Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Safari HIGH 9.3
CVE-2010-0052EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Safari HIGH 9.3
CVE-2010-0053EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Safari HIGH 9.3
CVE-2010-0054EPSS 6%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Safari HIGH 8.8
CVE-2010-0047EPSS 5%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Safari HIGH 8.8
CVE-2010-0048EPSS 5%

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (a…

Fix: after 4.0.4
Fix from $1,950 2010-03-15
Internet Explorer HIGH 8.8
CVE-2010-0806 KEVEPSS 82%

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers t…

Patch available
Fix from $1,950 2010-03-10
Perforce Server MEDIUM 5.0
CVE-2010-0930

The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that i…

No fix yet
Fix from $1,600 2010-03-05
Pidgin MEDIUM 5.0
CVE-2010-0423

gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smiley…

Fix: after 2.6.5
Fix from $1,600 2010-02-24
Firefox HIGH 10.0
CVE-2010-0160EPSS 6%

The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle arra…

Fix: after 3.0.17
Fix from $1,950 2010-02-22
Chrome MEDIUM 5.0
CVE-2010-0664

Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrom…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Chrome HIGH 9.3
CVE-2010-0655EPSS 7%

Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash…

Fix: after 4.0.249.78
Fix from $1,950 2010-02-18
Chrome HIGH 9.3
CVE-2010-0659

The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which…

Fix: after 4.0.249.78
Fix from $1,950 2010-02-18
Chrony MEDIUM 5.0
CVE-2010-0293

The client logging functionality in chronyd in Chrony before 1.23.1 does not restrict the amount of memory used for storage of client information, wh…

Fix: after 1.23-pre1
Fix from $1,600 2010-02-08
Chrony MEDIUM 5.0
CVE-2010-0294

chronyd in Chrony before 1.23.1, and possibly 1.24-pre1, generates a syslog message for each unauthorized cmdmon packet, which allows remote attacker…

Fix: after 1.23-pre1
Fix from $1,600 2010-02-08
Chrony MEDIUM 5.0
CVE-2010-0292

The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service…

Fix: after 1.23-pre1
Fix from $1,600 2010-02-08
Lighttpd MEDIUM 5.0
CVE-2010-0295EPSS 12%

lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a den…

Fix: after 1.4.25
Fix from $1,600 2010-02-03
Linux Kernel HIGH 7.2
CVE-2009-4141

Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privil…

Fix: after 2.6.33
Fix from $1,950 2010-01-19
Netware HIGH 7.8
CVE-2010-0317EPSS 10%

Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a la…

No fix yet
Fix from $1,950 2010-01-15
OpenSSL MEDIUM 5.0
CVE-2009-4355EPSS 9%

Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote at…

Fix: after 0.9.8l
Fix from $1,600 2010-01-14
Acrobat HIGH 10.0
CVE-2009-3955EPSS 16%

Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted …

Fix: after 9.2
Fix from $1,950 2010-01-13
Adium MEDIUM 5.0
CVE-2010-0277

slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.6, including 2.6.4, and Adium 1.3.8 allows remote attackers to cause a denial of s…

Fix: after 2.6.5
Fix from $1,600 2010-01-09
Firefox MEDIUM 5.0
CVE-2010-0220

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a deni…

Fix: after 3.5.6
Fix from $1,600 2010-01-07
Mailsite HIGH 7.8
CVE-2009-4479

LDAP3A.exe in MailSite 8.0.4 allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) via unspecified vectors, …

No fix yet
Fix from $1,950 2009-12-30
Mybb MEDIUM 5.0
CVE-2009-4448

inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to cause a denial of service (CPU…

Patch available
Fix from $1,600 2009-12-29
Firefox HIGH 9.3
CVE-2009-3388

liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (app…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3980

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remot…

Fix: after 2.0
Fix from $1,950 2009-12-17
Linux Kernel HIGH 7.1
CVE-2009-4308

The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to c…

Fix: after 2.6.31
Fix from $1,950 2009-12-13
Adobe Air HIGH 9.3
CVE-2009-3797EPSS 6%

Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that tri…

Fix: after 1.5.2
Fix from $1,950 2009-12-10
Adobe Air HIGH 9.3
CVE-2009-3798EPSS 6%

Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger …

Fix: after 10.0.32.18
Fix from $1,950 2009-12-10
Office Project HIGH 9.3
CVE-2009-0102EPSS 24%

Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remo…

Mitigation only
Fix from $1,950 2009-12-09