Vulnerability index

Browse CVEs

982 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Numeric ErrorsCWE-189 × clear
Xen MEDIUM 5.2
CVE-2014-1893

Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlie…

Fix: after 4.1.6.1
Fix from $1,600 2014-04-01
Xen MEDIUM 5.2
CVE-2014-1894

Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is enabled, allow local users to ca…

Fix: after 3.2.3
Fix from $1,600 2014-04-01
Xen MEDIUM 5.8
CVE-2014-1895

Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CP…

Patch available
Fix from $1,600 2014-04-01
PostgreSQL MEDIUM 6.5
CVE-2014-2669

Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before…

Patch available
Fix from $1,600 2014-03-31
PostgreSQL MEDIUM 6.5
CVE-2014-0064EPSS 5%

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.…

Fix: after 8.4.19
Fix from $1,600 2014-03-31
Icinga MEDIUM 5.0
CVE-2014-2386

Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vector…

Fix: after 1.10.2
Fix from $1,600 2014-03-25
Xnview HIGH 9.3
CVE-2013-3938

Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY struct…

Mitigation only
Fix from $1,950 2014-03-18
Ubuntu Linux MEDIUM 6.8
CVE-2013-6475

Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow …

Fix: after 1.0.46
Fix from $1,600 2014-03-14
Ffmpeg MEDIUM 6.8
CVE-2014-2099

The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to…

Fix: after 2.1.3
Fix from $1,600 2014-03-02
Libpng MEDIUM 5.0
CVE-2014-0333

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of …

Patch available
Fix from $1,600 2014-02-27
Mac Os X HIGH 7.5
CVE-2014-1261

Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (appl…

Fix: after 10.9.1
Fix from $1,950 2014-02-27
Enterprise Virtualization MEDIUM 5.0
CVE-2012-3404

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer le…

Patch available
Fix from $1,600 2014-02-10
Enterprise Virtualization MEDIUM 5.0
CVE-2012-3405

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer le…

Mitigation only
Fix from $1,600 2014-02-10
Android Msm HIGH 7.8
CVE-2013-4736

Multiple integer overflows in the JPEG engine drivers in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Cen…

Patch available
Fix from $1,950 2014-02-10
Mumble HIGH 7.5
CVE-2014-0045

The needSamples method in AudioOutputSpeech.cpp in the client in Mumble 1.2.4 and the 1.2.3 pre-release snapshots, Mumble for iOS 1.1 through 1.2.2, …

Mitigation only
Fix from $1,950 2014-02-08
Pidgin HIGH 7.5
CVE-2013-6487EPSS 8%

Integer overflow in libpurple/protocols/gg/lib/http.c in the Gadu-Gadu (gg) parser in Pidgin before 2.10.8 allows remote attackers to have an unspeci…

Fix: after 2.10.7
Fix from $1,950 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6489EPSS 6%

Integer signedness error in the MXit functionality in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (segmentation fault) …

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Pidgin MEDIUM 5.0
CVE-2013-6477

Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a…

Fix: after 2.10.7
Fix from $1,600 2014-02-06
Csound HIGH 9.3
CVE-2012-2106EPSS 6%

Integer overflow in the pv_import function in util/pv_import.c in Csound 5.16.6, when converting a file, allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2014-02-04
Csound HIGH 9.3
CVE-2012-2107EPSS 7%

Integer overflow in the main function in util/lpci_main.c in Csound before 5.17.2, when converting a file, allows user-assisted remote attackers to e…

Fix: after 5.17
Fix from $1,950 2014-02-04
Streaming Media HIGH 7.5
CVE-2013-6933EPSS 17%

The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, all…

Mitigation only
Fix from $1,950 2014-01-23
Streaming Media HIGH 7.5
CVE-2013-6934EPSS 28%

The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attacker…

Fix: 2.1.0+
Fix from $1,950 2014-01-23
Libreswan MEDIUM 5.0
CVE-2013-4564

Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number…

Patch available
Fix from $1,600 2014-01-07
Freerdp MEDIUM 6.8
CVE-2014-0791

Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a d…

Patch available
Fix from $1,600 2014-01-03
Linux Kernel MEDIUM 5.7
CVE-2013-6367

The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial o…

Fix: after 3.12.5
Fix from $1,600 2013-12-14
Linux Kernel MEDIUM 5.2
CVE-2013-6376

The recalculate_apic_map function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a de…

Fix: after 3.12.5
Fix from $1,600 2013-12-14
Memcached MEDIUM 5.0
CVE-2011-4971EPSS 22%

Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) process_bin_…

Fix: after 1.4.5
Fix from $1,600 2013-12-12
Ffmpeg MEDIUM 6.8
CVE-2013-7010

Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds ar…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7013

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote at…

Fix: after 2.0.1
Fix from $1,600 2013-12-09
Ffmpeg MEDIUM 6.8
CVE-2013-7014

Integer signedness error in the add_bytes_l2_c function in libavcodec/pngdsp.c in FFmpeg before 2.1 allows remote attackers to cause a denial of serv…

Fix: after 2.0.1
Fix from $1,600 2013-12-09