Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Linux Kernel HIGH 7.8
CVE-2007-3642

The decode_choice function in net/netfilter/nf_conntrack_h323_asn1.c in the Linux kernel before 2.6.20.15, 2.6.21.x before 2.6.21.6, and before 2.6.2…

Fix: after 2.6.20.14
Fix from $1,950 2007-07-10
Glibc HIGH 7.2
CVE-2007-3508

Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large …

Fix: after 2.5
Fix from $1,950 2007-07-03
File MEDIUM 5.1
CVE-2007-2799

Integer overflow in the "file" program 4.20, when running on 32-bit systems, as used in products including The Sleuth Kit, might allow user-assisted …

Mitigation only
Fix from $1,600 2007-05-23
Jdk MEDIUM 6.8
CVE-2007-2788EPSS 18%

Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit (JDK) before 1.5.0_11-b03 and 1.6.x before 1.6.0_01-b06, and Su…

Patch available
Fix from $1,600 2007-05-22
Ubuntu Linux HIGH 8.5
CVE-2007-1351EPSS 6%

Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remot…

Patch available
Fix from $1,950 2007-04-06
Esx Server MEDIUM 5.0
CVE-2007-1270

Double free vulnerability in VMware ESX Server 3.0.0 and 3.0.1 allows attackers to cause a denial of service (crash), obtain sensitive information, o…

Mitigation only
Fix from $1,600 2007-04-06
Imagemagick MEDIUM 6.8
CVE-2007-1797

Multiple integer overflows in ImageMagick before 6.3.3-5 allow remote attackers to execute arbitrary code via (1) a crafted DCM image, which results …

Patch available
Fix from $1,600 2007-04-02
Debian Linux HIGH 9.3
CVE-2007-1667

Multiple integer overflows in (1) the XGetPixel function in ImUtil.c in X.Org libx11 before 1.0.3, and (2) XInitImage function in xwd.c for ImageMagi…

Fix: after 1.0.2
Fix from $1,950 2007-03-24
File HIGH 9.3
CVE-2007-1536EPSS 12%

Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execute arbitrary code via a file t…

Fix: after 4.19
Fix from $1,950 2007-03-20
Wordperfect Document Importer Exporter MEDIUM 6.8
CVE-2007-1466

Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assi…

Fix: after 0.8.8
Fix from $1,600 2007-03-16
Tcpdump MEDIUM 6.8
CVE-2007-1218

Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote att…

Fix: after 3.9.5
Fix from $1,600 2007-03-02
Firefox MEDIUM 6.8
CVE-2007-0008

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.…

Fix: after 1.5.0.9
Fix from $1,600 2007-02-26
FreeBSD HIGH 7.2
CVE-2007-0229

Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly …

No fix yet
Fix from $1,950 2007-01-13
Openoffice HIGH 9.3
CVE-2006-5870EPSS 8%

Multiple integer overflows in OpenOffice.org (OOo) 2.0.4 and earlier, and possibly other versions before 2.1.0; and StarOffice 6 through 8; allow use…

Fix: after 2.0.4
Fix from $1,950 2006-12-31
Nod32 Antivirus HIGH 9.3
CVE-2006-6676EPSS 6%

Integer overflow in the (a) OLE2 and (b) CHM parsers for ESET NOD32 Antivirus before 1.1743 allows remote attackers to execute arbitrary code via a c…

Fix: after 1.1742
Fix from $1,950 2006-12-21
Avg Antivirus HIGH 10.0
CVE-2006-5940

Unspecified vulnerability in Grisoft AVG Anti-Virus before 7.1.407 has unknown impact and remote attack vectors related to "Integer Issues" and parsi…

Patch available
Fix from $1,950 2006-11-16
Windows 2000 HIGH 7.5
CVE-2006-3445EPSS 41%

Integer overflow in the ReadWideString function in agentdpv.dll in Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 a…

Mitigation only
Fix from $1,950 2006-11-14
Imanager HIGH 7.8
CVE-2006-4517

Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP …

Fix: after 2.5
Fix from $1,950 2006-11-01
Kdelibs MEDIUM 6.8
CVE-2006-4811

Integer overflow in Qt 3.3 before 3.3.7, 4.1 before 4.1.5, and 4.2 before 4.2.1, as used in the KDE khtml library, kdelibs 3.1.3, and possibly other …

Patch available
Fix from $1,600 2006-10-18
Office HIGH 9.3
CVE-2006-3647EPSS 26%

Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code vi…

Mitigation only
Fix from $1,950 2006-10-10
Imagemagick MEDIUM 5.1
CVE-2006-3744

Multiple integer overflows in ImageMagick before 6.2.9 allows user-assisted attackers to execute arbitrary code via crafted Sun Rasterfile (bitmap) i…

Fix: after 6.2.8
Fix from $1,600 2006-08-25
Libtiff HIGH 7.5
CVE-2006-3464

TIFF library (libtiff) before 3.8.2 allows context-dependent attackers to pass numeric range checks and possibly execute code, and trigger assert err…

Fix: after 3.8.1
Fix from $1,950 2006-08-03
HTTP Server HIGH 7.6
CVE-2006-3747EPSS 96%

Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, …

Fix: 1.3.37 / 2.0.59+
Fix from $1,950 2006-07-28
Firefox HIGH 7.5
CVE-2006-3806EPSS 5%

Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might a…

Patch available
Fix from $1,950 2006-07-27
Mikmod MEDIUM 5.0
CVE-2006-3879EPSS 9%

Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial …

No fix yet
Fix from $1,600 2006-07-27
Freetype HIGH 7.5
CVE-2006-3467

Integer overflow in FreeType before 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafte…

Fix: after 2.1
Fix from $1,950 2006-07-21
Wireshark HIGH 7.5
CVE-2006-3630

Multiple off-by-one errors in Wireshark (aka Ethereal) 0.9.7 to 0.99.0 have unknown impact and remote attack vectors via the (1) NCP NMAS and (2) NDP…

Patch available
Fix from $1,950 2006-07-21
Itunes MEDIUM 5.1
CVE-2006-1467EPSS 7%

Integer overflow in the AAC file parsing code in Apple iTunes before 6.0.5 on Mac OS X 10.2.8 or later, and Windows XP and 2000, allows remote user-a…

Fix: after 6.0.4
Fix from $1,600 2006-06-29
Gnupg MEDIUM 5.0
CVE-2006-3082EPSS 7%

parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly o…

Fix: after 1.9.20
Fix from $1,600 2006-06-19
Wv2 MEDIUM 6.5
CVE-2006-2197

Integer overflow in wv2 before 0.2.3 might allow context-dependent attackers to execute arbitrary code via a crafted Microsoft Word document.

Fix: after 0.2.3
Fix from $1,600 2006-06-15