Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Opensolaris HIGH 7.8
CVE-2009-2487

Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through sn…

Patch available
Fix from $1,950 2009-07-16
Airlock Web Application Firewall HIGH 10.0
CVE-2009-2300

The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width…

Patch available
Fix from $1,950 2009-07-02
Pidgin MEDIUM 5.0
CVE-2009-1889

The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote…

Fix: after 2.5.7
Fix from $1,600 2009-07-01
Secure Gateway MEDIUM 5.0
CVE-2009-2214

The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an uns…

Fix: after 3.1
Fix from $1,600 2009-06-25
Physical Access Gateway HIGH 7.8
CVE-2009-1163

Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) v…

Fix: after 1.0
Fix from $1,950 2009-06-25
Jpeg2000 Jbig2 Decoder Add On HIGH 9.3
CVE-2009-0691EPSS 6%

The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a fatal error during deco…

Fix: after 2.0.2009.303
Fix from $1,950 2009-06-23
Opensolaris HIGH 7.8
CVE-2009-2137

Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-…

Patch available
Fix from $1,950 2009-06-19
Safari HIGH 7.1
CVE-2009-1692

WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows re…

No fix yet
Fix from $1,950 2009-06-19
Git MEDIUM 5.0
CVE-2009-2108EPSS 6%

git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request contai…

Patch available
Fix from $1,600 2009-06-18
Acrobat HIGH 9.3
CVE-2009-1857EPSS 7%

Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers t…

Patch available
Fix from $1,950 2009-06-11
Acrobat HIGH 9.3
CVE-2009-1858EPSS 9%

The JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1…

Patch available
Fix from $1,950 2009-06-11
Acrobat HIGH 9.3
CVE-2009-1859EPSS 7%

Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attac…

Patch available
Fix from $1,950 2009-06-11
Office HIGH 9.3
CVE-2009-0560EPSS 28%

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and S…

Mitigation only
Fix from $1,950 2009-06-10
Adam HIGH 7.8
CVE-2009-1139EPSS 39%

Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) o…

Mitigation only
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1701EPSS 8%

Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS fo…

Fix: after 3.2.2
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1709EPSS 7%

Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to exec…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1711EPSS 7%

WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code o…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1687EPSS 8%

The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 do…

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Safari HIGH 9.3
CVE-2009-1690EPSS 7%

Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, …

Fix: after 4.0_beta
Fix from $1,950 2009-06-10
Cups MEDIUM 5.0
CVE-2009-1196

The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon ou…

Patch available
Fix from $1,600 2009-06-09
Strongswan MEDIUM 5.0
CVE-2009-1957

charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and…

Fix: after 4.3.0
Fix from $1,600 2009-06-08
Strongswan MEDIUM 5.0
CVE-2009-1958

charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote…

Fix: after 4.2.9
Fix from $1,600 2009-06-08
Firefox MEDIUM 5.0
CVE-2009-1827

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Ra…

No fix yet
Fix from $1,600 2009-05-29
Firefox MEDIUM 5.0
CVE-2009-1828EPSS 9%

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN el…

No fix yet
Fix from $1,600 2009-05-29
Xen MEDIUM 5.0
CVE-2009-1758

The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows…

Fix: after 3.3.1
Fix from $1,600 2009-05-22
Ipsec Tools MEDIUM 5.0
CVE-2009-1632

Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) …

Fix: after 0.7.1
Fix from $1,600 2009-05-14
Chrome MEDIUM 5.0
CVE-2009-1514

Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement …

No fix yet
Fix from $1,600 2009-05-04
Firefox HIGH 9.3
CVE-2009-1313EPSS 8%

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,950 2009-04-30
Acrobat HIGH 9.3
CVE-2009-1492EPSS 26%

The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial o…

Fix: after 9.1
Fix from $1,950 2009-04-30
Reader MEDIUM 6.8
CVE-2009-1493EPSS 22%

The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers …

No fix yet
Fix from $1,600 2009-04-30