Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2010-0442

Published Feb 2, 2010

The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0010

Published Feb 2, 2010

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to ca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0001

Published Jan 29, 2010

Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of s…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4003

Published Jan 21, 2010

Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, lead…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4012

Published Jan 19, 2010

Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, re…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0316

Published Jan 15, 2010

Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a crafted SK…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4212

Published Jan 13, 2010

Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow r…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4536

Published Jan 12, 2010

drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4418

Published Dec 24, 2009

The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4413

Published Dec 24, 2009

The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a requ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4356

Published Dec 18, 2009

Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (1) JPEG or (2) PNG data in an…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-2281

Published Dec 18, 2009

Integer overflow in the _ncp32._NtrpTCPReceiveMsg function in rds.exe in the Cell Manager Database Service in the Application Recovery Manager component in HP OpenView Storage Dat…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3997

Published Dec 18, 2009

Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary code via an Oktalyzer file that triggers a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3389

Published Dec 17, 2009

Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4307

Published Dec 13, 2009

The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3799

Published Dec 10, 2009

Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3586

Published Dec 8, 2009

Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1566

Published Dec 3, 2009

Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimension…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0895

Published Dec 3, 2009

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containin…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3930

Published Nov 10, 2009

Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed compound document (aka cdf) file…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2838

Published Nov 10, 2009

Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft O…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 801-825 of 1,247 CVEsPage 33 of 50