CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2009-1984

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Application Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Patch Administrator.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-0192

    Last Modified: 23 Apr 2026

    Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-1382

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in mimetex.cgi in mimeTeX, when downloaded before 20090713, allow remote attackers to execute arbitrary code via a TeX file with long (1) picture, (2) circle, or (3) input tags.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2009-1383

    Last Modified: 23 Apr 2026

    The getdirective function in mathtex.cgi in mathTeX, when downloaded before 20090713, allows remote attackers to execute arbitrary commands via shell metacharacters in the dpi tag.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-1422

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privileges via unknown vectors, aka PR_41209.

    Published: 14 Jul 2009
    7.8
    High

    CVE-2009-1424

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39412, a different vulnerability than CVE-2009-1423 and CVE-2009-1425.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-2456

    Last Modified: 23 Apr 2026

    The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-2457

    Last Modified: 23 Apr 2026

    The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.

    Published: 14 Jul 2009
    5.4
    Medium

    CVE-2009-2458

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Fire V215 Server, when using XVR-100 graphic cards on system boards with part number 375-3463 and a hardware dash level -04 or later, allows remote attackers to cause a denial of service (panic) via unknown vectors.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-2459

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-2460

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors.

    Published: 14 Jul 2009
    7.2
    High

    CVE-2009-2461

    Last Modified: 23 Apr 2026

    mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.

    Published: 14 Jul 2009
    7.8
    High

    CVE-2009-1423

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service via unknown vectors, aka PR_39898, a different vulnerability than CVE-2009-1424 and CVE-2009-1425.

    Published: 14 Jul 2009
    7.8
    High

    CVE-2009-1425

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to cause a denial of service by triggering a stop or crash in httpd, aka PR_18770, a different vulnerability than CVE-2009-1423 and CVE-2009-1424.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6855

    Last Modified: 23 Apr 2026

    Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a certain cookie.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6858

    Last Modified: 23 Apr 2026

    Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6859

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6860

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6864

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6866

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules.php in the Current_Issue module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a summary action.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6867

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2009-2451

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-2452

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6857

    Last Modified: 23 Apr 2026

    Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6862

    Last Modified: 23 Apr 2026

    Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6865

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules.php in the Sectionsnew module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printpage action.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2009-2453

    Last Modified: 23 Apr 2026

    Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6854

    Last Modified: 23 Apr 2026

    Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6856

    Last Modified: 23 Apr 2026

    Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6861

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    7.5
    High

    CVE-2008-6863

    Last Modified: 23 Apr 2026

    Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-2454

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Citrix Web Interface 4.6, 5.0, and 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-2455

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in webadmin/admin.php in @mail 5.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) type and (2) func parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-3050

    Last Modified: 23 Apr 2026

    Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-3012

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site.

    Published: 14 Jul 2009
    6.9
    Medium

    CVE-2009-1893

    Last Modified: 23 Apr 2026

    The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command.

    Published: 14 Jul 2009
    10
    Critical

    CVE-2009-0692

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-0217

    Last Modified: 23 Apr 2026

    The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-1892

    Last Modified: 23 Apr 2026

    dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.

    Published: 14 Jul 2009
    9.3
    Critical

    CVE-2009-2477

    Last Modified: 23 Apr 2026

    js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

    Published: 14 Jul 2009
    5
    Medium

    CVE-2009-2478

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."

    Published: 14 Jul 2009
    7.8
    High

    CVE-2009-2479

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.

    Published: 14 Jul 2009
    4.3
    Medium

    CVE-2009-2448

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the search_choice parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Jul 2009
    7.5
    High

    CVE-2009-2449

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in maillinglist/admin/change_config.php in ADbNewsSender before 1.5.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter.

    Published: 13 Jul 2009
    5
    Medium

    CVE-2009-2445

    Last Modified: 23 Apr 2026

    Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-2447

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ogp_show.php in Online Guestbook Pro 5.1 allow remote attackers to inject arbitrary web script or HTML via the (1) search or (2) display parameter.

    Published: 13 Jul 2009
    7.2
    High

    CVE-2009-2450

    Last Modified: 23 Apr 2026

    The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon containing arbitrary kernel addresses, as demonstrated using the 0x830020C3 IOCTL.

    Published: 13 Jul 2009
    5
    Medium

    CVE-2009-2435

    Last Modified: 23 Apr 2026

    The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

    Published: 13 Jul 2009
    7.2
    High

    CVE-2009-2434

    Last Modified: 23 Apr 2026

    Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vectors.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-2442

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a resultats-recherche action.

    Published: 13 Jul 2009