CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-2480

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jul 2009
    5.8
    Medium

    CVE-2009-2481

    Last Modified: 23 Apr 2026

    mt-wizard.cgi in Six Apart Movable Type before 4.261, when global templates are not initialized, allows remote attackers to bypass access restrictions and (1) send e-mail to arbitrary addresses or (2) obtain sensitive information via unspecified vectors.

    Published: 16 Jul 2009
    7.8
    High

    CVE-2009-2486

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SCTP implementation in Sun Solaris 10, and OpenSolaris before snv_120, allows remote attackers to cause a denial of service (panic) via unspecified packets.

    Published: 16 Jul 2009
    7.8
    High

    CVE-2009-2487

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors.

    Published: 16 Jul 2009
    4.9
    Medium

    CVE-2009-2488

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NFSv4 module in the kernel in Sun Solaris 10, and OpenSolaris snv_102 through snv_119, allows local users to cause a denial of service (client panic) via vectors involving "file operations."

    Published: 16 Jul 2009
    2.1
    Low

    CVE-2009-2489

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the utdmsession program in Sun Ray Server Software (SRSS) 4.0 allows local users to access the sessions of arbitrary users via unknown vectors.

    Published: 16 Jul 2009
    1.9
    Low

    CVE-2009-2490

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to cause a denial of service (audio outage) or possibly gain privileges via unknown vectors related to "resource leaks."

    Published: 16 Jul 2009
    9.3
    Critical

    CVE-2009-2485

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file.

    Published: 16 Jul 2009
    9.3
    Critical

    CVE-2009-2484

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.

    Published: 16 Jul 2009
    6.9
    Medium

    CVE-2009-2482

    Last Modified: 23 Apr 2026

    The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is already known, even when they are not in the wheel group.

    Published: 16 Jul 2009
    4.4
    Medium

    CVE-2009-2491

    Last Modified: 23 Apr 2026

    The utaudiod daemon in Sun Ray Server Software (SRSS) 4.0, when Solaris Trusted Extensions is enabled, allows local users to access the sessions of arbitrary users via unknown vectors related to "resource leaks."

    Published: 16 Jul 2009
    4.9
    Medium

    CVE-2009-2483

    Last Modified: 23 Apr 2026

    libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.

    Published: 16 Jul 2009
    9
    Critical

    CVE-2009-2047

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to read, modify, or delete arbitrary files via unspecified vectors.

    Published: 16 Jul 2009
    3.5
    Low

    CVE-2009-2048

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or HTML into the CCX database via unspecified vectors.

    Published: 16 Jul 2009
    7.2
    High

    CVE-2009-1894

    Last Modified: 23 Apr 2026

    Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.

    Published: 16 Jul 2009
    8.8
    High

    CVE-2009-0231

    Last Modified: 23 Apr 2026

    The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."

    Published: 15 Jul 2009
    9.3
    Critical

    CVE-2009-0566

    Last Modified: 23 Apr 2026

    Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability."

    Published: 15 Jul 2009
    9.3
    Critical

    CVE-2009-1539

    Last Modified: 23 Apr 2026

    The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability."

    Published: 15 Jul 2009
    9.3
    Critical

    CVE-2009-0232

    Last Modified: 23 Apr 2026

    Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability."

    Published: 15 Jul 2009
    9
    Critical

    CVE-2009-1135

    Last Modified: 23 Apr 2026

    Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability."

    Published: 15 Jul 2009
    9.3
    Critical

    CVE-2009-1136

    Last Modified: 23 Apr 2026

    The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."

    Published: 15 Jul 2009
    9.3
    Critical

    CVE-2009-1538

    Last Modified: 23 Apr 2026

    The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability."

    Published: 15 Jul 2009
    9
    Critical

    CVE-2009-1542

    Last Modified: 23 Apr 2026

    The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability."

    Published: 15 Jul 2009
    5
    Medium

    CVE-2009-2535

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 15 Jul 2009
    4.3
    Medium

    CVE-2009-2537

    Last Modified: 23 Apr 2026

    KDE Konqueror allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 15 Jul 2009
    4
    Medium

    CVE-2009-1015

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2009-1019

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jul 2009
    9
    Critical

    CVE-2009-1020

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jul 2009
    5.5
    Medium

    CVE-2009-1021

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jul 2009
    5.5
    Medium

    CVE-2009-0987

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2009-1963

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and availability via unknown vectors.

    Published: 14 Jul 2009
    2.1
    Low

    CVE-2009-1969

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-1970

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991.

    Published: 14 Jul 2009
    5.5
    Medium

    CVE-2009-1973

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to VPD policies.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-1976

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 14 Jul 2009
    6
    Medium

    CVE-2009-1980

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jul 2009
    3
    Low

    CVE-2009-1981

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Highly Interactive Client component in Siebel Product Suite 7.5.3, 7.7.2, 7.8.2, 8.0.0.5, and 8.1.0 allows local users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jul 2009
    2.6
    Low

    CVE-2009-1986

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-1987

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools - Enterprise Portal component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.21 allows remote attackers to affect integrity via unknown vectors.

    Published: 14 Jul 2009
    5.5
    Medium

    CVE-2009-1989

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise FMS component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.8 SP1, 8.9 Bundle 33, and 9.0 Bundle 24 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jul 2009
    6.8
    Medium

    CVE-2009-1974

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Servlet Container Package.

    Published: 14 Jul 2009
    5.5
    Medium

    CVE-2009-1966

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1967.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-1982

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.6 allows remote attackers to affect integrity via unknown vectors.

    Published: 14 Jul 2009
    4
    Medium

    CVE-2009-1988

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS eProfile Manager component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.8 SP1, 8.9 Bundle 19, and 9.0 Bundle 9 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 14 Jul 2009
    5.5
    Medium

    CVE-2009-1967

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1966.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-1968

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search.

    Published: 14 Jul 2009
    6.8
    Medium

    CVE-2009-1975

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and availability, related to the WLS Console Package.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-1977

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php.

    Published: 14 Jul 2009
    9
    Critical

    CVE-2009-1978

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows remote authenticated users to execute arbitrary code with SYSTEM privileges via vectors involving property_box.php.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-1983

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows remote attackers to affect integrity via unknown vectors.

    Published: 14 Jul 2009