Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Openview Network Node Manager HIGH 7.8
CVE-2008-0212

ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted …

Patch available
Fix from $1,950 2008-02-06
Linux Kernel HIGH 7.8
CVE-2007-6694

The chrp_show_cpuinfo function (chrp/setup.c) in Linux kernel 2.4.21 through 2.6.18-53, when running on PowerPC, might allow local users to cause a d…

Mitigation only
Fix from $1,950 2008-01-29
International Components For Unicode MEDIUM 6.8
CVE-2007-4770

libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka …

Fix: after 3.8.1
Fix from $1,600 2008-01-29
International Components For Unicode HIGH 9.3
CVE-2007-4771

Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allow…

Fix: after 3.8.1
Fix from $1,950 2008-01-29
Enterprise Message Service HIGH 10.0
CVE-2007-5656EPSS 5%

TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers…

Fix: after 6.8.0
Fix from $1,950 2008-01-16
Safari MEDIUM 6.8
CVE-2008-0035EPSS 5%

Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, a…

Mitigation only
Fix from $1,600 2008-01-16
Mambo Open Source MEDIUM 5.0
CVE-2008-0261

Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flo…

Patch available
Fix from $1,600 2008-01-15
Firewall MEDIUM 5.0
CVE-2008-0263

The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only strea…

Fix: after 4.6
Fix from $1,600 2008-01-15
Debian Linux MEDIUM 5.0
CVE-2007-6284

The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containi…

Patch available
Fix from $1,600 2008-01-12
HTTP Server HIGH 7.8
CVE-2007-6423

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to tr…

Mitigation only
Fix from $1,950 2008-01-12
Pragma Telnetserver MEDIUM 5.0
CVE-2008-0153EPSS 13%

telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a craft…

Mitigation only
Fix from $1,600 2008-01-09
Asterisk Appliance Developer Kit MEDIUM 5.0
CVE-2008-0095EPSS 25%

The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Develope…

Fix: after 1.4.16
Fix from $1,600 2008-01-08
Opera Browser HIGH 7.8
CVE-2007-6523

Algorithmic complexity vulnerability in Opera 9.50 beta and 9.x before 9.25 allows remote attackers to cause a denial of service (CPU consumption) vi…

No fix yet
Fix from $1,950 2007-12-24
P4web HIGH 7.8
CVE-2007-6349

P4Webs.exe in Perforce P4Web 2006.2 and earlier, when running on Windows, allows remote attackers to cause a denial of service (CPU consumption) via …

Patch available
Fix from $1,950 2007-12-20
Wireshark MEDIUM 6.1
CVE-2007-6439

Wireshark (formerly Ethereal) 0.99.6 allows remote attackers to cause a denial of service (infinite or large loop) via the (1) IPv6 or (2) USB dissec…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X HIGH 9.3
CVE-2007-4710

Unspecified vulnerability in ColorSync in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or ex…

Mitigation only
Fix from $1,950 2007-12-19
Safari HIGH 9.3
CVE-2007-5859EPSS 6%

Unspecified vulnerability in Safari RSS in Apple Mac OS X 10.4.11 allows remote attackers to cause a denial of service (application termination) or e…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X MEDIUM 6.8
CVE-2007-5861

Unspecified vulnerability in Spotlight in Apple Mac OS X 10.4.11 allows user-assisted attackers to cause a denial of service (application termination…

Mitigation only
Fix from $1,600 2007-12-19
Exiftags MEDIUM 5.0
CVE-2007-6356

exiftags before 1.01 allows attackers to cause a denial of service (infinite loop) via recursive IFD references in the EXIF data in a JPEG image.

Fix: after 1.01
Fix from $1,600 2007-12-18
Linux Kernel HIGH 7.2
CVE-2007-6417

The shmem_getpage function (mm/shmem.c) in Linux kernel 2.6.11 through 2.6.23 does not properly clear allocated memory in some rare circumstances rel…

Mitigation only
Fix from $1,950 2007-12-18
Ie HIGH 9.3
CVE-2007-3902EPSS 36%

Use-after-free vulnerability in the CRecalcProperty function in mshtml.dll in Microsoft Internet Explorer 5.01 through 7 allows remote attackers to e…

Mitigation only
Fix from $1,950 2007-12-12
Ie MEDIUM 6.8
CVE-2007-3903EPSS 31%

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to …

Mitigation only
Fix from $1,600 2007-12-12
Ie MEDIUM 6.8
CVE-2007-5347EPSS 28%

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTM…

Mitigation only
Fix from $1,600 2007-12-12
Libflac HIGH 9.3
CVE-2007-6279

Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitra…

Fix: after 1.2
Fix from $1,950 2007-12-07
Kerberos 5 MEDIUM 6.9
CVE-2007-5901

Use-after-free vulnerability in the gss_indicate_mechs function in lib/gssapi/mechglue/g_initialize.c in MIT Kerberos 5 (krb5) has unknown impact and…

Fix: after 1.6.3_kdc
Fix from $1,600 2007-12-06
Kerberos 5 MEDIUM 6.9
CVE-2007-5971

Double free vulnerability in the gss_krb5int_make_seal_token_v3 function in lib/gssapi/krb5/k5sealv3.c in MIT Kerberos 5 (krb5) has unknown impact an…

Fix: after 1.6.3_kdc
Fix from $1,600 2007-12-06
Backupexec System Recovery MEDIUM 5.0
CVE-2007-4346

The Job Engine (bengine.exe) service in Symantec Backup Exec for Windows Servers (BEWS) 11d build 11.0.7170 and 11.0.6.6235 allows remote attackers t…

Patch available
Fix from $1,600 2007-11-29
Director HIGH 7.8
CVE-2007-5612

CIM Server in IBM Director 5.20.1 and earlier allows remote attackers to cause a denial of service (CPU consumption, connection slot exhaustion, and …

Fix: after 5.20.1
Fix from $1,950 2007-11-21
Websphere Mq HIGH 10.0
CVE-2007-6044

Multiple unspecified vulnerabilities in IBM WebSphere MQ 6.0 have unknown impact and remote attack vectors involving "memory corruption." NOTE: as of…

No fix yet
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 9.3
CVE-2007-6053

IBM DB2 UDB 9.1 before Fixpak 4 does not properly handle use of large numbers of file descriptors, which might allow attackers to have an unknown imp…

Fix: after 9.1
Fix from $1,950 2007-11-20