Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Mac Os X HIGH 7.1
CVE-2008-4222

natd in network_cmds in Apple Mac OS X before 10.5.6, when Internet Sharing is enabled, allows remote attackers to cause a denial of service (infinit…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Mac Os X HIGH 7.1
CVE-2008-4236

Apple Type Services (ATS) in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to cause a denial of service (infinite loop) via a crafted emb…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Aruba Mobility Controller HIGH 7.8
CVE-2008-5563

Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.x, 3.1.x, 3.2.x, 3.3.1.x, and 3.3.2.x allows remote attackers to cause a denial of service (device crash)…

Mitigation only
Fix from $1,950 2008-12-15
Smsgate MEDIUM 5.0
CVE-2008-5421

The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large int…

Fix: after 1.1n
Fix from $1,600 2008-12-11
Office Excel HIGH 9.3
CVE-2008-4264EPSS 26%

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Office Compatibility Pack f…

Mitigation only
Fix from $1,950 2008-12-10
Office Excel HIGH 9.3
CVE-2008-4265EPSS 25%

Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, w…

Mitigation only
Fix from $1,950 2008-12-10
Excel HIGH 9.3
CVE-2008-4266EPSS 28%

Array index vulnerability in Microsoft Office Excel 2000 SP3, 2002 SP3, and 2003 SP3; Excel Viewer 2003 Gold and SP3; Office 2004 and 2008 for Mac; a…

Mitigation only
Fix from $1,950 2008-12-10
Wordpad HIGH 9.3
CVE-2008-4841EPSS 43%

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute ar…

No fix yet
Fix from $1,950 2008-12-10
Office HIGH 9.3
CVE-2008-4026EPSS 23%

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, …

Mitigation only
Fix from $1,950 2008-12-10
Office HIGH 9.3
CVE-2008-4027EPSS 34%

Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 G…

Mitigation only
Fix from $1,950 2008-12-10
Office HIGH 9.3
CVE-2008-4030EPSS 23%

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compa…

Mitigation only
Fix from $1,950 2008-12-10
Office HIGH 9.3
CVE-2008-4031EPSS 23%

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibi…

Mitigation only
Fix from $1,950 2008-12-10
Office Frontpage HIGH 8.5
CVE-2008-4253EPSS 21%

The FlexGrid ActiveX control in Microsoft Visual Basic 6.0, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, Office FrontPage 2002 SP3, and Office Project …

Mitigation only
Fix from $1,950 2008-12-10
Office Frontpage HIGH 8.5
CVE-2008-4256EPSS 21%

The Charts ActiveX control in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 doe…

Mitigation only
Fix from $1,950 2008-12-10
Trillian HIGH 10.0
CVE-2008-5402EPSS 7%

Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expressio…

Mitigation only
Fix from $1,950 2008-12-10
Ruby HIGH 7.8
CVE-2008-4310EPSS 14%

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (C…

Mitigation only
Fix from $1,950 2008-12-09
Esx HIGH 7.2
CVE-2008-4917

Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and…

Fix: after 6.0.5
Fix from $1,950 2008-12-09
Wireshark MEDIUM 5.0
CVE-2008-5285

Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.

Fix: after 1.0.4
Fix from $1,600 2008-12-01
Zim Server MEDIUM 5.0
CVE-2008-5280EPSS 7%

The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer …

Fix: after 2.1
Fix from $1,600 2008-11-29
Iphone Os HIGH 7.1
CVE-2008-1586

ImageIO in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allow remote attackers to cause a denial of service (memory c…

Mitigation only
Fix from $1,950 2008-11-25
Libxml HIGH 10.0
CVE-2008-4226

Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruptio…

Patch available
Fix from $1,950 2008-11-25
Safari HIGH 9.3
CVE-2008-4231EPSS 6%

Safari in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 does not properly handle HTML TABLE elements, which allows rem…

Mitigation only
Fix from $1,950 2008-11-25
Geshi MEDIUM 5.0
CVE-2008-5185

The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (infinite loop) via an XML seq…

Fix: after 1.0.7.22
Fix from $1,600 2008-11-21
Office Communicator MEDIUM 5.0
CVE-2008-5181EPSS 13%

Microsoft Communicator allows remote attackers to cause a denial of service (application or device outage) via instant messages containing large numb…

Mitigation only
Fix from $1,600 2008-11-20
Firefox HIGH 9.3
CVE-2008-5013

Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properl…

Fix: after 2.0.0.17
Fix from $1,950 2008-11-13
Firefox MEDIUM 5.0
CVE-2008-5016

The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to ca…

Fix: after 3.0.3
Fix from $1,600 2008-11-13
Firefox HIGH 10.0
CVE-2008-5018

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 10.0
CVE-2008-5052

The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x…

Fix: 2.0.0.18+
Fix from $1,950 2008-11-13
Linux Kernel HIGH 7.8
CVE-2008-5033

The chip_command function in drivers/media/video/tvaudio.c in the Linux kernel 2.6.25.x before 2.6.25.19, 2.6.26.x before 2.6.26.7, and 2.6.27.x befo…

Patch available
Fix from $1,950 2008-11-10
Hardware Management Console MEDIUM 5.0
CVE-2008-5035

The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers t…

Mitigation only
Fix from $1,600 2008-11-10