CWE-189 · 1,236 records
Numeric Errors
CVEs in this class
1,238 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
77This week | CVE-2013-2094Weaponized | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows lolinux · linux kernel · CWE-189 | High8.4 | KEV | 47.7% | May 14, 2013 |
70This week | CVE-2015-1538Proof of concept | Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allgoogle · android · CWE-189 | Critical10.0 | — | 99.1% | Sep 30, 2015 |
67This week | CVE-2015-3829No exploit | Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows regoogle · android · CWE-189 | Critical10.0 | — | 89.8% | Sep 30, 2015 |
66This week | CVE-2015-3864Weaponized | Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 google · android · CWE-189 | Critical10.0 | — | 87.1% | Sep 30, 2015 |
66This week | CVE-2015-1539No exploit | Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remotgoogle · android · CWE-189 | Critical10.0 | — | 85.8% | Sep 30, 2015 |
65This week | CVE-2007-0071No exploit | Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code viadobe · flash player · CWE-189 | Critical9.3 | — | 92.5% | Apr 9, 2008 |
63This week | CVE-2011-2371Weaponized | Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMmozilla · seamonkey · CWE-189 | Critical10.0 | — | 75.7% | Jun 30, 2011 |
62This week | CVE-2012-1182Weaponized | The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array lensamba · samba · CWE-189 | Critical10.0 | — | 74.4% | Apr 10, 2012 |
62This week | CVE-2015-3087Proof of concept | Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460adobe · air · CWE-189 | Critical10.0 | — | 74.3% | May 13, 2015 |
60This week | CVE-2015-5560Proof of concept | Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, adobe · flash player · CWE-189 | Critical10.0 | — | 66.0% | Aug 13, 2015 |
59Plan | CVE-2006-3747Weaponized | Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions beforeapache · http server · CWE-189 | High7.6 | — | 96.6% | Jul 28, 2006 |
58Plan | CVE-2009-2990Weaponized | Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execadobe · acrobat · CWE-189 | Critical9.3 | — | 68.7% | Oct 19, 2009 |
58Plan | CVE-2008-5159Weaponized | Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote atclientsoftware · wincome mpd total · CWE-189 | Critical10.0 | — | 59.7% | Nov 18, 2008 |
56Plan | CVE-2008-0550Weaponized | Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary coradio toolbox · steamcast · CWE-189 | Critical10.0 | — | 53.8% | Feb 1, 2008 |
55Plan | CVE-2011-0257Weaponized | Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (appliapple · quicktime · CWE-189 | Critical9.3 | — | 60.1% | Aug 15, 2011 |
54Plan | CVE-2007-3456Proof of concept | Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value adobe · flash player · CWE-189 | Critical9.3 | — | 56.3% | Jul 11, 2007 |
53Plan | CVE-2007-5348Proof of concept | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2microsoft · digital image suite · CWE-189 | Critical9.3 | — | 52.9% | Sep 10, 2008 |
53Plan | CVE-2007-3034Proof of concept | Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 microsoft · windows 2000 · CWE-189 | Critical9.3 | — | 51.9% | Aug 14, 2007 |
52Plan | CVE-2009-2754Proof of concept | Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka poribm · informix dynamic server · CWE-189 | Critical10.0 | — | 40.1% | Mar 5, 2010 |
52Plan | CVE-2015-0135No exploit | IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of servibm · domino · CWE-189 | Critical10.0 | — | 39.8% | Apr 21, 2015 |
51Plan | CVE-2010-0028Proof of concept | Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary comicrosoft · windows 2000 · CWE-189 | Critical9.3 | — | 48.3% | Feb 10, 2010 |
49Plan | CVE-2008-3015No exploit | Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visimicrosoft · digital image suite · CWE-189 | Critical9.3 | — | 39.3% | Sep 10, 2008 |
49Plan | CVE-2011-2013Proof of concept | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold anmicrosoft · windows 7 · CWE-189 | Critical9.8 | — | 32.3% | Nov 8, 2011 |
48Plan | CVE-2009-0221No exploit | Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint filmicrosoft · office powerpoint · CWE-189 | Critical9.3 | — | 37.9% | May 12, 2009 |
48Plan | CVE-2009-0561No exploit | Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Micrmicrosoft · office · CWE-189 | Critical9.3 | — | 36.9% | Jun 10, 2009 |
- CVE-2013-209477This week
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows lo
HighCVSS 8.4KEVWeaponizedEPSS 48%linux · linux kernelMay 14, 2013
- CVE-2015-153870This week
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I all
CriticalCVSS 10.0Proof of conceptEPSS 99%google · androidSep 30, 2015
- CVE-2015-382967This week
Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows re
CriticalCVSS 10.0No exploitEPSS 90%google · androidSep 30, 2015
- CVE-2015-386466This week
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1
CriticalCVSS 10.0WeaponizedEPSS 87%google · androidSep 30, 2015
- CVE-2015-153966This week
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remot
CriticalCVSS 10.0No exploitEPSS 86%google · androidSep 30, 2015
- CVE-2007-007165This week
Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code vi
CriticalCVSS 9.3No exploitEPSS 93%adobe · flash playerApr 9, 2008
- CVE-2011-237163This week
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM
CriticalCVSS 10.0WeaponizedEPSS 76%mozilla · seamonkeyJun 30, 2011
- CVE-2012-118262This week
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array len
CriticalCVSS 10.0WeaponizedEPSS 74%samba · sambaApr 10, 2012
- CVE-2015-308762This week
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
CriticalCVSS 10.0Proof of conceptEPSS 74%adobe · airMay 13, 2015
- CVE-2015-556060This week
Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
CriticalCVSS 10.0Proof of conceptEPSS 66%adobe · flash playerAug 13, 2015
- CVE-2006-374759Plan
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before
HighCVSS 7.6WeaponizedEPSS 97%apache · http serverJul 28, 2006
- CVE-2009-299058Plan
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to exec
CriticalCVSS 9.3WeaponizedEPSS 69%adobe · acrobatOct 19, 2009
- CVE-2008-515958Plan
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote at
CriticalCVSS 10.0WeaponizedEPSS 60%clientsoftware · wincome mpd totalNov 18, 2008
- CVE-2008-055056Plan
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary co
CriticalCVSS 10.0WeaponizedEPSS 54%radio toolbox · steamcastFeb 1, 2008
- CVE-2011-025755Plan
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (appli
CriticalCVSS 9.3WeaponizedEPSS 60%apple · quicktimeAug 15, 2011
- CVE-2007-345654Plan
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value
CriticalCVSS 9.3Proof of conceptEPSS 56%adobe · flash playerJul 11, 2007
- CVE-2007-534853Plan
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2
CriticalCVSS 9.3Proof of conceptEPSS 53%microsoft · digital image suiteSep 10, 2008
- CVE-2007-303453Plan
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1
CriticalCVSS 9.3Proof of conceptEPSS 52%microsoft · windows 2000Aug 14, 2007
- CVE-2009-275452Plan
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka por
CriticalCVSS 10.0Proof of conceptEPSS 40%ibm · informix dynamic serverMar 5, 2010
- CVE-2015-013552Plan
IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of serv
CriticalCVSS 10.0No exploitEPSS 40%ibm · dominoApr 21, 2015
- CVE-2010-002851Plan
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary co
CriticalCVSS 9.3Proof of conceptEPSS 48%microsoft · windows 2000Feb 10, 2010
- CVE-2008-301549Plan
Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visi
CriticalCVSS 9.3No exploitEPSS 39%microsoft · digital image suiteSep 10, 2008
- CVE-2011-201349Plan
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold an
CriticalCVSS 9.8Proof of conceptEPSS 32%microsoft · windows 7Nov 8, 2011
- CVE-2009-022148Plan
Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint fil
CriticalCVSS 9.3No exploitEPSS 38%microsoft · office powerpointMay 12, 2009
- CVE-2009-056148Plan
Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Micr
CriticalCVSS 9.3No exploitEPSS 37%microsoft · officeJun 10, 2009