Skip to main content

CWE archive

CWE-119 CVEs

Programmatic archive

14,095 CVEs tagged with CWE-1194,379 Critical, 6,230 High, 3,091 Medium, 395 Low, 0 Unrated.

CVE-2007-1413

Published Mar 12, 2007

Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably other PHP 4 versions, allows context-dependent attackers t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1381

Published Mar 10, 2007

The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and fixed on 20070304, calls strlcpy where strlcat was intende…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7157

Published Mar 7, 2007

Buffer overflow in Google Earth v4.0.2091 (beta) allows remote user-assisted attackers to cause a denial of service (crash) via a KML or KMZ file with a long href element.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0718

Published Mar 5, 2007

Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a QTI…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1256

Published Mar 3, 2007

Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly se…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1245

Published Mar 3, 2007

IrfanView 3.99 allows remote attackers to cause a denial of service (application crash) via a malformed WMF file.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1246

Published Mar 3, 2007

The DMO_VideoDecoder_Open function in loader/dmo/DMO_VideoDecoder.c in MPlayer 1.0rc1 and earlier, as used in xine-lib, does not set the biSize before use in a memcpy, which allow…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1217

Published Mar 2, 2007

Buffer overflow in the bufprint function in capiutil.c in libcapi, as used in Linux kernel 2.6.9 to 2.6.20 and isdn4k-utils, allows local users to cause a denial of service (crash…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1218

Published Mar 2, 2007

Off-by-one buffer overflow in the parse_elements function in the 802.11 printer code (print-802_11.c) for tcpdump 3.9.5 and earlier allows remote attackers to cause a denial of se…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1087

Published Feb 23, 2007

IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 does not properly terminate certain input strings, which allows local users to execute arbitrary code via unspecified en…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1088

Published Feb 23, 2007

Stack-based buffer overflow in IBM DB2 8.x before 8.1 FixPak 15 and 9.1 before Fix Pack 2 allows local users to execute arbitrary code via a long string in unspecified environment…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-0320

Published Feb 23, 2007

Multiple buffer overflows in (a) an ActiveX control (iftw.dll) and (b) Netscape plug-in (npiftw32.dll) for Macrovision (formerly InstallShield) InstallFromTheWeb allow remote atta…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1083

Published Feb 23, 2007

Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1037

Published Feb 21, 2007

Stack-based buffer overflow in News File Grabber 4.1.0.1 and earlier allows remote attackers to execute arbitrary code via a .nzb file with a long subject field. NOTE: the proven…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-1041

Published Feb 21, 2007

Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute arbitrary code via a .nzb file with a long (1) group or (2) s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0988

Published Feb 20, 2007

The zend_hash_init function in PHP 5 before 5.2.1 and PHP 4 before 4.4.5, when running on a 64-bit platform, allows context-dependent attackers to cause a denial of service (infin…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-0906

Published Feb 13, 2007

Multiple buffer overflows in PHP before 5.2.1 allow attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors in the (1) session, (2) zip,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-3448

Published Feb 13, 2007

Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 13,701-13,725 of 14,095 CVEsPage 549 of 564