Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2014-3938

Published Jul 23, 2014

Integer overflow in Autodesk SketchBook Pro before 6.2.6 allows remote attackers to execute arbitrary code via crafted layer mask data in a PSD file, which triggers a heap-based b…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-4962

Published Jul 15, 2014

Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price o…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4715

Published Jul 3, 2014

Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-depende…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4508

Published Jun 23, 2014

arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4020

Published Jun 18, 2014

The dissect_frame function in epan/dissectors/packet-frame.c in the frame metadissector in Wireshark 1.10.x before 1.10.8 interprets a negative integer as a length value even thou…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4045

Published Jun 17, 2014

The Publish/Subscribe Framework in the PJSIP channel driver in Asterisk Open Source 12.x before 12.3.1, when sub_min_expiry is set to zero, allows remote attackers to cause a deni…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0099

Published May 31, 2014

Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0075

Published May 31, 2014

Integer overflow in the parseChunkHeader function in java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x befor…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5876

Published May 30, 2014

Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to cause a denial of service (crash) via a long string in the (…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3152

Published May 21, 2014

Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-1744

Published May 21, 2014

Integer overflow in the AudioInputRendererHost::OnCreateStream function in content/browser/renderer_host/media/audio_input_renderer_host.cc in Google Chrome before 35.0.1916.114 a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0211

Published May 15, 2014

Multiple integer overflows in the (1) fs_get_reply, (2) fs_alloc_glyphs, and (3) fs_read_extent_info functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 allow re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-0209

Published May 15, 2014

Multiple integer overflows in the (1) FontFileAddEntry and (2) lexAlias functions in X.Org libXfont before 1.4.8 and 1.4.9x before 1.4.99.901 might allow local users to gain privi…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1741

Published May 14, 2014

Multiple integer overflows in the replace-data functionality in the CharacterData interface implementation in core/dom/CharacterData.cpp in Blink, as used in Google Chrome before…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7354

Published May 6, 2014

Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7353

Published May 6, 2014

Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2889

Published Apr 27, 2014

Off-by-one error in the bpf_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 3.1.8, when BPF JIT is enabled, allows local users to cause a denial of…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2894

Published Apr 23, 2014

Off-by-one error in the cmd_smart function in the smart self test in hw/ide/core.c in QEMU before 2.0 allows local users to have unspecified impact via a SMART EXECUTE OFFLINE com…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4651

Published Apr 23, 2014

Cisco IOS before 15.3(2)T, when scansafe is enabled, allows remote attackers to cause a denial of service (latency) via SYN packets that are not accompanied by SYN-ACK packets fro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,247 CVEsPage 11 of 50