CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2009-3377

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 27 Oct 2009
    5
    Medium

    CVE-2009-3549

    Last Modified: 23 Apr 2026

    packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace.

    Published: 27 Oct 2009
    4.3
    Medium

    CVE-2009-3550

    Last Modified: 23 Apr 2026

    The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained from third party information.

    Published: 27 Oct 2009
    5
    Medium

    CVE-2009-3551

    Last Modified: 23 Apr 2026

    Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained from third party information.

    Published: 27 Oct 2009
    4.3
    Medium

    CVE-2009-3780

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1 and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Oct 2009
    7.5
    High

    CVE-2009-3781

    Last Modified: 23 Apr 2026

    The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.

    Published: 26 Oct 2009
    3.5
    Low

    CVE-2009-3782

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with "View own userpoints" permissions to read the userpoint data of arbitrary users via unknown attack vectors.

    Published: 26 Oct 2009
    4.3
    Medium

    CVE-2009-3783

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vector.

    Published: 26 Oct 2009
    5
    Medium

    CVE-2009-3787

    Last Modified: 23 Apr 2026

    files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.

    Published: 26 Oct 2009
    7.5
    High

    CVE-2009-3788

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.

    Published: 26 Oct 2009
    6.8
    Medium

    CVE-2009-3784

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 26 Oct 2009
    7.5
    High

    CVE-2009-3778

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 26 Oct 2009
    4.3
    Medium

    CVE-2009-3779

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content.

    Published: 26 Oct 2009
    6.8
    Medium

    CVE-2009-3785

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allow remote attackers to hijack the authentication of arbitrary users via unknown vectors.

    Published: 26 Oct 2009
    4.3
    Medium

    CVE-2009-3786

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title.

    Published: 26 Oct 2009
    4.3
    Medium

    CVE-2009-3789

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.

    Published: 26 Oct 2009
    9.3
    Critical

    CVE-2009-3790

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Oct 2009
    6.9
    Medium

    CVE-2009-5064

    Last Modified: 11 Apr 2025

    ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc.

    Published: 26 Oct 2009
    7.5
    High

    CVE-2009-4611

    Last Modified: 23 Apr 2026

    Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator, related to (1) a string value in the Age parameter to the default URI for the Cookie Dump Servlet in test-jetty-webapp/src/main/java/com/acme/CookieDump.java under cookie/, (2) an alphabetic value in the A parameter to jsp/expr.jsp, or (3) an alphabetic value in the Content-Length HTTP header to an arbitrary application.

    Published: 25 Oct 2009
    5
    Medium

    CVE-2009-4609

    Last Modified: 23 Apr 2026

    The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstrated by discovering the value of the getPathTranslated variable.

    Published: 25 Oct 2009
    4.3
    Medium

    CVE-2009-4612

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.

    Published: 25 Oct 2009
    4.3
    Medium

    CVE-2009-4610

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.

    Published: 25 Oct 2009
    5
    Medium

    CVE-2009-3941

    Last Modified: 23 Apr 2026

    Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 24 Oct 2009
    2.1
    Low

    CVE-2010-2522

    Last Modified: 11 Apr 2025

    The mipv6 daemon in UMIP 0.4 does not verify that netlink messages originated in the kernel, which allows local users to spoof netlink socket communication via a crafted unicast message.

    Published: 24 Oct 2009
    6.4
    Medium

    CVE-2009-3942

    Last Modified: 23 Apr 2026

    Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 24 Oct 2009
    10
    Critical

    CVE-2010-2523

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in ha.c in the mipv6 daemon in UMIP 0.4 allow remote attackers to have an unspecified impact via a crafted (1) ND_OPT_PREFIX_INFORMATION or (2) ND_OPT_HOME_AGENT_INFO packet.

    Published: 24 Oct 2009
    10
    Critical

    CVE-2009-2281

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.

    Published: 23 Oct 2009
    9.9
    Critical

    CVE-2009-3616

    Last Modified: 23 Apr 2026

    Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3768

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3769

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3770

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3771

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3772

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3773

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3774

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3776

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3775

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    Unknown

    CVE-2009-3777

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Oct 2009
    5.5
    Medium

    CVE-2009-1964

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 22 Oct 2009
    3.5
    Low

    CVE-2009-1971

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 22 Oct 2009
    2.1
    Low

    CVE-2009-1972

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL and DBMS_SQL.

    Published: 22 Oct 2009
    10
    Critical

    CVE-2009-1985

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 22 Oct 2009
    5.5
    Medium

    CVE-2009-1993

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remote authenticated users to affect confidentiality and integrity, related to FLOWS_030000.WWV_EXECUTE_IMMEDIATE.

    Published: 22 Oct 2009
    5
    Medium

    CVE-2009-1997

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Authentication component in Oracle Database 10.2.0.3 and 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    4.9
    Medium

    CVE-2009-1995

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_AQ_INV.

    Published: 22 Oct 2009
    6.5
    Medium

    CVE-2009-2001

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PL/SQL component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 22 Oct 2009
    5
    Medium

    CVE-2009-3395

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the AutoVue component in Oracle E-Business Suite 19.3.2 allows remote attackers to affect availability via unknown vectors.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3396

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.0, 9.1, 9.2.3, 10.0.1, and 10.3 allows remote attackers to affect integrity, related to WLS Console.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3397

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3399

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 7.0.6 and 8.1.5 allows remote attackers to affect integrity, related to WLS Console.

    Published: 22 Oct 2009