Skip to content
Noroxi

CWE-189 · 1,236 records

Numeric Errors

CVEs in this class

1,238 records

  • CVE-2013-2094
    77This week

    The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows lo

    HighCVSS 8.4KEVWeaponizedEPSS 48%

    linux · linux kernelMay 14, 2013

  • CVE-2015-1538
    70This week

    Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I all

    CriticalCVSS 10.0Proof of conceptEPSS 99%

    google · androidSep 30, 2015

  • CVE-2015-3829
    67This week

    Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows re

    CriticalCVSS 10.0No exploitEPSS 90%

    google · androidSep 30, 2015

  • CVE-2015-3864
    66This week

    Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1

    CriticalCVSS 10.0WeaponizedEPSS 87%

    google · androidSep 30, 2015

  • CVE-2015-1539
    66This week

    Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remot

    CriticalCVSS 10.0No exploitEPSS 86%

    google · androidSep 30, 2015

  • CVE-2007-0071
    65This week

    Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code vi

    CriticalCVSS 9.3No exploitEPSS 93%

    adobe · flash playerApr 9, 2008

  • CVE-2011-2371
    63This week

    Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM

    CriticalCVSS 10.0WeaponizedEPSS 76%

    mozilla · seamonkeyJun 30, 2011

  • CVE-2012-1182
    62This week

    The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array len

    CriticalCVSS 10.0WeaponizedEPSS 74%

    samba · sambaApr 10, 2012

  • CVE-2015-3087
    62This week

    Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460

    CriticalCVSS 10.0Proof of conceptEPSS 74%

    adobe · airMay 13, 2015

  • CVE-2015-5560
    60This week

    Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,

    CriticalCVSS 10.0Proof of conceptEPSS 66%

    adobe · flash playerAug 13, 2015

  • Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before

    HighCVSS 7.6WeaponizedEPSS 97%

    apache · http serverJul 28, 2006

  • Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to exec

    CriticalCVSS 9.3WeaponizedEPSS 69%

    adobe · acrobatOct 19, 2009

  • Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote at

    CriticalCVSS 10.0WeaponizedEPSS 60%

    clientsoftware · wincome mpd totalNov 18, 2008

  • Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary co

    CriticalCVSS 10.0WeaponizedEPSS 54%

    radio toolbox · steamcastFeb 1, 2008

  • Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (appli

    CriticalCVSS 9.3WeaponizedEPSS 60%

    apple · quicktimeAug 15, 2011

  • Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value

    CriticalCVSS 9.3Proof of conceptEPSS 56%

    adobe · flash playerJul 11, 2007

  • Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2

    CriticalCVSS 9.3Proof of conceptEPSS 53%

    microsoft · digital image suiteSep 10, 2008

  • Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1

    CriticalCVSS 9.3Proof of conceptEPSS 52%

    microsoft · windows 2000Aug 14, 2007

  • Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka por

    CriticalCVSS 10.0Proof of conceptEPSS 40%

    ibm · informix dynamic serverMar 5, 2010

  • IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of serv

    CriticalCVSS 10.0No exploitEPSS 40%

    ibm · dominoApr 21, 2015

  • Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary co

    CriticalCVSS 9.3Proof of conceptEPSS 48%

    microsoft · windows 2000Feb 10, 2010

  • Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visi

    CriticalCVSS 9.3No exploitEPSS 39%

    microsoft · digital image suiteSep 10, 2008

  • Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold an

    CriticalCVSS 9.8Proof of conceptEPSS 32%

    microsoft · windows 7Nov 8, 2011

  • Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint fil

    CriticalCVSS 9.3No exploitEPSS 38%

    microsoft · office powerpointMay 12, 2009

  • Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Micr

    CriticalCVSS 9.3No exploitEPSS 37%

    microsoft · officeJun 10, 2009

All vulnerability classes