Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2009-2478

Published Jul 16, 2009

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2347

Published Jul 14, 2009

Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0192

Published Jul 14, 2009

Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2369

Published Jul 8, 2009

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2355

Published Jul 7, 2009

The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (application crash) by specifying (1) an empty string or (2) a non-num…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2295

Published Jul 5, 2009

Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height valu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2294

Published Jul 5, 2009

Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1935

Published Jun 18, 2009

Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1391

Published Jun 16, 2009

Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-d…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1904

Published Jun 11, 2009

The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1856

Published Jun 11, 2009

Integer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows attackers to cause a…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-1705

Published Jun 10, 2009

CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote attackers to execute arbitrary…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0791

Published Jun 9, 2009

Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1959

Published Jun 8, 2009

Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1717

Published Jun 5, 2009

Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1932

Published Jun 4, 2009

Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1882

Published Jun 2, 2009

Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possib…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1831

Published May 29, 2009

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3870

Published May 26, 2009

Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC request that triggers a heap-based buffer overflow, related…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 876-900 of 1,247 CVEsPage 36 of 50