CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2009-5004

    Last Modified: 21 Nov 2024

    qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-0146

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg.

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-0147

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap.

    Published: 16 Apr 2009
    6.8
    Medium

    CVE-2009-0195

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments.

    Published: 16 Apr 2009
    7.5
    High

    CVE-2009-1182

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-1183

    Last Modified: 23 Apr 2026

    The JBIG2 MMR decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted PDF file.

    Published: 16 Apr 2009
    3.6
    Low

    CVE-2009-1189

    Last Modified: 23 Apr 2026

    The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834.

    Published: 16 Apr 2009
    10
    Critical

    CVE-2009-1119

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execute arbitrary code via a crafted message to (1) ctrlservice.exe or (2) rep_srv.exe, possibly related to an integer overflow.

    Published: 15 Apr 2009
    6.4
    Medium

    CVE-2009-1013

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1014.

    Published: 15 Apr 2009
    5.8
    Medium

    CVE-2009-1014

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1013.

    Published: 15 Apr 2009
    8.5
    High

    CVE-2009-1016

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow involving an unspecified Server Plug-in and a crafted SSL certificate.

    Published: 15 Apr 2009
    4
    Medium

    CVE-2009-1017

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-0994.

    Published: 15 Apr 2009
    7.2
    High

    CVE-2009-0681

    Last Modified: 23 Apr 2026

    PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0975

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0978.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0976

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to LTADM.

    Published: 15 Apr 2009
    5
    Medium

    CVE-2009-0973

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Cluster Ready Services component in Oracle Database 10.1.0.5 allows remote attackers to affect availability via unknown vectors.

    Published: 15 Apr 2009
    4.3
    Medium

    CVE-2009-0974

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0983 and CVE-2009-3407.

    Published: 15 Apr 2009
    4.3
    Medium

    CVE-2009-0983

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-3407.

    Published: 15 Apr 2009
    4
    Medium

    CVE-2009-0982

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.19 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 15 Apr 2009
    2.1
    Low

    CVE-2009-0988

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Password Policy component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0990

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0989.

    Published: 15 Apr 2009
    5.4
    Medium

    CVE-2009-0986

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2009
    4.3
    Medium

    CVE-2009-0995

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 allows remote attackers to affect integrity via unknown vectors.

    Published: 15 Apr 2009
    4
    Medium

    CVE-2009-0996

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 15 Apr 2009
    4
    Medium

    CVE-2009-0997

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0998

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS - eBenefits component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 and 9.0.8 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 15 Apr 2009
    6.8
    Medium

    CVE-2009-0999

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2009
    5
    Medium

    CVE-2009-1003

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect integrity via unknown vectors related to "access to source code of web pages."

    Published: 15 Apr 2009
    4
    Medium

    CVE-2009-1004

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 15 Apr 2009
    4.1
    Medium

    CVE-2009-1005

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Product Suite 10.3.0, 3.2, 3.0.1, and 3.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2009
    5.8
    Medium

    CVE-2009-1002

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Oracle BEA WebLogic Server 10.3, 10.0 Gold through MP1, 9.2 Gold through MP3, 9.1, 9.0, 8.1 Gold through SP6, and 7.0 Gold through SP7 allows remote attackers to gain privileges via unknown vectors.

    Published: 15 Apr 2009
    6.5
    Medium

    CVE-2009-0972

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 11.1.0.6, 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2009
    9
    Critical

    CVE-2009-0979

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Resource Manager component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2009
    4
    Medium

    CVE-2009-0981

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue allows remote authenticated users to obtain APEX password hashes from the WWV_FLOW_USERS table via a SELECT statement.

    Published: 15 Apr 2009
    4.4
    Medium

    CVE-2009-1009

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.

    Published: 15 Apr 2009
    10
    Critical

    CVE-2009-1006

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.2 and earlier, with SDK/JRE 1.4.2, JRE/JDK 5, and JRE/JDK 6, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 15 Apr 2009
    4.4
    Medium

    CVE-2009-1008

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.

    Published: 15 Apr 2009
    4.4
    Medium

    CVE-2009-1010

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.

    Published: 15 Apr 2009
    4.4
    Medium

    CVE-2009-1011

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.

    Published: 15 Apr 2009
    10
    Critical

    CVE-2009-1012

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidentiality, integrity, and availability. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow in an unspecified plug-in that parses HTTP requests, which leads to a heap-based buffer overflow.

    Published: 15 Apr 2009
    5
    Medium

    CVE-2007-4514

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0978

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0975.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0980

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SQLX Functions component in Oracle Database 10.2.0.3 and 11.1.0.6 allows remote authenticated users to affect integrity and availability, related to AGGXQIMP.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0984

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_SYS_SQL.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0989

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0990.

    Published: 15 Apr 2009
    7.5
    High

    CVE-2009-1000

    Last Modified: 23 Apr 2026

    The Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 uses default passwords for unspecified "FND Applications Users (not DB users)," which has unknown impact and attack vectors.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0977

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the GRANT_TYPE_ACCESS procedure in the DBMS_AQADM_SYS package.

    Published: 15 Apr 2009
    7.1
    High

    CVE-2009-0985

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users with the IMP_FULL_DATABASE role to affect confidentiality, integrity, and availability.

    Published: 15 Apr 2009
    5
    Medium

    CVE-2009-0991

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-1970.

    Published: 15 Apr 2009
    5.5
    Medium

    CVE-2009-0992

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the DEQ_EXEJOB procedure.

    Published: 15 Apr 2009