Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Imap Toolkit MEDIUM 5.0
CVE-2008-5006

smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer d…

Mitigation only
Fix from $1,600 2008-11-10
Acrobat HIGH 9.3
CVE-2008-4813EPSS 9%

Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbitrary code via a crafted PDF document that (1) pe…

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Ffmpeg HIGH 10.0
CVE-2008-4869

FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers to cause a denial of service (memory consumption) via unknown vectors, aka a "Tc…

Fix: after 0.4.9
Fix from $1,950 2008-11-01
Debug Diagnostic Tool MEDIUM 5.0
CVE-2008-4800EPSS 26%

The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of serv…

No fix yet
Fix from $1,600 2008-10-31
Adaptive Security Appliance 5500 Series HIGH 7.8
CVE-2008-3817

Memory leak in Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 8.0 before 8.0(4) and 8.1 before 8.1(2) allows remote…

Patch available
Fix from $1,950 2008-10-23
Wireshark MEDIUM 5.0
CVE-2008-4683

The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a …

Patch available
Fix from $1,600 2008-10-22
Wireshark MEDIUM 5.0
CVE-2008-4685

Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3 allows r…

Patch available
Fix from $1,600 2008-10-22
Websphere Application Server HIGH 7.8
CVE-2008-4678

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attacker…

Mitigation only
Fix from $1,950 2008-10-22
Mplayer MEDIUM 5.0
CVE-2008-4610EPSS 9%

MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2)…

Fix: after 1.0_rc1
Fix from $1,600 2008-10-20
Vlc Media Player MEDIUM 6.8
CVE-2008-4558EPSS 8%

Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist fil…

No fix yet
Fix from $1,600 2008-10-15
Strongswan MEDIUM 5.0
CVE-2008-4551

strongSwan 4.2.6 and earlier allows remote attackers to cause a denial of service (daemon crash) via an IKE_SA_INIT message with a large number of NU…

Fix: after 4.2.6
Fix from $1,600 2008-10-14
Unity HIGH 7.1
CVE-2008-4543

Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentica…

Fix: after 7.0
Fix from $1,950 2008-10-13
Cups HIGH 10.0
CVE-2008-3641EPSS 24%

The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and …

Fix: after 1.3.8
Fix from $1,950 2008-10-10
Libxml2 MEDIUM 5.0
CVE-2008-4409EPSS 9%

libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a d…

No fix yet
Fix from $1,600 2008-10-03
Officescan MEDIUM 5.0
CVE-2008-4403

The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to cau…

Mitigation only
Fix from $1,600 2008-10-03
Konqueror MEDIUM 5.0
CVE-2008-4382

Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a U…

Mitigation only
Fix from $1,600 2008-10-02
Firefox MEDIUM 5.0
CVE-2008-4324EPSS 9%

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer der…

No fix yet
Fix from $1,600 2008-09-29
Lighttpd MEDIUM 5.0
CVE-2008-4298

Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory co…

Fix: after 1.4.19
Fix from $1,600 2008-09-27
Denora Irc Stats MEDIUM 5.0
CVE-2008-4246

Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service (application crash) via a cr…

Patch available
Fix from $1,600 2008-09-25
Firefox HIGH 10.0
CVE-2008-4062

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.1…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 10.0
CVE-2008-4064

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and a…

Fix: after 3.0.1
Fix from $1,950 2008-09-24
Pdnsd MEDIUM 5.0
CVE-2008-4194EPSS 7%

The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long…

Fix: after 1.2.6-par
Fix from $1,600 2008-09-24
Symbian Os HIGH 7.8
CVE-2008-4135

Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause a denial of service (device …

No fix yet
Fix from $1,950 2008-09-19
Mac Os X HIGH 9.3
CVE-2008-2332

ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and appl…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 9.3
CVE-2008-3608

ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and appl…

Patch available
Fix from $1,950 2008-09-16
Mac Os X MEDIUM 6.1
CVE-2008-3613

Finder in Apple Mac OS X 10.5.2 through 10.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) …

Patch available
Fix from $1,600 2008-09-16
Mac Os X HIGH 9.3
CVE-2008-3621EPSS 6%

VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and applica…

Patch available
Fix from $1,950 2008-09-16
Debian Linux MEDIUM 5.0
CVE-2008-3912

libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to…

Fix: 0.94+
Fix from $1,600 2008-09-11
Iphone HIGH 9.3
CVE-2008-3632EPSS 6%

Use-after-free vulnerability in WebKit in Apple iPod touch 1.1 through 2.0.2, and iPhone 1.0 through 2.0.2, allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2008-09-11
Digital Image Suite HIGH 9.3
CVE-2008-3013EPSS 52%

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP…

Mitigation only
Fix from $1,950 2008-09-11