Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Acpid MEDIUM 5.0
CVE-2009-0798

ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connectivity loss) by opening a lar…

Fix: after 1.0.8
Fix from $1,600 2009-04-24
Xpdf MEDIUM 6.8
CVE-2009-1180EPSS 5%

The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute a…

Fix: after 3.02
Fix from $1,600 2009-04-23
Firefox MEDIUM 5.0
CVE-2009-1302

The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a d…

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1304

The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause …

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1305

The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a de…

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Office HIGH 9.3
CVE-2009-0100EPSS 29%

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and…

Mitigation only
Fix from $1,950 2009-04-15
Wic MEDIUM 5.0
CVE-2008-6713EPSS 8%

World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data bloc…

Fix: after 1.008
Fix from $1,600 2009-04-10
Internet Security HIGH 7.2
CVE-2009-0686

The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows l…

No fix yet
Fix from $1,950 2009-04-01
iOS HIGH 7.1
CVE-2009-0635

Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, a…

Patch available
Fix from $1,950 2009-03-27
iOS HIGH 7.8
CVE-2009-0626

The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS pa…

Mitigation only
Fix from $1,950 2009-03-27
Firefox HIGH 9.3
CVE-2009-1169EPSS 10%

The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a de…

Fix: after 3.0.7
Fix from $1,950 2009-03-27
Ldns MEDIUM 6.4
CVE-2009-1086

Heap-based buffer overflow in the ldns_rr_new_frm_str_internal function in ldns 1.4.x allows remote attackers to cause a denial of service (memory co…

Mitigation only
Fix from $1,600 2009-03-25
Liveaudio Activex Control HIGH 9.3
CVE-2009-1092EPSS 9%

Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers t…

No fix yet
Fix from $1,950 2009-03-25
Firefox HIGH 9.3
CVE-2009-1044EPSS 6%

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree met…

Patch available
Fix from $1,950 2009-03-23
Opera Browser HIGH 9.3
CVE-2009-0914

Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.

Fix: after 9.63
Fix from $1,950 2009-03-16
Wesnoth MEDIUM 5.0
CVE-2009-0878

The read_game_map function in src/terrain_translation.cpp in Wesnoth before r32987 allows remote attackers to cause a denial of service (memory consu…

Fix: after 1.4.7
Fix from $1,600 2009-03-12
Firefox HIGH 10.0
CVE-2009-0771

The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of ser…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 9.3
CVE-2009-0772

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denia…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 10.0
CVE-2009-0773EPSS 6%

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 9.3
CVE-2009-0774

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denia…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 10.0
CVE-2009-0775

Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execut…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox MEDIUM 5.0
CVE-2009-0821EPSS 5%

Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print fu…

Fix: after 2.0.0.20
Fix from $1,600 2009-03-05
Avahi Daemon HIGH 7.8
CVE-2009-0758

The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account for the network byte order of…

Mitigation only
Fix from $1,950 2009-03-03
Yaws MEDIUM 5.0
CVE-2009-0751EPSS 10%

Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.

Fix: after 1.79
Fix from $1,600 2009-03-02
Libpng HIGH 7.1
CVE-2008-6218

Memory leak in the png_handle_tEXt function in pngrutil.c in libpng before 1.2.33 rc02 and 1.4.0 beta36 allows context-dependent attackers to cause a…

Patch available
Fix from $1,950 2009-02-20
Networker Client HIGH 7.8
CVE-2008-6219

nsrexecd.exe in multiple EMC Networker products including EMC NetWorker Server, Storage Node, and Client 7.3.x and 7.4, 7.4.1, 7.4.2, Client and Stor…

Fix: after 7.3.2
Fix from $1,950 2009-02-20
Windows HIGH 7.8
CVE-2008-6194EPSS 11%

Memory leak in the DNS server in Microsoft Windows allows remote attackers to cause a denial of service (memory consumption) via DNS packets. NOTE: …

Mitigation only
Fix from $1,950 2009-02-19
Websphere Application Server MEDIUM 5.0
CVE-2008-4285

Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere A…

Patch available
Fix from $1,600 2009-02-17
Ip Soft Phone MEDIUM 5.0
CVE-2008-6141

Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount o…

Mitigation only
Fix from $1,600 2009-02-14
Mac Os X HIGH 9.3
CVE-2009-0140

Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory ex…

Patch available
Fix from $1,950 2009-02-13