Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2008-6680

Published Apr 8, 2009

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6672

Published Apr 8, 2009

Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service ("runtime error") via a crafted join packet to UDP port 27960, probably related to an invali…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6671

Published Apr 8, 2009

Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted join packet to UDP port 27960.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6670

Published Apr 8, 2009

Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1265

Published Apr 8, 2009

Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive informati…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0789

Published Mar 27, 2009

OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invali…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1095

Published Mar 25, 2009

Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0787

Published Mar 25, 2009

The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an e…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0584

Published Mar 23, 2009

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier,…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0587

Published Mar 14, 2009

Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0585

Published Mar 14, 2009

Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4316

Published Mar 14, 2009

Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0887

Published Mar 12, 2009

Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might a…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0537

Published Mar 9, 2009

Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to ca…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0186

Published Mar 5, 2009

Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6393

Published Mar 3, 2009

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0698

Published Feb 23, 2009

Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0577

Published Feb 20, 2009

Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostSc…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0608

Published Feb 17, 2009

Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspec…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0607

Published Feb 17, 2009

Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_callo…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0139

Published Feb 13, 2009

Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0475

Published Feb 11, 2009

Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0480

Published Feb 9, 2009

The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cau…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 926-950 of 1,247 CVEsPage 38 of 50