Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2008-5247

Published Nov 26, 2008

The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, uses an untrusted height (aka codec_data_length) value as a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5241

Published Nov 26, 2008

Integer underflow in demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allows remote attackers to cause a denial of service (crash) via a crafted media file th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5238

Published Nov 26, 2008

Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, allows remote attackers to cause a denial of service (crash)…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5237

Published Nov 26, 2008

Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4225

Published Nov 25, 2008

Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-5159

Published Nov 18, 2008

Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5031

Published Nov 10, 2008

Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4799

Published Oct 31, 2008

pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4686

Published Oct 22, 2008

Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably 0.9.4, might allow remote attackers to execute arbitrary co…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4478

Published Oct 14, 2008

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Co…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3640

Published Oct 14, 2008

Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3520

Published Oct 2, 2008

Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4327

Published Sep 30, 2008

gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attackers to cause a denial of service (divide-by-zero error and a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3827

Published Sep 29, 2008

Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to cause a denial of service (process termination) and possibl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4166

Published Sep 22, 2008

Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL e…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4107

Published Sep 18, 2008

The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows attackers to leverage exposures in products that rely on t…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4102

Published Sep 18, 2008

Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP's mt_rand function, as demo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3616

Published Sep 16, 2008

Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 976-1,000 of 1,247 CVEsPage 40 of 50