Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Haproxy MEDIUM 5.0
CVE-2014-6269

Multiple integer overflows in the http_request_forward_body function in proto_http.c in HAProxy 1.5-dev23 before 1.5.4 allow remote attackers to caus…

No fix yet
Fix from $1,600 2014-09-30
Tvos MEDIUM 6.8
CVE-2014-4377EPSS 7%

Integer overflow in CoreGraphics in Apple iOS before 8 and Apple TV before 7 allows remote attackers to execute arbitrary code or cause a denial of s…

Fix: after 10.9.4
Fix from $1,600 2014-09-18
Iphone Os HIGH 9.3
CVE-2014-4389

Integer overflow in IOKit in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context via an appli…

Fix: after 10.9.4
Fix from $1,950 2014-09-18
Debian Linux HIGH 7.5
CVE-2014-5119EPSS 18%

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a de…

Fix: 2.20+
Fix from $1,950 2014-08-29
Kerberos 5 HIGH 8.5
CVE-2014-4345EPSS 8%

Off-by-one error in the krb5_encode_krbsecretkey function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c in the LDAP KDB module in kadmind in MIT …

Patch available
Fix from $1,950 2014-08-14
Access Gateway Plug In MEDIUM 6.8
CVE-2011-2593

Integer overflow in the StartEpa method in the nsepacom ActiveX control (nsepa.exe) in Citrix Access Gateway Enterprise Edition Plug-in for Windows 9…

Fix: after 9.3
Fix from $1,600 2014-08-12
Ubuntu Linux MEDIUM 6.8
CVE-2014-4909EPSS 5%

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial o…

Fix: after 2.83
Fix from $1,600 2014-07-29
Sketchbook Pro HIGH 9.3
CVE-2014-3938

Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file,…

Fix: after 6.2.5
Fix from $1,950 2014-07-23
Shopizer MEDIUM 6.4
CVE-2014-4962

Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity param…

Fix: after 1.1.5
Fix from $1,600 2014-07-15
Rt MEDIUM 5.0
CVE-2014-1474

Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denia…

Fix: after 0.01
Fix from $1,600 2014-07-15
Lz4 MEDIUM 5.0
CVE-2014-4715

Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows…

Mitigation only
Fix from $1,600 2014-07-03
Mac Os X HIGH 10.0
CVE-2014-1358

Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code…

Fix: after 7.1.1
Fix from $1,950 2014-07-01
Tvos HIGH 10.0
CVE-2014-1359

Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary cod…

Fix: after 7.1.1
Fix from $1,950 2014-07-01
Opensuse HIGH 10.0
CVE-2014-2977EPSS 7%

Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote a…

Mitigation only
Fix from $1,950 2014-06-11
Tomcat MEDIUM 5.0
CVE-2014-0075EPSS 20%

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.…

Mitigation only
Fix from $1,600 2014-05-31
Mediahome MEDIUM 5.0
CVE-2012-5876

Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (cra…

Fix: after 4.5.8.0
Fix from $1,600 2014-05-30
Chrome HIGH 7.5
CVE-2014-1744

Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google…

Fix: after 35.0.1916.113
Fix from $1,950 2014-05-21
Fedora HIGH 7.5
CVE-2014-3152

Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrom…

Fix: after 35.0.1916.113
Fix from $1,950 2014-05-21
Ubuntu Linux HIGH 7.5
CVE-2014-0211

Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4…

Fix: after 1.4.7
Fix from $1,950 2014-05-15
Chrome HIGH 7.5
CVE-2014-1741

Multiple integer overflows in the replace-data functionality in the CharacterData interface implementation in core/dom/CharacterData.cpp in Blink, as…

Fix: after 34.0.1847.136
Fix from $1,950 2014-05-14
Android Debug Bridge HIGH 7.5
CVE-2014-1909

Integer signedness error in system/core/adb/adb_client.c in Android Debug Bridge (ADB) for Android 4.4 in the Android SDK Platform Tools 18.0.1 allow…

No fix yet
Fix from $1,950 2014-05-14
Libpng MEDIUM 6.5
CVE-2013-7353

Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause …

Fix: after 1.5.13
Fix from $1,600 2014-05-06
Libpng MEDIUM 6.5
CVE-2013-7354

Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png…

Fix: after 1.5.13
Fix from $1,600 2014-05-06
Qemu HIGH 7.2
CVE-2014-2894

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact v…

Fix: after 1.7.1
Fix from $1,950 2014-04-23
Openjpeg HIGH 10.0
CVE-2013-4289

Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigg…

Fix: after 1.5.1
Fix from $1,950 2014-04-18
Elfutils MEDIUM 6.8
CVE-2014-0172

Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows…

Patch available
Fix from $1,600 2014-04-11
Chrome HIGH 7.5
CVE-2014-1721

Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows remote attackers to cause a d…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1717

Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote at…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Chrome HIGH 7.5
CVE-2014-1718

Integer overflow in the SoftwareFrameManager::SwapToNewFrame function in content/browser/renderer_host/software_frame_manager.cc in the software comp…

Fix: after 34.0.1847.115
Fix from $1,950 2014-04-09
Xen MEDIUM 5.2
CVE-2014-1891

Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID suboperations in the flask hyper…

Fix: after 4.3.0
Fix from $1,600 2014-04-01