CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2009-3956

    Last Modified: 23 Apr 2026

    The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers.

    Published: 12 Jan 2010
    10
    Critical

    CVE-2009-3958

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.

    Published: 12 Jan 2010
    10
    Critical

    CVE-2009-4212

    Last Modified: 23 Apr 2026

    Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.

    Published: 12 Jan 2010
    8.8
    High

    CVE-2009-3953

    Last Modified: 21 Apr 2026

    The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

    Published: 12 Jan 2010
    7.5
    High

    CVE-2009-4492

    Last Modified: 23 Apr 2026

    WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

    Published: 11 Jan 2010
    5
    Medium

    CVE-2010-2089

    Last Modified: 11 Apr 2025

    The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

    Published: 11 Jan 2010
    4.3
    Medium

    CVE-2010-2630

    Last Modified: 11 Apr 2025

    The TIFFReadDirectory function in LibTIFF 3.9.0 does not properly validate the data types of codec-specific tags that have an out-of-order position in a TIFF file, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.

    Published: 11 Jan 2010
    7.2
    High

    CVE-2010-4512

    Last Modified: 11 Apr 2025

    Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories.

    Published: 11 Jan 2010
    3.7
    Low

    CVE-2010-0014

    Last Modified: 23 Apr 2026

    System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, via an arbitrary password, to the screen-locking program on a workstation that has any user's Kerberos ticket-granting ticket (TGT); and might allow remote attackers to bypass intended access restrictions via vectors involving an arbitrary password in conjunction with a valid TGT.

    Published: 11 Jan 2010
    6.8
    Medium

    CVE-2009-4487

    Last Modified: 23 Apr 2026

    nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

    Published: 10 Jan 2010
    6.9
    Medium

    CVE-2010-0301

    Last Modified: 11 Apr 2025

    main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's home directory, which allows local users to gain privileges via a crafted file.

    Published: 10 Jan 2010
    10
    Critical

    CVE-2009-4594

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH.

    Published: 9 Jan 2010
    10
    Critical

    CVE-2010-0274

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.

    Published: 9 Jan 2010
    10
    Critical

    CVE-2010-0276

    Last Modified: 23 Apr 2026

    IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU.

    Published: 9 Jan 2010
    10
    Critical

    CVE-2010-0275

    Last Modified: 23 Apr 2026

    Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.

    Published: 9 Jan 2010
    4.3
    Medium

    CVE-2010-0648

    Last Modified: 11 Apr 2025

    Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.

    Published: 9 Jan 2010
    7.5
    High

    CVE-2009-4486

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema.

    Published: 8 Jan 2010
    10
    Critical

    CVE-2009-3952

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Illustrator CS3 13.0.3 and earlier and Illustrator CS4 14.0.0 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 8 Jan 2010
    10
    Critical

    CVE-2009-4009

    Last Modified: 23 Apr 2026

    Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.

    Published: 8 Jan 2010
    7.5
    High

    CVE-2009-4010

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones.

    Published: 8 Jan 2010
    8.8
    High

    CVE-2010-0012

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.

    Published: 8 Jan 2010
    4.6
    Medium

    CVE-2010-0271

    Last Modified: 23 Apr 2026

    hald in Sun OpenSolaris snv_51 through snv_130 does not have the proc_audit privilege during unspecified attempts to write to the auditing log, which makes it easier for physically proximate attackers to avoid detection of changes to the set of connected hardware devices supporting the Hardware Abstraction Layer (HAL) specification.

    Published: 8 Jan 2010
    7.5
    High

    CVE-2010-0272

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 8 Jan 2010
    7.5
    High

    CVE-2010-0273

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process memory address and crafted data to TCP port 80, as demonstrated by the vd_sjws2 module in VulnDisco. NOTE: as of 20100106, this disclosure has no actionable information. However, because the VulnDisco author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 8 Jan 2010
    5.4
    Medium

    CVE-2010-0003

    Last Modified: 11 Apr 2025

    The print_fatal_signal function in kernel/signal.c in the Linux kernel before 2.6.32.4 on the i386 platform, when print-fatal-signals is enabled, allows local users to discover the contents of arbitrary memory locations by jumping to an address and then reading a log file, and might allow local users to cause a denial of service (system slowdown or crash) by jumping to an address.

    Published: 8 Jan 2010
    2.1
    Low

    CVE-2010-0007

    Last Modified: 23 Apr 2026

    net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting or modifying rules, which allows local users to bypass intended access restrictions and configure arbitrary network-traffic filtering via a modified ebtables application.

    Published: 8 Jan 2010
    4.3
    Medium

    CVE-2009-3742

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the p_p_id parameter.

    Published: 7 Jan 2010
    4.3
    Medium

    CVE-2009-4497

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in LXR Cross Referencer 0.9.5 and 0.9.6 allows remote attackers to inject arbitrary web script or HTML via the i parameter to the ident program.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0224

    Last Modified: 23 Apr 2026

    SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0225

    Last Modified: 23 Apr 2026

    SanDisk Cruzer Enterprise USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0226

    Last Modified: 23 Apr 2026

    SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0227

    Last Modified: 23 Apr 2026

    Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0228

    Last Modified: 23 Apr 2026

    Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.

    Published: 7 Jan 2010
    2.1
    Low

    CVE-2010-0223

    Last Modified: 23 Apr 2026

    Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.

    Published: 7 Jan 2010
    2.1
    Low

    CVE-2010-0221

    Last Modified: 23 Apr 2026

    Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0222

    Last Modified: 23 Apr 2026

    Kingston DataTraveler BlackBox (DTBB), DataTraveler Secure Privacy Edition (DTSP), and DataTraveler Elite Privacy Edition (DTEP) USB flash drives use a fixed 256-bit key for obtaining access to the cleartext drive contents, which makes it easier for physically proximate attackers to read or modify data by determining and providing this key.

    Published: 7 Jan 2010
    4.6
    Medium

    CVE-2010-0229

    Last Modified: 23 Apr 2026

    Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time.

    Published: 7 Jan 2010
    4.3
    Medium

    CVE-2009-4586

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.html in Wowd client before 1.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sortby, (2) tags, or (3) ctx parameter in a search action.

    Published: 7 Jan 2010
    5
    Medium

    CVE-2009-4587

    Last Modified: 23 Apr 2026

    Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.

    Published: 7 Jan 2010
    7.5
    High

    CVE-2009-4591

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 7 Jan 2010
    7.5
    High

    CVE-2009-4592

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to include arbitrary local files via unknown vectors.

    Published: 7 Jan 2010
    5
    Medium

    CVE-2009-4593

    Last Modified: 23 Apr 2026

    The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 7 Jan 2010
    9.3
    Critical

    CVE-2009-4588

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlier in AwingSoft Awakening Web3D Player and Winds3D Viewer allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long SceneUrl property value, a different vulnerability than CVE-2009-2386. NOTE: some of these details are obtained from third party information.

    Published: 7 Jan 2010
    4.3
    Medium

    CVE-2009-4589

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter.

    Published: 7 Jan 2010
    4.3
    Medium

    CVE-2009-4590

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in base_local_rules.php in Basic Analysis and Security Engine (BASE) before 1.4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jan 2010
    6.8
    Medium

    CVE-2010-0309

    Last Modified: 11 Apr 2025

    The pit_ioport_read function in the Programmable Interval Timer (PIT) emulation in i8254.c in KVM 83 does not properly use the pit_state data structure, which allows guest OS users to cause a denial of service (host OS crash or hang) by attempting to read the /dev/port file.

    Published: 7 Jan 2010
    4.3
    Medium

    CVE-2009-4575

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 RC2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the personel_sira parameter in a sirala action to index.php.

    Published: 6 Jan 2010
    7.5
    High

    CVE-2009-4576

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php.

    Published: 6 Jan 2010
    7.5
    High

    CVE-2009-4577

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MDForum module 2.x through 2.07 for MAXdev MDPro allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.

    Published: 6 Jan 2010
    4.3
    Medium

    CVE-2009-4578

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Facileforms (com_facileforms) component for Joomla! and Mambo allows remote attackers to inject arbitrary web script or HTML via the Itemid parameter to index.php.

    Published: 6 Jan 2010