Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Clamav MEDIUM 5.0
CVE-2008-1389

libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malforme…

Fix: after 0.93.3
Fix from $1,600 2008-09-04
Secure Acs HIGH 7.5
CVE-2008-2441

Cisco Secure ACS 3.x before 3.3(4) Build 12 patch 7, 4.0.x, 4.1.x before 4.1(4) Build 13 Patch 11, and 4.2.x before 4.2(0) Build 124 Patch 4 does not…

Mitigation only
Fix from $1,950 2008-09-04
Adaptive Security Appliance 5500 HIGH 7.1
CVE-2008-2734

Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 befo…

Mitigation only
Fix from $1,950 2008-09-04
Directory Server HIGH 7.1
CVE-2008-2930EPSS 7%

Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of se…

Patch available
Fix from $1,950 2008-08-29
Directory Server HIGH 7.8
CVE-2008-3283

Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow rem…

Patch available
Fix from $1,950 2008-08-29
Ruby MEDIUM 5.0
CVE-2008-3443EPSS 16%

The regular expression engine (regex.c) in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows r…

No fix yet
Fix from $1,600 2008-08-14
Ipsec Tools HIGH 7.8
CVE-2008-3652

src/racoon/handler.c in racoon in ipsec-tools does not remove an "orphaned ph1" (phase 1) handle when it has been initiated remotely, which allows re…

Mitigation only
Fix from $1,950 2008-08-13
Ruby HIGH 7.8
CVE-2008-3656EPSS 70%

Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.…

Fix: after 1.8.5
Fix from $1,950 2008-08-13
Office Powerpoint Viewer HIGH 9.3
CVE-2008-0120EPSS 32%

Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture…

Patch available
Fix from $1,950 2008-08-13
Office Powerpoint Viewer HIGH 9.3
CVE-2008-0121EPSS 31%

A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an inva…

Mitigation only
Fix from $1,950 2008-08-13
Compatibility Pack Word Excel Powerpoint MEDIUM 6.8
CVE-2008-1455EPSS 26%

A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, E…

Mitigation only
Fix from $1,600 2008-08-13
Office HIGH 9.3
CVE-2008-3006EPSS 36%

Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Offic…

Mitigation only
Fix from $1,950 2008-08-12
Office HIGH 9.3
CVE-2008-3019EPSS 30%

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (E…

Patch available
Fix from $1,950 2008-08-12
Office HIGH 9.3
CVE-2008-3020EPSS 30%

Microsoft Office 2000 SP3 and XP SP3; Office Converter Pack; and Works 8 do not properly parse the length of a BMP file, which allows remote attacker…

Mitigation only
Fix from $1,950 2008-08-12
Office HIGH 9.3
CVE-2008-3021EPSS 36%

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows rem…

Patch available
Fix from $1,950 2008-08-12
Office HIGH 9.3
CVE-2008-3460EPSS 32%

WPGIMP32.FLT in Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 does not properly parse the length of a WordPerfe…

Mitigation only
Fix from $1,950 2008-08-12
F Prot Antivirus MEDIUM 5.0
CVE-2008-3447EPSS 8%

The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, …

No fix yet
Fix from $1,600 2008-08-04
Mailenable MEDIUM 5.0
CVE-2008-3449

MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote attackers to cause a denial of service (crash) via multiple IMAP connection requests t…

Patch available
Fix from $1,600 2008-08-04
Coregraphics HIGH 9.3
CVE-2008-2321EPSS 12%

Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of…

Patch available
Fix from $1,950 2008-08-04
Data Detectors Engine HIGH 7.1
CVE-2008-2323

Unspecified vulnerability in Data Detectors Engine in Apple Mac OS X 10.5.4 allows attackers to cause a denial of service (resource consumption) via …

Patch available
Fix from $1,950 2008-08-04
Quicklook HIGH 9.3
CVE-2008-2325

QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and …

Patch available
Fix from $1,950 2008-08-04
Unreal Tournament 3 MEDIUM 5.0
CVE-2008-3410

Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP p…

Fix: after 1.3
Fix from $1,600 2008-07-31
Retrospect Backup Client MEDIUM 5.0
CVE-2008-3290

retroclient.exe in EMC Dantz Retrospect Backup Client 7.5.116 allows remote attackers to cause a denial of service (daemon crash) via a series of lon…

Patch available
Fix from $1,600 2008-07-24
Winremotepc Full MEDIUM 5.0
CVE-2008-3269EPSS 11%

WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of service (CPU consumption) via …

No fix yet
Fix from $1,600 2008-07-24
Asterisk HIGH 7.8
CVE-2008-3263EPSS 28%

The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before …

No fix yet
Fix from $1,950 2008-07-22
Clamav MEDIUM 5.0
CVE-2008-3215

libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite file that triggers an out-of-b…

No fix yet
Fix from $1,600 2008-07-18
Yacc HIGH 7.8
CVE-2008-3196

skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an o…

Mitigation only
Fix from $1,950 2008-07-16
Javascriptcore MEDIUM 6.8
CVE-2008-1590

JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remo…

Mitigation only
Fix from $1,600 2008-07-14
Safari HIGH 9.3
CVE-2008-2317EPSS 8%

WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2008-07-14
Sip Multimedia Pc Client MEDIUM 5.0
CVE-2008-3157

Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows attackers to cause a denial of…

Mitigation only
Fix from $1,600 2008-07-11