Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Mplayer HIGH 7.5
CVE-2008-0486EPSS 5%

Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1…

No fix yet
Fix from $1,950 2008-02-05
Steamcast MEDIUM 5.0
CVE-2008-0548

Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP heade…

Fix: after 0.9.75
Fix from $1,600 2008-02-01
Steamcast MEDIUM 5.0
CVE-2008-0549

Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemo…

Fix: after 0.9.75
Fix from $1,600 2008-02-01
Steamcast HIGH 10.0
CVE-2008-0550EPSS 54%

Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a …

Fix: after 0.9.75
Fix from $1,950 2008-02-01
Firebird HIGH 7.8
CVE-2008-0387EPSS 46%

Integer overflow in Firebird SQL 1.0.3 and earlier, 1.5.x before 1.5.6, 2.0.x before 2.0.4, and 2.1.x before 2.1.0 RC1 might allow remote attackers t…

Fix: 1.5.6 / 2.0.4+
Fix from $1,950 2008-01-29
Axigen Mail Server HIGH 9.3
CVE-2008-0434EPSS 10%

Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string s…

No fix yet
Fix from $1,950 2008-01-23
Evi HIGH 9.3
CVE-2007-6429

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request …

Fix: after 1.4
Fix from $1,950 2008-01-18
Bind HIGH 10.0
CVE-2008-0122EPSS 12%

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows…

Fix: after 9.4.2
Fix from $1,950 2008-01-16
PostgreSQL MEDIUM 6.8
CVE-2007-4769

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.…

Fix: after 8.4.16
Fix from $1,600 2008-01-09
PostgreSQL MEDIUM 6.8
CVE-2007-6067

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11…

Fix: after 8.4.16
Fix from $1,600 2008-01-09
Feng HIGH 7.5
CVE-2007-6627

Integer overflow in the RTSP_remove_msg function in RTSP_lowlevel.c in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of se…

Fix: after 0.1.15
Fix from $1,950 2008-01-04
Opera Browser HIGH 7.8
CVE-2007-6523

Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) vi…

No fix yet
Fix from $1,950 2007-12-24
Libexif MEDIUM 6.8
CVE-2007-6352

Integer overflow in libexif 0.6.16 and earlier allows context-dependent attackers to execute arbitrary code via an image with crafted EXIF tags, poss…

Fix: after 0.6.16
Fix from $1,600 2007-12-20
Clamav HIGH 7.5
CVE-2007-6335EPSS 18%

Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW packed PE file, which trigger…

Fix: after 0.92
Fix from $1,950 2007-12-20
Clamav MEDIUM 6.8
CVE-2007-6336

Off-by-one error in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MS-ZIP compressed CAB file.

Fix: after 0.91
Fix from $1,600 2007-12-20
Linux Kernel HIGH 7.2
CVE-2007-5966

Integer overflow in the hrtimer_start function in kernel/hrtimer.c in the Linux kernel before 2.6.23.10 allows local users to execute arbitrary code …

Patch available
Fix from $1,950 2007-12-20
Cups HIGH 9.3
CVE-2007-5849EPSS 14%

Integer underflow in the asn1_get_string function in the SNMP back end (backend/snmp.c) for CUPS 1.2 through 1.3.4 allows remote attackers to execute…

Mitigation only
Fix from $1,950 2007-12-19
Exiftags HIGH 10.0
CVE-2007-6355

Integer overflow in exiftags before 1.01 has unknown impact and attack vectors, resulting from a "field offset overflow" that triggers an "illegal me…

Fix: after 1.00
Fix from $1,950 2007-12-18
Ie HIGH 9.3
CVE-2007-3902EPSS 36%

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to e…

Mitigation only
Fix from $1,950 2007-12-12
E2fsprogs MEDIUM 5.8
CVE-2007-5497

Multiple integer overflows in libext2fs in e2fsprogs before 1.40.3 allow user-assisted remote attackers to execute arbitrary code via a crafted files…

Fix: after 1.40.2
Fix from $1,600 2007-12-07
Mac Os X HIGH 7.8
CVE-2007-6276EPSS 9%

The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a …

No fix yet
Fix from $1,950 2007-12-07
Pro Wireless 3945abg MEDIUM 5.0
CVE-2007-5938

The iwl_set_rate function in compatible/iwl3945-base.c in iwlwifi 1.1.21 and earlier dereferences an iwl_get_hw_mode return value without checking fo…

No fix yet
Fix from $1,600 2007-12-06
Kerberos 5 HIGH 10.0
CVE-2007-5902EPSS 6%

Integer overflow in the svcauth_gss_get_principal function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (krb5) allows remote attackers to have an unkn…

No fix yet
Fix from $1,950 2007-12-06
Windows Media Player MEDIUM 5.0
CVE-2007-6236EPSS 19%

Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a certain AIFF file that triggers a…

No fix yet
Fix from $1,600 2007-12-04
Typespeed MEDIUM 5.0
CVE-2007-6220

typespeed before 0.6.4 allows remote attackers to cause a denial of service (application crash) via unspecified network behavior that triggers a divi…

Patch available
Fix from $1,600 2007-12-04
Cairo MEDIUM 6.8
CVE-2007-5503EPSS 5%

Multiple integer overflows in Cairo before 1.4.12 might allow remote attackers to execute arbitrary code, as demonstrated using a crafted PNG image w…

Fix: after 1.4.10
Fix from $1,600 2007-11-30
Backupexec System Recovery HIGH 7.8
CVE-2007-4347

Multiple integer overflows in the Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.…

Patch available
Fix from $1,950 2007-11-29
Mac Os X HIGH 7.2
CVE-2007-4269

Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleT…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-4686

Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cau…

Patch available
Fix from $1,950 2007-11-15
Pcre MEDIUM 6.8
CVE-2006-7227

Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to execute arbitrary code via a r…

Fix: after 6.6
Fix from $1,600 2007-11-14