Skip to main content

CWE archive

CWE-125 CVEs

Programmatic archive

9,324 CVEs tagged with CWE-125694 Critical, 3,869 High, 4,244 Medium, 513 Low, 4 Unrated.

CVE-2011-2844

Published Sep 19, 2011

Google Chrome before 14.0.835.163 does not properly process MP3 files, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2843

Published Sep 19, 2011

Google Chrome before 14.0.835.163 does not properly handle media buffers, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2803

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not properly handle Skia paths, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2794

Published Aug 3, 2011

Google Chrome before 13.0.782.107 does not properly perform text iteration, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2345

Published Jun 29, 2011

The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings, which allows remote attackers to cause a denial of service (out-of-bounds read) via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1455

Published May 3, 2011

Google Chrome before 11.0.696.57 does not properly handle PDF documents with multipart encoding, which allows remote attackers to cause a denial of service (out-of-bounds read) vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1445

Published May 3, 2011

Google Chrome before 11.0.696.57 does not properly handle SVG documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1192

Published Mar 11, 2011

Google Chrome before 10.0.648.127 on Linux does not properly handle Unicode ranges, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1122

Published Mar 1, 2011

The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71960.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1120

Published Mar 1, 2011

The WebGL implementation in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, aka Issue 71717.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1113

Published Mar 1, 2011

Google Chrome before 9.0.597.107 on 64-bit Linux platforms does not properly perform pickle deserialization, which allows remote attackers to cause a denial of service (out-of-bou…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0984

Published Feb 10, 2011

Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2523

Published Nov 11, 2009

The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null termi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-6016

Published Nov 21, 2006

wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5393

Published Oct 18, 2006

Cisco Secure Desktop (CSD) does not require that the ClearPageFileAtShutdown (aka CCE-Winv2.0-407) registry value equals 1, which might allow local users to read certain memory pa…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1940

Published Dec 31, 2004

sipclient.cpp in KPhone 4.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a STUN response packet with a large attrLen value that causes an out-of-…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0183

Published May 4, 2004

TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0184

Published May 4, 2004

Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification pay…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0221

Published May 4, 2004

isakmpd in OpenBSD 3.4 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with a delete payload containing a large number of SPIs, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,301-9,324 of 9,324 CVEsPage 373 of 373