Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2009-1376

Published May 26, 2009

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1755

Published May 22, 2009

Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0155

Published May 13, 2009

Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to exec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0010

Published May 13, 2009

Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cau…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0221

Published May 12, 2009

Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1194

Published May 11, 2009

Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-dependent attackers to cause a denial of service (applicati…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1442

Published May 7, 2009

Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might allow remote attackers to execute arbitrary code in the ren…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-2438

Published Apr 28, 2009

Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1438

Published Apr 27, 2009

Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-depe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-1188

Published Apr 23, 2009

Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1187

Published Apr 23, 2009

Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vector…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0163

Published Apr 23, 2009

Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary c…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1331

Published Apr 17, 2009

Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demons…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1301

Published Apr 16, 2009

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5259

Published Apr 16, 2009

Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream F…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0794

Published Apr 13, 2009

Integer overflow in the PulseAudioTargetDataL class in src/java/org/classpath/icedtea/pulseaudio/PulseAudioTargetDataLine.java in Pulse-Java, as used in OpenJDK 1.6.0.0 and other…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0197

Published Apr 9, 2009

Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0847

Published Apr 9, 2009

The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash)…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 901-925 of 1,247 CVEsPage 37 of 50