Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2006-7227

Published Nov 14, 2007

Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7 allows context-dependent attackers to execute arbitrary code via a regular expression containing a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7228

Published Nov 14, 2007

Integer overflow in Perl-Compatible Regular Expression (PCRE) library before 6.7 might allow context-dependent attackers to execute arbitrary code via a regular expression that in…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4766

Published Nov 7, 2007

Multiple integer overflows in Perl-Compatible Regular Expression (PCRE) library before 7.3 allow context-dependent attackers to cause a denial of service (crash) or execute arbitr…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4997

Published Nov 6, 2007

Integer underflow in the ieee80211_rx function in net/ieee80211/ieee80211_rx.c in the Linux kernel 2.6.x before 2.6.23 allows remote attackers to cause a denial of service (crash)…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2007-4622

Published Nov 5, 2007

Integer underflow in the dns_name_fromtext function in (1) libdns_nonsecure.a and (2) libdns_secure.a in IBM AIX 5.2 allows local users to gain privileges via a crafted "-y" (TSIG…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-2957

Published Oct 31, 2007

Integer overflow in McAfee E-Business Server before 8.5.3 for Solaris, and before 8.1.2 for Linux, HP-UX, and AIX, allows remote attackers to execute arbitrary code via a large le…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4351

Published Oct 31, 2007

Off-by-one error in the ippReadIO function in cups/ipp.c in CUPS 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted (1) textWithLanguage or (2) nameW…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5552

Published Oct 18, 2007

Integer overflow in Cisco IOS allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5558

Published Oct 18, 2007

Integer overflow in the LG Mobile handset allows remote attackers to cause a denial of service (reboot) via a crafted HTTP packet. NOTE: as of 20071016, the only disclosure is a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5467

Published Oct 15, 2007

Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s"…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4995

Published Oct 13, 2007

Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-4619

Published Oct 12, 2007

Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5416

Published Oct 12, 2007

Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter's hash value, which allow…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5369

Published Oct 11, 2007

The GetMagicNumberString function in Massive Entertainment World in Conflict 1.000 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon cr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5300

Published Oct 9, 2007

Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other versions allows remote attackers to cause a denial of service…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5266

Published Oct 8, 2007

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.0.29 beta1 and 1.2.x before 1.2.21 beta1 allows remote attackers to caus…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5267

Published Oct 8, 2007

Off-by-one error in ICC profile chunk handling in the png_set_iCCP function in pngset.c in libpng before 1.2.22 beta1 allows remote attackers to cause a denial of service (crash)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4568

Published Oct 5, 2007

Integer overflow in the build_range function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) Q…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4990

Published Oct 5, 2007

The swap_char2b function in X.Org X Font Server (xfs) before 1.0.5 allows context-dependent attackers to execute arbitrary code via (1) QueryXBitmaps and (2) QueryXExtents protoco…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5225

Published Oct 5, 2007

Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the contents of unspecified memory locations via a negative maxim…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5135

Published Sep 27, 2007

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,126-1,150 of 1,247 CVEsPage 46 of 50