CWE-189 · 1 236 записей
Numeric Errors
CVE этого класса
1 238 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
77На этой неделе | CVE-2013-2094Готовый эксплойт | The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows lolinux · linux kernel · CWE-189 | Высокая8,4 | KEV | 47,7 % | 14 мая 2013 г. |
70На этой неделе | CVE-2015-1538Proof of concept | Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I allgoogle · android · CWE-189 | Критическая10,0 | — | 99,1 % | 30 сент. 2015 г. |
67На этой неделе | CVE-2015-3829Эксплойта нет | Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows regoogle · android · CWE-189 | Критическая10,0 | — | 89,8 % | 30 сент. 2015 г. |
66На этой неделе | CVE-2015-3864Готовый эксплойт | Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1 google · android · CWE-189 | Критическая10,0 | — | 87,1 % | 30 сент. 2015 г. |
66На этой неделе | CVE-2015-1539Эксплойта нет | Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remotgoogle · android · CWE-189 | Критическая10,0 | — | 85,8 % | 30 сент. 2015 г. |
65На этой неделе | CVE-2007-0071Эксплойта нет | Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code viadobe · flash player · CWE-189 | Критическая9,3 | — | 92,5 % | 9 апр. 2008 г. |
63На этой неделе | CVE-2011-2371Готовый эксплойт | Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMmozilla · seamonkey · CWE-189 | Критическая10,0 | — | 75,7 % | 30 июн. 2011 г. |
62На этой неделе | CVE-2012-1182Готовый эксплойт | The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array lensamba · samba · CWE-189 | Критическая10,0 | — | 74,4 % | 10 апр. 2012 г. |
62На этой неделе | CVE-2015-3087Proof of concept | Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460adobe · air · CWE-189 | Критическая10,0 | — | 74,3 % | 13 мая 2015 г. |
60На этой неделе | CVE-2015-5560Proof of concept | Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, adobe · flash player · CWE-189 | Критическая10,0 | — | 66,0 % | 13 авг. 2015 г. |
59В плане | CVE-2006-3747Готовый эксплойт | Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions beforeapache · http server · CWE-189 | Высокая7,6 | — | 96,6 % | 28 июл. 2006 г. |
58В плане | CVE-2009-2990Готовый эксплойт | Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execadobe · acrobat · CWE-189 | Критическая9,3 | — | 68,7 % | 19 окт. 2009 г. |
58В плане | CVE-2008-5159Готовый эксплойт | Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote atclientsoftware · wincome mpd total · CWE-189 | Критическая10,0 | — | 59,7 % | 18 нояб. 2008 г. |
56В плане | CVE-2008-0550Готовый эксплойт | Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary coradio toolbox · steamcast · CWE-189 | Критическая10,0 | — | 53,8 % | 1 февр. 2008 г. |
55В плане | CVE-2011-0257Готовый эксплойт | Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (appliapple · quicktime · CWE-189 | Критическая9,3 | — | 60,1 % | 15 авг. 2011 г. |
54В плане | CVE-2007-3456Proof of concept | Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value adobe · flash player · CWE-189 | Критическая9,3 | — | 56,3 % | 11 июл. 2007 г. |
53В плане | CVE-2007-5348Proof of concept | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2microsoft · digital image suite · CWE-189 | Критическая9,3 | — | 52,9 % | 10 сент. 2008 г. |
53В плане | CVE-2007-3034Proof of concept | Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 microsoft · windows 2000 · CWE-189 | Критическая9,3 | — | 51,9 % | 14 авг. 2007 г. |
52В плане | CVE-2009-2754Proof of concept | Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka poribm · informix dynamic server · CWE-189 | Критическая10,0 | — | 40,1 % | 5 мар. 2010 г. |
52В плане | CVE-2015-0135Эксплойта нет | IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of servibm · domino · CWE-189 | Критическая10,0 | — | 39,8 % | 21 апр. 2015 г. |
51В плане | CVE-2010-0028Proof of concept | Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary comicrosoft · windows 2000 · CWE-189 | Критическая9,3 | — | 48,3 % | 10 февр. 2010 г. |
49В плане | CVE-2008-3015Эксплойта нет | Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visimicrosoft · digital image suite · CWE-189 | Критическая9,3 | — | 39,3 % | 10 сент. 2008 г. |
49В плане | CVE-2011-2013Proof of concept | Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold anmicrosoft · windows 7 · CWE-189 | Критическая9,8 | — | 32,3 % | 8 нояб. 2011 г. |
48В плане | CVE-2009-0221Эксплойта нет | Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint filmicrosoft · office powerpoint · CWE-189 | Критическая9,3 | — | 37,9 % | 12 мая 2009 г. |
48В плане | CVE-2009-0561Эксплойта нет | Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Micrmicrosoft · office · CWE-189 | Критическая9,3 | — | 36,9 % | 10 июн. 2009 г. |
- CVE-2013-209477На этой неделе
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows lo
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 48 %linux · linux kernel14 мая 2013 г.
- CVE-2015-153870На этой неделе
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android before 5.1.1 LMY48I all
КритическаяCVSS 10,0Proof of conceptEPSS 99 %google · android30 сент. 2015 г.
- CVE-2015-382967На этой неделе
Off-by-one error in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I allows re
КритическаяCVSS 10,0Эксплойта нетEPSS 90 %google · android30 сент. 2015 г.
- CVE-2015-386466На этой неделе
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android before 5.1.1
КритическаяCVSS 10,0Готовый эксплойтEPSS 87 %google · android30 сент. 2015 г.
- CVE-2015-153966На этой неделе
Multiple integer underflows in the ESDS::parseESDescriptor function in ESDS.cpp in libstagefright in Android before 5.1.1 LMY48I allow remot
КритическаяCVSS 10,0Эксплойта нетEPSS 86 %google · android30 сент. 2015 г.
- CVE-2007-007165На этой неделе
Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code vi
КритическаяCVSS 9,3Эксплойта нетEPSS 93 %adobe · flash player9 апр. 2008 г.
- CVE-2011-237163На этой неделе
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM
КритическаяCVSS 10,0Готовый эксплойтEPSS 76 %mozilla · seamonkey30 июн. 2011 г.
- CVE-2012-118262На этой неделе
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement validation of an array len
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %samba · samba10 апр. 2012 г.
- CVE-2015-308762На этой неделе
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
КритическаяCVSS 10,0Proof of conceptEPSS 74 %adobe · air13 мая 2015 г.
- CVE-2015-556060На этой неделе
Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
КритическаяCVSS 10,0Proof of conceptEPSS 66 %adobe · flash player13 авг. 2015 г.
- CVE-2006-374759В плане
Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before
ВысокаяCVSS 7,6Готовый эксплойтEPSS 97 %apache · http server28 июл. 2006 г.
- CVE-2009-299058В плане
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to exec
КритическаяCVSS 9,3Готовый эксплойтEPSS 69 %adobe · acrobat19 окт. 2009 г.
- CVE-2008-515958В плане
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote at
КритическаяCVSS 10,0Готовый эксплойтEPSS 60 %clientsoftware · wincome mpd total18 нояб. 2008 г.
- CVE-2008-055056В плане
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary co
КритическаяCVSS 10,0Готовый эксплойтEPSS 54 %radio toolbox · steamcast1 февр. 2008 г.
- CVE-2011-025755В плане
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (appli
КритическаяCVSS 9,3Готовый эксплойтEPSS 60 %apple · quicktime15 авг. 2011 г.
- CVE-2007-345654В плане
Integer overflow in Adobe Flash Player 9.0.45.0 and earlier might allow remote attackers to execute arbitrary code via a large length value
КритическаяCVSS 9,3Proof of conceptEPSS 56 %adobe · flash player11 июл. 2007 г.
- CVE-2007-534853В плане
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2
КритическаяCVSS 9,3Proof of conceptEPSS 53 %microsoft · digital image suite10 сент. 2008 г.
- CVE-2007-303453В плане
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1
КритическаяCVSS 9,3Proof of conceptEPSS 52 %microsoft · windows 200014 авг. 2007 г.
- CVE-2009-275452В плане
Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka por
КритическаяCVSS 10,0Proof of conceptEPSS 40 %ibm · informix dynamic server5 мар. 2010 г.
- CVE-2015-013552В плане
IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of serv
КритическаяCVSS 10,0Эксплойта нетEPSS 40 %ibm · domino21 апр. 2015 г.
- CVE-2010-002851В плане
Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary co
КритическаяCVSS 9,3Proof of conceptEPSS 48 %microsoft · windows 200010 февр. 2010 г.
- CVE-2008-301549В плане
Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visi
КритическаяCVSS 9,3Эксплойта нетEPSS 39 %microsoft · digital image suite10 сент. 2008 г.
- CVE-2011-201349В плане
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold an
КритическаяCVSS 9,8Proof of conceptEPSS 32 %microsoft · windows 78 нояб. 2011 г.
- CVE-2009-022148В плане
Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint fil
КритическаяCVSS 9,3Эксплойта нетEPSS 38 %microsoft · office powerpoint12 мая 2009 г.
- CVE-2009-056148В плане
Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Micr
КритическаяCVSS 9,3Эксплойта нетEPSS 37 %microsoft · office10 июн. 2009 г.