Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Hd Audio Codec Drivers MEDIUM 6.8
CVE-2008-1932

Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arb…

Fix: after 6.0.1.5604
Fix from $1,600 2008-04-25
Openoffice.org MEDIUM 6.8
CVE-2007-5746

Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an…

Mitigation only
Fix from $1,600 2008-04-17
Openoffice.org MEDIUM 6.8
CVE-2007-5747

Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a…

Fix: after 2.3.0
Fix from $1,600 2008-04-17
Openview Network Node Manager HIGH 10.0
CVE-2008-1842EPSS 12%

Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a de…

Fix: after 7.53
Fix from $1,950 2008-04-16
Fireflymediaserver HIGH 7.5
CVE-2008-1771

Integer overflow in the ws_getpostvars function in Firefly Media Server (formerly mt-daapd) 0.2.4.1 (0.9~r1696-1.2 on Debian) allows remote attackers…

Mitigation only
Fix from $1,950 2008-04-16
Libpng HIGH 7.5
CVE-2008-1382EPSS 6%

libpng 1.0.6 through 1.0.32, 1.2.0 through 1.2.26, and 1.4.0beta01 through 1.4.0beta19 allows context-dependent attackers to cause a denial of servic…

Mitigation only
Fix from $1,950 2008-04-14
Worksite Web HIGH 9.3
CVE-2008-1617

Double free vulnerability in Web TransferCtrl Class 8,2,1,4 (iManFile.cab), as used in WorkSite Web 8.2 before SP1 P2, allows remote attackers to exe…

Fix: after 8.2
Fix from $1,950 2008-04-08
Xine Lib HIGH 9.3
CVE-2008-1686EPSS 6%

Array index vulnerability in Speex 1.1.12 and earlier, as used in libfishsound 0.9.0 and earlier, including Illiminable DirectShow Filters and Annode…

Fix: after 1.1.12
Fix from $1,950 2008-04-08
Gcc MEDIUM 6.8
CVE-2008-1685

gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to…

Mitigation only
Fix from $1,600 2008-04-06
Recursor MEDIUM 6.8
CVE-2008-1637

PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for …

Fix: after 3.1.4
Fix from $1,600 2008-04-02
Silc Client MEDIUM 6.8
CVE-2008-1552

The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client b…

Fix: after 1.1.6
Fix from $1,600 2008-03-31
Mplayer HIGH 10.0
CVE-2008-1558EPSS 17%

Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory an…

No fix yet
Fix from $1,950 2008-03-31
FreeBSD HIGH 7.5
CVE-2008-1391EPSS 19%

Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent atta…

No fix yet
Fix from $1,950 2008-03-27
Vlc MEDIUM 6.8
CVE-2008-1489EPSS 12%

Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibl…

No fix yet
Fix from $1,600 2008-03-25
Xine Lib MEDIUM 6.8
CVE-2008-0073EPSS 9%

Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code …

Patch available
Fix from $1,600 2008-03-24
Xine Lib MEDIUM 6.8
CVE-2008-1482EPSS 10%

Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrar…

No fix yet
Fix from $1,600 2008-03-24
Mac Os X MEDIUM 6.9
CVE-2008-0051

Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 6.8
CVE-2008-0057

Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary…

Patch available
Fix from $1,600 2008-03-18
Perforce Server HIGH 7.8
CVE-2008-1338

The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a…

Fix: after 2007.3_143793
Fix from $1,950 2008-03-14
Perforce Server MEDIUM 5.0
CVE-2008-1302

The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a…

Fix: after 2007.3_143793
Fix from $1,600 2008-03-12
Maxdb HIGH 9.3
CVE-2008-0307

Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown…

Mitigation only
Fix from $1,950 2008-03-11
Speedstream 6520 HIGH 7.8
CVE-2008-1267

The Siemens SpeedStream 6520 router allows remote attackers to cause a denial of service (web interface crash) via an HTTP request to basehelp_Englis…

No fix yet
Fix from $1,950 2008-03-10
Android Sdk HIGH 7.5
CVE-2008-0986

Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote at…

No fix yet
Fix from $1,950 2008-03-06
Instant Messaging MEDIUM 5.0
CVE-2008-0944EPSS 12%

Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via…

No fix yet
Fix from $1,600 2008-02-25
Connect Enterprise Server HIGH 10.0
CVE-2007-6149EPSS 12%

Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote at…

Fix: after 6
Fix from $1,950 2008-02-13
Print Server MEDIUM 5.0
CVE-2008-0767EPSS 8%

ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with th…

Fix: after 5.1.2
Fix from $1,600 2008-02-13
Clamav HIGH 10.0
CVE-2008-0318EPSS 8%

Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of serv…

Fix: after 0.92
Fix from $1,950 2008-02-12
Acrobat HIGH 9.3
CVE-2008-0726EPSS 15%

Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSe…

Fix: after 8.1.1
Fix from $1,950 2008-02-12
Gnumeric HIGH 9.3
CVE-2008-0668

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute…

Fix: after 1.7.91
Fix from $1,950 2008-02-11
Mplayer HIGH 9.3
CVE-2008-0485EPSS 9%

Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV…

Fix: after 1.02rc2
Fix from $1,950 2008-02-05