CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2009-3402

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    10
    Critical

    CVE-2009-3403

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.4: JRE/JDK, 1.4.2, 5, and, and 6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this issue subsumes CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, and CVE-2009-2676.

    Published: 22 Oct 2009
    4
    Medium

    CVE-2009-3404

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools & Enterprise Portal component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.23 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 22 Oct 2009
    4.1
    Medium

    CVE-2009-3405

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.98.1.4 allows remote authenticated users to affect integrity and availability via unknown vectors.

    Published: 22 Oct 2009
    2.7
    Low

    CVE-2009-3406

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.98.2.1 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    1.7
    Low

    CVE-2009-3401

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows local users to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-1999

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Business Intelligence Enterprise Edition component in unspecified Oracle Application Server versions allows remote attackers to affect integrity via unknown vectors.

    Published: 22 Oct 2009
    5.4
    Medium

    CVE-2009-3392

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Agile Engineering Data Management (EDM) component in Oracle E-Business Suite 6.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 22 Oct 2009
    6.5
    Medium

    CVE-2009-1007

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS.

    Published: 22 Oct 2009
    5.5
    Medium

    CVE-2009-1018

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC).

    Published: 22 Oct 2009
    5.4
    Medium

    CVE-2009-1965

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 22 Oct 2009
    1.7
    Low

    CVE-2009-1990

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Business Intelligence Enterprise Edition component in Oracle Application Server 10.1.3.4.1 allows local users to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    4.9
    Medium

    CVE-2009-1998

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Communications Order and Service Management component in Oracle Industry Applications 2.8.0, 6.2.0, 6.3.0, and 6.3.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 22 Oct 2009
    10
    Critical

    CVE-2009-1979

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.

    Published: 22 Oct 2009
    3.6
    Low

    CVE-2009-1991

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idx_owner or (2) idx_name parameters to the create_tables procedure.

    Published: 22 Oct 2009
    10
    Critical

    CVE-2009-1992

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 22 Oct 2009
    6.5
    Medium

    CVE-2009-1994

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability, related to MDSYS.PRVT_CMT_CBK.

    Published: 22 Oct 2009
    5
    Medium

    CVE-2009-2000

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-2002

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 8.1.6, 9.2.3, 10.0.1, 10.2.1, and 10.3.1.0.0 allows remote attackers to affect integrity via unknown vectors.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3393

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors.

    Published: 22 Oct 2009
    5.5
    Medium

    CVE-2009-3400

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Advanced Benefits component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3407

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-0983.

    Published: 22 Oct 2009
    5.1
    Medium

    CVE-2009-3408

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 22 Oct 2009
    3.6
    Low

    CVE-2009-3409

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise HCM (TAM) component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 9.0 Bundle 10 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-3750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3751

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent parameter.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-3752

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-3753

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-3754

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action to advancedsearch.php.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3755

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php; and the PATH_INFO to (3) modules_view.php, (4) tabledefs_options.php, and (5) adminsettings.php in phpbms\modules\base\.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-3760

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.

    Published: 22 Oct 2009
    8.8
    High

    CVE-2009-3759

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3747

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter. NOTE: this was originally reported for tbmnet.php, but that program does not exist in the TBmnetCMS 1.0 distribution.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3748

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and (6) MessagePart parameters to web/msgList/viewmsg/actions/msgAnalyse.asp; the (7) Queue, (8) FileName, (9) IsolatedMessageID, and (10) ServerName parameters to actions/msgForwardToRiskFilter.asp and viewHeaders.asp in web/msgList/viewmsg/; and (11) the subject in an e-mail message that is held in a Queue.

    Published: 22 Oct 2009
    5
    Medium

    CVE-2009-3749

    Last Modified: 23 Apr 2026

    The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response.

    Published: 22 Oct 2009
    5
    Medium

    CVE-2009-3756

    Last Modified: 23 Apr 2026

    phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3757

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php. NOTE: some of these details are obtained from third party information.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-3758

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 22 Oct 2009
    1.9
    Low

    CVE-2009-3746

    Last Modified: 23 Apr 2026

    XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276 and CVE-2009-2711.

    Published: 22 Oct 2009
    10
    Critical

    CVE-2008-3684

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to execute arbitrary code via crafted packet data to TCP port 2606.

    Published: 22 Oct 2009
    10
    Critical

    CVE-2008-3685

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606.

    Published: 22 Oct 2009
    5
    Medium

    CVE-2009-3744

    Last Modified: 23 Apr 2026

    rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted packet to TCP port 7144.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3745

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 22 Oct 2009
    7.5
    High

    CVE-2009-1479

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3641

    Last Modified: 23 Apr 2026

    Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.

    Published: 22 Oct 2009
    4.9
    Medium

    CVE-2009-4021

    Last Modified: 23 Apr 2026

    The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer dereference and OOPS) via vectors possibly related to a memory-consumption attack.

    Published: 22 Oct 2009
    2.1
    Low

    CVE-2010-2223

    Last Modified: 11 Apr 2025

    Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.

    Published: 22 Oct 2009
    7.8
    High

    CVE-2010-0741

    Last Modified: 11 Apr 2025

    The virtio_net_bad_features function in hw/virtio-net.c in the virtio-net driver in the Linux kernel before 2.6.26, when used on a guest OS in conjunction with qemu-kvm 0.11.0 or KVM 83, allows remote attackers to cause a denial of service (guest OS crash, and an associated qemu-kvm process exit) by sending a large amount of network traffic to a TCP port on the guest OS, related to a virtio-net whitelist that includes an improper implementation of TCP Segment Offloading (TSO).

    Published: 22 Oct 2009
    4.3
    Medium

    CVE-2009-3627

    Last Modified: 23 Apr 2026

    The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

    Published: 22 Oct 2009
    1.9
    Low

    CVE-2009-2911

    Last Modified: 23 Apr 2026

    SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.

    Published: 21 Oct 2009