Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2009-0388

Published Feb 4, 2009

Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application cr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0282

Published Jan 27, 2009

Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attac…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0006

Published Jan 21, 2009

Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cin…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0136

Published Jan 16, 2009

Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of ser…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0132

Published Jan 15, 2009

Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5903

Published Jan 15, 2009

Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0070

Published Jan 8, 2009

Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably ha…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5823

Published Jan 2, 2009

An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of serv…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5745

Published Dec 29, 2008

Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a deni…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5744

Published Dec 26, 2008

Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by wri…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5714

Published Dec 24, 2008

Off-by-one error in monitor.c in Qemu 0.9.1 might make it easier for remote attackers to guess the VNC password, which is limited to seven characters where eight was intended.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5701

Published Dec 22, 2008

Array index error in arch/mips/kernel/scall64-o32.S in the Linux kernel before 2.6.28-rc8 on 64-bit MIPS platforms allows local users to cause a denial of service (system crash) v…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4220

Published Dec 17, 2008

Integer overflow in the inet_net_pton API in Libsystem in Apple Mac OS X before 10.5.6 allows context-dependent attackers to execute arbitrary code or cause a denial of service (a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4218

Published Dec 17, 2008

Multiple integer overflows in the kernel in Apple Mac OS X before 10.5.6 on Intel platforms allow local users to gain privileges via a crafted call to (1) i386_set_ldt or (2) i386…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-4217

Published Dec 17, 2008

Integer signedness error in BOM in Apple Mac OS X before 10.5.6 allows remote attackers to execute arbitrary code via the headers in a crafted CPIO archive, leading to a stack-bas…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5396

Published Dec 9, 2008

Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5357

Published Dec 5, 2008

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK an…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5352

Published Dec 5, 2008

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5276

Published Dec 3, 2008

Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5286

Published Dec 1, 2008

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 951-975 of 1,247 CVEsPage 39 of 50