Vulnerability index

Browse CVEs

983 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Windows 98 HIGH 7.5
CVE-2006-2376EPSS 41%

Integer overflow in the PolyPolygon function in Graphics Rendering Engine on Microsoft Windows 98 and Me allows remote attackers to execute arbitrary…

Patch available
Fix from $1,950 2006-06-13
Freetype MEDIUM 5.0
CVE-2006-0747EPSS 12%

Integer underflow in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a font file with an odd number of blue valu…

Fix: after 2.1
Fix from $1,600 2006-05-23
Freetype HIGH 7.5
CVE-2006-1861

Multiple integer overflows in FreeType before 2.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via…

Patch available
Fix from $1,950 2006-05-23
Netware MEDIUM 6.4
CVE-2006-2327

Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4…

Patch available
Fix from $1,600 2006-05-12
Opera Browser MEDIUM 5.1
CVE-2006-1834EPSS 12%

Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass…

Fix: after 8.53
Fix from $1,600 2006-04-19
Firefox HIGH 9.3
CVE-2006-1737

Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allo…

Mitigation only
Fix from $1,950 2006-04-14
Firefox HIGH 9.3
CVE-2006-1730EPSS 10%

Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.…

Patch available
Fix from $1,950 2006-04-14
Safari MEDIUM 5.0
CVE-2006-1552

Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image…

Patch available
Fix from $1,600 2006-03-31
Linux Kernel MEDIUM 6.9
CVE-2006-0038

Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows lo…

Patch available
Fix from $1,600 2006-03-22
Itunes MEDIUM 6.8
CVE-2006-1249EPSS 6%

Integer overflow in Apple QuickTime Player 7.0.3 and 7.0.4 and iTunes 6.0.1 and 6.0.2 allows remote attackers to execute arbitrary code via a FlashPi…

Mitigation only
Fix from $1,600 2006-03-19
Windows 2000 HIGH 9.3
CVE-2006-0020EPSS 19%

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and p…

Patch available
Fix from $1,950 2006-01-10
Linux MEDIUM 5.0
CVE-2005-3624

The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attac…

Patch available
Fix from $1,600 2005-12-31
Net Snmp HIGH 10.0
CVE-2005-4837EPSS 10%

snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote …

Fix: after 5.2.1.2
Fix from $1,950 2005-12-31
Skype HIGH 10.0
CVE-2005-3267EPSS 7%

Integer overflow in Skype client before 1.4.x.84 on Windows, before 1.3.x.17 on Mac OS, before 1.2.x.18 on Linux, and 1.1.x.6 and earlier allows remo…

Patch available
Fix from $1,950 2005-10-27
Xfree86 MEDIUM 5.1
CVE-2005-2495

Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.

Mitigation only
Fix from $1,600 2005-09-15
Ekg HIGH 7.5
CVE-2005-1852

Multiple integer overflows in libgadu, as used in Kopete in KDE 3.2.3 to 3.4.1, ekg before 1.6rc3, GNU Gadu, CenterICQ, Kadu, and other packages, all…

Patch available
Fix from $1,950 2005-07-26
Ethereal MEDIUM 5.0
CVE-2005-0739EPSS 8%

The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting strings, which could leave it v…

Fix: after 0.10.9
Fix from $1,600 2005-05-02
Unreal Engine HIGH 10.0
CVE-2003-1432EPSS 8%

Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (CPU consumption or crash) and possibly execute arbitr…

No fix yet
Fix from $1,950 2003-12-31
Vbulletin MEDIUM 5.0
CVE-2002-2235

member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which causes an error message to be ref…

No fix yet
Fix from $1,600 2002-12-31
Ftpd MEDIUM 5.0
CVE-2002-2245

ftpd in NetBSD 1.5 through 1.5.3 and 1.6 does not properly quote a digit in response to a STAT command for a filename that contains a carriage return…

Mitigation only
Fix from $1,600 2002-12-31
Apt Www Proxy MEDIUM 5.0
CVE-2002-2286

The parse-get function in utils.c for apt-www-proxy 0.1 allows remote attackers to cause a denial of service (crash) via an empty HTTP request, which…

No fix yet
Fix from $1,600 2002-12-31
Socks5 HIGH 7.8
CVE-2002-2367EPSS 5%

Off-by-one buffer overflow in NEC SOCKS5 1.0 r11 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code…

No fix yet
Fix from $1,950 2002-12-31
Dctc HIGH 7.8
CVE-2002-2419

Direct connect text client (DCTC) client 0.83.3 allows remote attackers to cause a denial of service (crash) via a string ending with a NULL byte cha…

Patch available
Fix from $1,950 2002-12-31