-1420EPSS 6%

Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbi…

Mitigation only
Fix from $1,600 2008-05-16
Libvorbis HIGH 9.3
CVE-2008-1423EPSS 8%

Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2008-05-16
Rdesktop HIGH 9.3
CVE-2008-1803EPSS 7%

Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parame…

Patch available
Fix from $1,950 2008-05-12
Rdesktop HIGH 9.3
CVE-2008-1801EPSS 13%

Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly ex…

No fix yet
Fix from $1,950 2008-05-12
Brightstor Arcserve Backup MEDIUM 5.0
CVE-2008-1979

The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a pac…

Fix: after 12.0.5454.0
Fix from $1,600 2008-04-27