Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2008-2719

Published Jun 16, 2008

Off-by-one error in the ppscan function (preproc.c) in Netwide Assembler (NASM) 2.02 allows context-dependent attackers to cause a denial of service (crash) and possibly execute a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2710

Published Jun 16, 2008

Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1377

Published Jun 16, 2008

The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security exten…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1379

Published Jun 16, 2008

Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1806

Published Jun 16, 2008

Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary tab…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1807

Published Jun 16, 2008

FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1808

Published Jun 16, 2008

Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2360

Published Jun 16, 2008

Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspec…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2361

Published Jun 16, 2008

Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of servic…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2362

Published Jun 16, 2008

Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLine…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2696

Published Jun 13, 2008

Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2654

Published Jun 13, 2008

Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a long request to a Motion HTTP…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2152

Published Jun 10, 2008

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2358

Published Jun 10, 2008

Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2388

Published Jun 6, 2008

Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors. NOTE: the vendor states that these "can be considered no security prob…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2559

Published Jun 5, 2008

Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050, which triggers a stack-based…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1034

Published Jun 2, 2008

Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted hel…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0891

Published May 29, 2008

Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malform…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1948

Published May 21, 2008

The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1950

Published May 21, 2008

Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,026-1,050 of 1,247 CVEsPage 42 of 50