Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2008-3636

Published Sep 11, 2008

Integer overflow in the IopfCompleteRequest API in the kernel in Microsoft Windows 2000, XP, Server 2003, and Vista allows context-dependent attackers to gain privileges. NOTE: th…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3015

Published Sep 11, 2008

Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Wor…

CVSS 9.3 · Critical

CVE-2008-2464

Published Sep 11, 2008

The mld_input function in sys/netinet6/mld6.c in the kernel in NetBSD 4.0, FreeBSD, and KAME, when INET6 is enabled, allows remote attackers to cause a denial of service (divide-b…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3910

Published Sep 4, 2008

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3526

Published Aug 27, 2008

Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 thr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3794

Published Aug 26, 2008

Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafte…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3732

Published Aug 20, 2008

Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execut…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3276

Published Aug 18, 2008

Integer overflow in the dccp_setsockopt_change function in net/dccp/proto.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.17-rc1 through 2.6…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3573

Published Aug 10, 2008

The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) within the URL in the SRC attri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2316

Published Aug 1, 2008

Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to "partial h…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3373

Published Jul 30, 2008

The files parsing engine in Grisoft AVG Anti-Virus before 8.0.156 allows remote attackers to cause a denial of service (engine crash) via a crafted UPX compressed file, which trig…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3217

Published Jul 18, 2008

PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3159

Published Jul 14, 2008

Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3135

Published Jul 10, 2008

Soldner Secret Wars 33724 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a packet with a large numeric value in a 0x80 data block.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2376

Published Jul 9, 2008

Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unsp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3072

Published Jul 8, 2008

Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown imp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2927

Published Jul 7, 2008

Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,001-1,025 of 1,247 CVEsPage 41 of 50