Total
29592 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4763 | 1 Phpmyvisites | 1 Phpmyvisites | 2024-11-21 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in the ClickHeat plugin, as used in phpMyVisites before 2.4, has unknown impact and attack vectors. NOTE: due to lack of details from the vendor, it is not clear whether this is related to CVE-2008-5793. | |||||
CVE-2009-4741 | 2 Microsoft, Skype | 2 Windows, Skype | 2024-11-21 | 10.0 HIGH | N/A |
Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors. | |||||
CVE-2009-4738 | 1 Justsystems | 3 Atok, Atok Flat-rate Service, Just Smile | 2024-11-21 | 7.2 HIGH | N/A |
Unspecified vulnerability in JustSystems Corporation ATOK 2006 through 2009 and ATOK flat-rate service, and Just Smile 4 with the ATOK Smile module, allows physically proximate users to bypass the screen lock and execute commands with system privileges via unknown vectors related to "launching external applications." | |||||
CVE-2009-4704 | 1 Typo3 | 2 Typo3, Ws Ecard | 2024-11-21 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors. | |||||
CVE-2009-4659 | 1 Mp3-cutter | 1 Ease Audio Cutter | 2024-11-21 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in MP3-Cutter Ease Audio Cutter 1.20 allows user-assisted remote attackers to cause a denial of service (application crash) via a long string in a WAV file. | |||||
CVE-2009-4603 | 1 Sap | 3 Sap Kernel, Sap Netweaver, Sap Web Application Server | 2024-11-21 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in sapstartsrv.exe in the SAP Kernel 6.40, 7.00, 7.01, 7.10, 7.11, and 7.20, as used in SAP NetWeaver 7.x and SAP Web Application Server 6.x and 7.x, allows remote attackers to cause a denial of service (Management Console shutdown) via a crafted request. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-4594 | 1 Ibm | 2 Lotus Domino, Lotus Inotes | 2024-11-21 | 10.0 HIGH | N/A |
Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH. | |||||
CVE-2009-4592 | 1 Secureideas | 1 Base | 2024-11-21 | 7.5 HIGH | N/A |
Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to include arbitrary local files via unknown vectors. | |||||
CVE-2009-4538 | 2 Debian, Linux | 2 Debian Linux, Linux Kernel | 2024-11-21 | 10.0 HIGH | N/A |
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537. | |||||
CVE-2009-4519 | 1 Ortro | 1 Ortro | 2024-11-21 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in Ortro before 1.3.4 have unknown impact and attack vectors. | |||||
CVE-2009-4492 | 1 Ruby-lang | 2 Ruby, Webrick | 2024-11-21 | 7.5 HIGH | N/A |
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-4487 | 1 F5 | 1 Nginx | 2024-11-21 | 6.8 MEDIUM | N/A |
nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-4483 | 1 Mailsite | 1 Mailsite | 2024-11-21 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in LDAP3A.exe in MailSite 8.0.4 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.13 through 8.11. NOTE: as of 20091229, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. | |||||
CVE-2009-4457 | 1 Provider4u | 1 Vsftpd Webmin Module | 2024-11-21 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues." | |||||
CVE-2009-4444 | 1 Microsoft | 1 Internet Information Services | 2024-11-21 | 6.0 MEDIUM | N/A |
Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a filename with a (1) .asp, (2) .cer, or (3) .asa first extension, followed by a semicolon and a safe extension, as demonstrated by the use of asp.dll to handle a .asp;.jpg file. | |||||
CVE-2009-4443 | 1 Sun | 1 Java System Directory Server | 2024-11-21 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the psearch (aka persistent search) functionality in Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allows remote attackers to cause a denial of service (psearch outage) by using a crafted psearch client to send requests that trigger a psearch thread loop, aka Bug Id 6855978. | |||||
CVE-2009-4439 | 1 Ibm | 1 Db2 | 2024-11-21 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query. | |||||
CVE-2009-4405 | 1 Edgewall | 1 Trac | 2024-11-21 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6." | |||||
CVE-2009-4404 | 1 Jochen Striepe | 1 T-prot | 2024-11-21 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in t-prot (TOFU Protection) before 2.8 allows remote attackers to cause a denial of service via unspecified vectors related to the "--maxlines" option and a crafted email message. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-4389 | 2 Robert Puntigam, Typo3 | 2 Aba Watchdog, Typo3 | 2024-11-21 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Watchdog (aba_watchdog) extension 2.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors. |