Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2008-3072
Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number ge…
Simple Machines Forum
after 1.1.4
HIGH 9.3
CVE-2008-2430EPSS 6%
Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code …
Vlc Media Player
Mitigation only
MEDIUM 6.8
CVE-2008-2927
Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libp…
Pidgin
after 2.4.2
HIGH 10.0
CVE-2008-2662
Multiple integer overflows in the rb_str_buf_append function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 befor…
Ruby
1.8.5.231 / 1.8.6.230+
HIGH 7.8
CVE-2008-2725
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.…
Ruby
1.8.5.231 / 1.8.6.230+
HIGH 7.8
CVE-2008-2726
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p2…
Ruby
1.8.5.231 / 1.8.6.230+
HIGH 9.3
CVE-2008-2785EPSS 5%
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as …
Firefox
after 2.0.0.15
MEDIUM 6.8
CVE-2008-2719EPSS 10%
Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service …
Netwide Assembler
Mitigation only
HIGH 7.2
CVE-2008-2710
Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10…
Opensolaris
after 10
HIGH 9.0
CVE-2008-1377
The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization …
X11
Patch available
MEDIUM 6.8
CVE-2008-1379
Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to re…
X11
Patch available
HIGH 7.5
CVE-2008-1806
Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values wit…
Freetype
Patch available
HIGH 7.5
CVE-2008-1807
FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PF…
Freetype
Mitigation only
HIGH 7.5
CVE-2008-1808
Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer…
Freetype
Patch available
HIGH 9.0
CVE-2008-2360
Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to exe…
X11
Patch available
MEDIUM 6.8
CVE-2008-2361
Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attacke…
X11
Patch available
HIGH 10.0
CVE-2008-2362
Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code v…
X11
Patch available
HIGH 10.0
CVE-2008-2654EPSS 8%
Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a …
Motion
after 3.2.10
HIGH 9.3
CVE-2008-2152EPSS 6%
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers …
Openoffice.org
Mitigation only
HIGH 7.2
CVE-2008-2358
Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel…
Linux Kernel
Mitigation only
HIGH 10.0
CVE-2008-2388
Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors. NOTE: the vendor states that these "can …
Opensuse
No fix yet
HIGH 7.5
CVE-2008-2559
Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050,…
Borland Interbase
No fix yet
HIGH 9.3
CVE-2008-1034EPSS 8%
Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (applic…
Mac Os X
after 10.4
HIGH 10.0
CVE-2008-1948EPSS 12%
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate …
Gnutls
Patch available
MEDIUM 5.0
CVE-2008-1950
Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attac…
Gnutls
Patch available
MEDIUM 6.8
CVE-2008-1420EPSS 6%
Integer overflow in residue partition value (aka partvals) evaluation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to execute arbi…
Libvorbis
Mitigation only
HIGH 9.3
CVE-2008-1423EPSS 8%
Integer overflow in a certain quantvals and quantlist calculation in Xiph.org libvorbis 1.2.0 and earlier allows remote attackers to cause a denial o…
Libvorbis
Mitigation only
HIGH 9.3
CVE-2008-1803EPSS 7%
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parame…
Rdesktop
Patch available
HIGH 9.3
CVE-2008-1801EPSS 13%
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly ex…
Rdesktop
No fix yet
MEDIUM 5.0
CVE-2008-1979
The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a pac…
Brightstor Arcserve Backup
after 12.0.5454.0