Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Gd Graphics Library MEDIUM 5.0
CVE-2007-3477

The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU cons…

Fix: after 2.0.35
Fix from $1,600 2007-06-28
Safari HIGH 7.8
CVE-2007-3185

Apple Safari Beta 3.0.1 for Windows public beta allows remote attackers to cause a denial of service (crash) via unspecified DHTML manipulations that…

Mitigation only
Fix from $1,950 2007-06-12
Maradns MEDIUM 5.0
CVE-2007-3114

Memory leak in server/MaraDNS.c in MaraDNS before 1.2.12.05, and 1.3.x before 1.3.03, allows remote attackers to cause a denial of service (memory co…

Patch available
Fix from $1,600 2007-06-07
Maradns HIGH 7.8
CVE-2007-3115

Multiple memory leaks in server/MaraDNS.c in MaraDNS before 1.2.12.06, and 1.3.x before 1.3.05, allow remote attackers to cause a denial of service (…

Patch available
Fix from $1,950 2007-06-07
Maradns MEDIUM 5.0
CVE-2007-3116

Memory leak in server/MaraDNS.c in MaraDNS 1.2.12.06 and 1.3.05 allows remote attackers to cause a denial of service (memory consumption) via unspeci…

Patch available
Fix from $1,600 2007-06-07
Veritas Volume Replicator MEDIUM 5.0
CVE-2007-1593

The administrative service in Symantec Veritas Volume Replicator (VVR) for Windows 3.1 through 4.3, and VVR for Unix 3.5 through 5.0, in Symantec Sto…

Patch available
Fix from $1,600 2007-06-04
Visual Basic HIGH 9.3
CVE-2007-2884EPSS 36%

Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption)…

No fix yet
Fix from $1,950 2007-05-30
Amavis HIGH 7.8
CVE-2007-1673

unzoo.c, as used in multiple products including AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a …

Fix: after 7.3.0.5
Fix from $1,950 2007-05-09
Office HIGH 9.3
CVE-2007-1747EPSS 32%

Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers t…

Mitigation only
Fix from $1,950 2007-05-08
Pi3web Web Server MEDIUM 5.0
CVE-2007-2415

Pi3Web Web Server 2.0.3 PL1 allows remote attackers to cause a denial of service (application exit) via a long URI. NOTE: this issue was originally …

Patch available
Fix from $1,600 2007-05-01
Clamav HIGH 7.8
CVE-2007-2029

File descriptor leak in the PDF handler in Clam AntiVirus (ClamAV) allows remote attackers to cause a denial of service via a crafted PDF file.

Patch available
Fix from $1,950 2007-04-30
Tippingpoint Ips HIGH 7.8
CVE-2007-2276

3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially incr…

Mitigation only
Fix from $1,950 2007-04-25
Sendmail HIGH 7.8
CVE-2007-2246

Unspecified vulnerability in HP-UX B.11.00 and B.11.11, when running sendmail 8.9.3 or 8.11.1; and HP-UX B.11.23 when running sendmail 8.11.1; allows…

Patch available
Fix from $1,950 2007-04-25
Application Server HIGH 7.8
CVE-2007-2120

The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Lis…

Mitigation only
Fix from $1,950 2007-04-18
Wireless Lan Controller Software MEDIUM 6.1
CVE-2007-2039

The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.171.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attack…

Fix: 3.2.171.5 / 4.0.206.0+
Fix from $1,600 2007-04-16
Windows 2000 HIGH 7.1
CVE-2007-1211EPSS 29%

Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-assisted remote attackers to c…

Mitigation only
Fix from $1,950 2007-04-04
Ftp Explorer HIGH 7.1
CVE-2007-1082

FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long res…

Patch available
Fix from $1,950 2007-02-22
Linux Kernel HIGH 7.8
CVE-2007-0772

The Linux kernel 2.6.13 and other versions before 2.6.20.1 allows remote attackers to cause a denial of service (oops) via a crafted NFSACL 2 ACCESS …

Fix: after 2.6.20
Fix from $1,950 2007-02-20
Visual C\+\+ MEDIUM 5.0
CVE-2007-0842EPSS 6%

The 64-bit versions of Microsoft Visual C++ 8.0 standard library (MSVCR80.DLL) time functions, including (1) localtime, (2) localtime_s, (3) gmtime, …

Patch available
Fix from $1,600 2007-02-13
Safari HIGH 7.5
CVE-2007-0342

WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element wi…

No fix yet
Fix from $1,950 2007-01-18
FreeBSD MEDIUM 6.6
CVE-2007-0267

The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly co…

Mitigation only
Fix from $1,600 2007-01-17
Squid MEDIUM 5.0
CVE-2007-0247EPSS 20%

squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing resp…

Mitigation only
Fix from $1,600 2007-01-16
Mac Os X MEDIUM 6.8
CVE-2007-0197EPSS 8%

Finder 10.4.6 on Apple Mac OS X 10.4.8 allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a l…

No fix yet
Fix from $1,600 2007-01-11
Acrobat HIGH 9.3
CVE-2006-5857EPSS 9%

Adobe Reader and Acrobat 7.0.8 and earlier allows user-assisted remote attackers to execute code via a crafted PDF file that triggers memory corrupti…

Fix: after 7.0.8
Fix from $1,950 2006-12-31
Chetcpasswd HIGH 7.5
CVE-2006-6681

Pedro Lineu Orso chetcpasswd 2.3.3 does not have a rate limit for client requests, which might allow remote attackers to determine passwords via a di…

Patch available
Fix from $1,950 2006-12-21
Linux Kernel HIGH 7.5
CVE-2006-6304

The do_coredump function in fs/exec.c in the Linux kernel 2.6.19 sets the flag variable to O_EXCL but does not use it, which allows context-dependent…

Patch available
Fix from $1,950 2006-12-14
Ruby MEDIUM 5.0
CVE-2006-6303

The read_multipart function in cgi.rb in Ruby before 1.8.5-p2 does not properly detect boundaries in MIME multipart content, which allows remote atta…

Patch available
Fix from $1,600 2006-12-06
Kdegraphics MEDIUM 5.0
CVE-2006-6297

Stack consumption vulnerability in the KFILE JPEG (kfile_jpeg) plugin in kdegraphics 3, as used by konqueror, digikam, and other KDE image browsers, …

Mitigation only
Fix from $1,600 2006-12-05
Activescan MEDIUM 6.4
CVE-2006-5966

Panda ActiveScan 5.53.00, and other versions before 5.54.01, allows remote attackers to (1) reboot the system using the Reinicializar method in the A…

Patch available
Fix from $1,600 2006-11-17
Vilistextum MEDIUM 5.0
CVE-2006-5656

Memory leak in the push_align function in src/util.c in Vilistextum before 2.6.9 allows remote attackers to cause a denial of service (memory consump…

Patch available
Fix from $1,600 2006-11-03