Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2014-0150

Published Apr 18, 2014

Integer overflow in the virtio_net_handle_mac function in hw/net/virtio-net.c in QEMU 2.0 and earlier allows local guest users to execute arbitrary code via a MAC addresses table…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4289

Published Apr 18, 2014

Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-0172

Published Apr 11, 2014

Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1721

Published Apr 9, 2014

Google V8, as used in Google Chrome before 34.0.1847.116, does not properly implement lazy deoptimization, which allows remote attackers to cause a denial of service (memory corru…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1718

Published Apr 9, 2014

Integer overflow in the SoftwareFrameManager::SwapToNewFrame function in content/browser/renderer_host/software_frame_manager.cc in the software compositor in Google Chrome before…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1717

Published Apr 9, 2014

Google V8, as used in Google Chrome before 34.0.1847.116, does not properly use numeric casts during handling of typed arrays, which allows remote attackers to cause a denial of s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1895

Published Apr 1, 2014

Off-by-one error in the flask_security_avc_cachestats function in xsm/flask/flask_op.c in Xen 4.2.x and 4.3.x, when the maximum number of physical CPUs are in use, allows local us…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1894

Published Apr 1, 2014

Multiple integer overflows in unspecified suboperations in the flask hypercall in Xen 3.2.x and earlier, when XSM is enabled, allow local users to cause a denial of service (proce…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1893

Published Apr 1, 2014

Multiple integer overflows in the (1) FLASK_GETBOOL and (2) FLASK_SETBOOL suboperations in the flask hypercall in Xen 4.1.x, 3.3.x, 3.2.x, and earlier, when XSM is enabled, allow…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1891

Published Apr 1, 2014

Multiple integer overflows in the (1) FLASK_GETBOOL, (2) FLASK_SETBOOL, (3) FLASK_USER, and (4) FLASK_CONTEXT_TO_SID suboperations in the flask hypercall in Xen 4.3.x, 4.2.x, 4.1.…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2669

Published Mar 31, 2014

Multiple integer overflows in contrib/hstore/hstore_io.c in PostgreSQL 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0064

Published Mar 31, 2014

Multiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x befo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2386

Published Mar 25, 2014

Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) display_nav_table…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3938

Published Mar 18, 2014

Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which trigg…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-1684

Published Mar 3, 2014

The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Player before 2.1.3 allows remote attackers to cause a denial of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2099

Published Mar 2, 2014

The msrle_decode_frame function in libavcodec/msrle.c in FFmpeg before 2.1.4 does not properly calculate line sizes, which allows remote attackers to cause a denial of service (ou…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0333

Published Feb 27, 2014

The png_push_read_chunk function in pngpread.c in the progressive decoder in libpng 1.6.x through 1.6.9 allows remote attackers to cause a denial of service (infinite loop and CPU…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1261

Published Feb 27, 2014

Integer signedness error in CoreText in Apple OS X before 10.9.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted U…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1245

Published Feb 27, 2014

Integer signedness error in Apple QuickTime before 7.7.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted stsz atom…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-2020

Published Feb 18, 2014

ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check data types, which might allow remote attackers to obtain sensitive information by using a (1) string or (2) array data type in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7328

Published Feb 18, 2014

Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service (application crash) or…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7226

Published Feb 18, 2014

Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a denial of service (application crash) or possibly have uns…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4736

Published Feb 10, 2014

Multiple integer overflows in the JPEG engine drivers in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 276-300 of 1,247 CVEsPage 12 of 50