Total
1225 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2011-5000 | 1 Openbsd | 1 Openssh | 2012-07-22 | 3.5 LOW | N/A |
The ssh_gssapi_parse_ename function in gss-serv.c in OpenSSH 5.8 and earlier, when gssapi-with-mic authentication is enabled, allows remote authenticated users to cause a denial of service (memory consumption) via a large value in a certain length field. NOTE: there may be limited scenarios in which this issue is relevant. | |||||
CVE-2012-1163 | 1 Nih | 1 Libzip | 2012-07-16 | 6.8 MEDIUM | N/A |
Integer overflow in the _zip_readcdir function in zip_open.c in libzip 0.10 allows remote attackers to execute arbitrary code via the size and offset values for the central directory in a zip archive, which triggers "improper restrictions of operations within the bounds of a memory buffer" and an information leak. | |||||
CVE-2012-3368 | 1 Redhat | 1 Dtach | 2012-07-04 | 2.6 LOW | N/A |
Integer signedness error in attach.c in dtach 0.8 allows remote attackers to obtain sensitive information from daemon stack memory in opportunistic circumstances by reading application data after an improper connection-close request, as demonstrated by running an IRC client in dtach. | |||||
CVE-2012-0659 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-30 | 6.8 MEDIUM | N/A |
Integer overflow in QuickTime in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG file. | |||||
CVE-2012-0662 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-30 | 7.5 HIGH | N/A |
Integer overflow in the Security Framework in Apple Mac OS X before 10.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted input. | |||||
CVE-2012-2428 | 1 Xarrow | 1 Xarrow | 2012-05-28 | 10.0 HIGH | N/A |
Integer overflow in the server in xArrow before 3.4.1 allows remote attackers to execute arbitrary code via a crafted packet that triggers an out-of-bounds read operation. | |||||
CVE-2012-2429 | 1 Xarrow | 1 Xarrow | 2012-05-28 | 10.0 HIGH | N/A |
The server in xArrow before 3.4.1 performs an invalid read operation, which allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2011-3459 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-05-18 | 6.8 MEDIUM | N/A |
Off-by-one error in QuickTime in Apple Mac OS X before 10.7.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted rdrf atom in a movie file that triggers a buffer overflow. | |||||
CVE-2011-2662 | 1 Novell | 1 Groupwise | 2012-05-14 | 10.0 HIGH | N/A |
Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message. | |||||
CVE-2012-0685 | 1 Xnview | 1 Xnview | 2012-05-10 | 9.3 HIGH | N/A |
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0684. | |||||
CVE-2012-0684 | 1 Xnview | 1 Xnview | 2012-05-10 | 9.3 HIGH | N/A |
Integer overflow in XnViewer (aka XnView) before 1.98.5 allows remote attackers to execute arbitrary code via a crafted file containing PSD record types, a different vulnerability than CVE-2012-0685. | |||||
CVE-2011-4043 | 1 Arcinfo | 3 Frontvue, Pcvue, Plantvue | 2012-04-03 | 9.3 HIGH | N/A |
Integer overflow in an unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code via a large value for an integer parameter, leading to a buffer overflow. | |||||
CVE-2011-1417 | 1 Apple | 3 Iphone Os, Mac Os X, Mac Os X Server | 2012-03-30 | 6.8 MEDIUM | N/A |
Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in the OfficeArtMetafileHeader, related to OfficeArtBlip, as demonstrated on the iPhone by Charlie Miller and Dion Blazakis during a Pwn2Own competition at CanSecWest 2011. | |||||
CVE-2011-4259 | 1 Realnetworks | 1 Realplayer | 2012-03-08 | 9.3 HIGH | N/A |
Integer underflow in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted width value in an MPG file. | |||||
CVE-2011-0200 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2012-02-04 | 6.8 MEDIUM | N/A |
Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow. | |||||
CVE-2012-0915 | 1 Renren | 1 Renren Talk | 2012-01-25 | 9.3 HIGH | N/A |
Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a heap-based buffer overflow, as demonstrated using a BMP image. | |||||
CVE-2012-0268 | 1 Yahoo | 1 Messenger | 2012-01-23 | 5.1 MEDIUM | N/A |
Integer overflow in the CYImage::LoadJPG method in YImage.dll in Yahoo! Messenger before 11.5.0.155, when photo sharing is enabled, might allow remote attackers to execute arbitrary code via a crafted JPG image that triggers a heap-based buffer overflow. | |||||
CVE-2011-3341 | 1 Openttd | 1 Openttd | 2012-01-19 | 7.5 HIGH | N/A |
Multiple off-by-one errors in order_cmd.cpp in OpenTTD before 1.1.3 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted CMD_INSERT_ORDER command. | |||||
CVE-2010-2643 | 1 Redhat | 1 Evince | 2012-01-19 | 7.6 HIGH | N/A |
Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | |||||
CVE-2011-1710 | 1 Novell | 1 Xtier Framework | 2012-01-02 | 7.5 HIGH | N/A |
Multiple integer overflows in the HTTP server in the Novell XTier framework 3.1.8 allow remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via crafted header length variables. |