Skip to main content

CWE archive

CWE-19 CVEs

Programmatic archive

235 CVEs tagged with CWE-1934 Critical, 105 High, 92 Medium, 4 Low, 0 Unrated.

CVE-2015-8772

Published Jan 29, 2016

McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1882

Published Jan 29, 2016

FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection wit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6429

Published Dec 19, 2015

The IKEv1 state machine in Cisco IOS 15.4 through 15.6 and IOS XE 3.15 through 3.17 allows remote attackers to cause a denial of service (IPsec connection termination) via a craft…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8339

Published Dec 17, 2015

The memory_exchange function in common/memory.c in Xen 3.2.x through 4.6.x does not properly hand back pages to a domain, which might allow guest OS administrators to cause a deni…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2328

Published Dec 2, 2015

PCRE before 8.36 mishandles the /((?(R)a|(?1)))+/ pattern and related patterns with certain recursion, which allows remote attackers to cause a denial of service (segmentation fau…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7971

Published Oct 30, 2015

Xen 3.2.x through 4.6.x does not limit the number of printk console messages when logging certain pmu and profiling hypercalls, which allows local guests to cause a denial of serv…

CVSS 2.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-5621

Published Aug 19, 2015

The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item when parsing of the SNMP PDU fails, wh…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3763

Published Aug 16, 2015

Safari in Apple iOS before 8.4.1 does not limit the rate of JavaScript alert messages, which allows remote attackers to cause a denial of service (apparent browser locking) via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5477

Published Jul 29, 2015

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

CVSS 7.8 · High
evidence mentions
6
Buzz score
27.5
Vendor/product tagsBeta · best-effort

CVE-2015-1270

Published Jul 23, 2015

The ucnv_io_getConverterName function in common/ucnv_io.cpp in International Components for Unicode (ICU), as used in Google Chrome before 44.0.2403.89, mishandles converter names…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2015-5363

Published Jul 16, 2015

The SRX Network Security Daemon (nsd) in Juniper SRX Series services gateways with Junos 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12…

CVSS 5.0 · Medium

CVE-2015-0989

Published Jun 28, 2015

PACTware 4.1 SP3 allows remote attackers to cause a denial of service (application crash) via a crafted file that triggers an internal error.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1759

Published Jun 10, 2015

Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-1687

Published Jun 10, 2015

Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Ex…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4147

Published Jun 9, 2015

The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows…

CVSS 7.5 · High
Showing 151-175 of 235 CVEsPage 7 of 10