Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2015-0851

Published Aug 12, 2015

XMLTooling-C before 1.5.5, as used in OpenSAML-C and Shibboleth Service Provider (SP), does not properly handle integer conversion exceptions, which allows remote attackers to cau…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3228

Published Aug 11, 2015

Integer overflow in the gs_heap_alloc_bytes function in base/gsmalloc.c in Ghostscript 9.15 and earlier allows remote attackers to cause a denial of service (crash) via a crafted…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5962

Published Aug 8, 2015

Integer signedness error in the SharedBufferManagerParent::RecvAllocateGrallocBuffer function in the buffer-management implementation in the graphics layer in Mozilla Firefox OS b…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1279

Published Jul 23, 2015

Integer overflow in the CJBig2_Image::expand function in fxcodec/jbig2/JBig2_Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2015-4472

Published Jun 11, 2015

Off-by-one error in the READ_ENCINT macro in chmd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified o…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4471

Published Jun 11, 2015

Off-by-one error in the lzxd_decompress function in lzxd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer under-read and application crash) v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4470

Published Jun 11, 2015

Off-by-one error in the inflate function in mszipd.c in libmspack before 0.5 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a cr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4468

Published Jun 11, 2015

Multiple integer overflows in the search_chunk function in chmd.c in libmspack before 0.5 allow remote attackers to cause a denial of service (buffer over-read and application cra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4467

Published Jun 11, 2015

The chmd_init_decomp function in chmd.c in libmspack before 0.5 does not properly validate the reset interval, which allows remote attackers to cause a denial of service (divide-b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4022

Published Jun 9, 2015

Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code…

CVSS 7.5 · High

CVE-2015-4021

Published Jun 9, 2015

The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is diffe…

CVSS 5.0 · Medium

CVE-2015-4003

Published Jun 7, 2015

The oz_usb_handle_ep_data function in drivers/staging/ozwpan/ozusbsvc1.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to cause a denial of servic…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4001

Published Jun 7, 2015

Integer signedness error in the oz_hcd_get_desc_cnf function in drivers/staging/ozwpan/ozhcd.c in the OZWPAN driver in the Linux kernel through 4.0.5 allows remote attackers to ca…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4067

Published May 29, 2015

Integer overflow in the libnv6 module in Dell NetVault Backup before 10.0.5 allows remote attackers to execute arbitrary code via crafted template string specifiers in a serialize…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3814

Published May 26, 2015

The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3809

Published May 26, 2015

The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not properly track the current offset, which allows re…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 1,247 CVEsPage 7 of 50