Total
11483 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-1044 | 1 Apple | 1 Iphone Os | 2014-01-27 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2. | |||||
CVE-2013-1045 | 1 Apple | 1 Iphone Os | 2014-01-27 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2. | |||||
CVE-2013-1046 | 1 Apple | 1 Iphone Os | 2014-01-27 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2. | |||||
CVE-2013-0850 | 1 Ffmpeg | 1 Ffmpeg | 2014-01-27 | 9.3 HIGH | N/A |
The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted H.264 data, which triggers an out-of-bounds array access. | |||||
CVE-2013-3482 | 1 Hexagon | 1 Erdas Er Viewer | 2014-01-21 | 9.3 HIGH | N/A |
Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS file. | |||||
CVE-2013-3483 | 1 Hexagon | 1 Erdas Er Viewer | 2014-01-21 | 9.3 HIGH | N/A |
Stack-based buffer overflow in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ERS file. | |||||
CVE-2013-6763 | 1 Linux | 1 Linux Kernel | 2014-01-07 | 6.9 MEDIUM | N/A |
The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, a different vulnerability than CVE-2013-4511. | |||||
CVE-2009-5137 | 1 Mini-stream | 1 Castripper | 2014-01-06 | 7.5 HIGH | N/A |
Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667. | |||||
CVE-2013-6937 | 1 Videocharge | 1 Watermark Master | 2014-01-03 | 6.8 MEDIUM | N/A |
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attribute of the cols element in a .wstyle file. | |||||
CVE-2013-2894 | 1 Linux | 1 Linux Kernel | 2014-01-03 | 4.7 MEDIUM | N/A |
drivers/hid/hid-lenovo-tpkbd.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LENOVO_TPKBD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device. | |||||
CVE-2013-2895 | 1 Linux | 1 Linux Kernel | 2014-01-03 | 5.4 MEDIUM | N/A |
drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or obtain sensitive information from kernel memory via a crafted device. | |||||
CVE-2011-3941 | 1 Ffmpeg | 1 Ffmpeg | 2014-01-03 | 7.5 HIGH | N/A |
The decode_mb function in libavcodec/error_resilience.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to an uninitialized block index, which triggers an out-of-bounds write. | |||||
CVE-2013-6932 | 1 Irfanview | 1 Irfanview | 2013-12-30 | 7.6 HIGH | N/A |
Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window. | |||||
CVE-2013-0847 | 1 Ffmpeg | 1 Ffmpeg | 2013-12-27 | 9.3 HIGH | N/A |
The ff_id3v2_parse function in libavformat/id3v2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via ID3v2 header data, which triggers an out-of-bounds array access. | |||||
CVE-2013-0851 | 1 Ffmpeg | 1 Ffmpeg | 2013-12-27 | 9.3 HIGH | N/A |
The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access. | |||||
CVE-2010-0430 | 1 Redhat | 1 Enterprise Virtualization Hypervisor | 2013-12-27 | 7.4 HIGH | N/A |
libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings. | |||||
CVE-2012-6616 | 1 Ffmpeg | 1 Ffmpeg | 2013-12-26 | 5.0 MEDIUM | N/A |
The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 data. | |||||
CVE-2013-7105 | 1 Fujitsu | 2 Interstage Application Server, Interstage Studio | 2013-12-19 | 10.0 HIGH | N/A |
Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1, and 10.0.0; and Interstage Studio 9.0.0, 9.1.0, 9.2.0, and 10.0.0, has unspecified impact and attack vectors related to "ihsrlog/rotatelogs." | |||||
CVE-2012-0806 | 1 Duckcorp | 1 Bip | 2013-12-12 | 6.5 MEDIUM | N/A |
Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors. | |||||
CVE-2011-0524 | 1 Iain | 1 Gypsy | 2013-12-12 | 2.1 LOW | N/A |
Multiple buffer overflows in the NMEA parser (nmea-gen.c) in gypsy 0.8 allow local users to cause a denial of service (crash) via unspecified vectors related to the sprintf function. |