Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2009-3201

Published Sep 15, 2009

Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed heade…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2805

Published Sep 14, 2009

Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a craf…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0200

Published Sep 2, 2009

Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the docum…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-7126

Published Aug 31, 2009

Integer overflow in osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1884

Published Aug 19, 2009

Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (appl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7013

Published Aug 19, 2009

NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6995

Published Aug 19, 2009

Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid ha…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2415

Published Aug 10, 2009

Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer ov…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2411

Published Aug 7, 2009

Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execut…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2412

Published Aug 6, 2009

Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a de…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-2688

Published Aug 5, 2009

Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2660

Published Aug 4, 2009

Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a h…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1869

Published Jul 31, 2009

Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1720

Published Jul 31, 2009

Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via uns…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2584

Published Jul 23, 2009

Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might a…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2468

Published Jul 22, 2009

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial o…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2463

Published Jul 22, 2009

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2547

Published Jul 20, 2009

Integer underflow in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) v…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2539

Published Jul 20, 2009

The Aigo P8860 allows remote attackers to cause a denial of service (memory consumption and browser hang) via a large integer value for the length property of a Select object, a r…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2483

Published Jul 16, 2009

libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized p…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 851-875 of 1,247 CVEsPage 35 of 50