Skip to main content

CWE archive

CWE-189 CVEs

Programmatic archive

1,247 CVEs tagged with CWE-189379 Critical, 275 High, 550 Medium, 43 Low, 0 Unrated.

CVE-2015-3808

Published May 26, 2015

The dissect_lbmr_pser function in epan/dissectors/packet-lbmr.c in the LBMR dissector in Wireshark 1.12.x before 1.12.5 does not reject a zero length, which allows remote attacker…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1258

Published May 20, 2015

Google Chrome before 43.0.2357.65 relies on libvpx code that was not built with an appropriate --size-limit value, which allows remote attackers to trigger a negative value for a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3885

Published May 19, 2015

Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer ov…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2717

Published May 14, 2015

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and ou…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0135

Published Apr 21, 2015

IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1149

Published Apr 10, 2015

Integer overflow in the simulator in Swift in Apple Xcode before 6.3 allows context-dependent attackers to cause a denial of service or possibly have unspecified other impact by t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0261

Published Mar 24, 2015

Integer signedness error in the mobility_opt_print function in the IPv6 mobility printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (out-of-bound…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1066

Published Mar 12, 2015

Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2063

Published Mar 9, 2015

Integer overflow in unace 1.2b allows remote attackers to cause a denial of service (crash) via a small file header in an ace archive, which triggers a buffer overflow.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1219

Published Mar 9, 2015

Integer overflow in the SkMallocPixelRef::NewAllocate function in core/SkMallocPixelRef.cpp in Skia, as used in Google Chrome before 41.0.2272.76, allows remote attackers to cause…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2015-2192

Published Mar 8, 2015

Integer overflow in the dissect_osd2_cdb_continuation function in epan/dissectors/packet-scsi-osd.c in the SCSI OSD dissector in Wireshark 1.12.x before 1.12.4 allows remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9683

Published Mar 3, 2015

Off-by-one error in the ecryptfs_decode_from_filename function in fs/ecryptfs/crypto.c in the eCryptfs subsystem in the Linux kernel before 3.18.2 allows local users to cause a de…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1474

Published Feb 16, 2015

Multiple integer overflows in the GraphicBuffer::unflatten function in platform/frameworks/native/libs/ui/GraphicBuffer.cpp in Android through 5.0 allow attackers to gain privileg…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-9670

Published Feb 8, 2015

Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflo…

CVSS 4.3 · Medium

CVE-2014-9666

Published Feb 8, 2015

The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote atta…

CVSS 6.8 · Medium
Showing 176-200 of 1,247 CVEsPage 8 of 50