CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-0054

    Last Modified: 23 Apr 2026

    PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to capture credentials by tricking a user into reading a modified or crafted e-mail message.

    Published: 16 Jan 2009
    6
    Medium

    CVE-2009-0170

    Last Modified: 23 Apr 2026

    Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access to resources," by visiting the Configuration Items component in the console.

    Published: 16 Jan 2009
    6.8
    Medium

    CVE-2009-0056

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.

    Published: 16 Jan 2009
    10
    Critical

    CVE-2009-0171

    Last Modified: 23 Apr 2026

    The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to the eXtended System Control Facility Unit (aka XSCFU or Service Processor), and have unspecified other impact.

    Published: 16 Jan 2009
    5
    Medium

    CVE-2009-0173

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream.

    Published: 16 Jan 2009
    9.3
    Critical

    CVE-2009-0135

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to execute arbitrary code via an Audible Audio (.aa) file with a large (1) nlen or (2) vlen Tag value, each of which triggers a heap-based buffer overflow.

    Published: 16 Jan 2009
    9.3
    Critical

    CVE-2009-0136

    Last Modified: 23 Apr 2026

    Multiple array index errors in the Audible::Tag::readTag function in metadata/audible/audibletag.cpp in Amarok 1.4.10 through 2.0.1 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via an Audible Audio (.aa) file with a crafted (1) nlen or (2) vlen Tag value, each of which can lead to an invalid pointer dereference, or the writing of a 0x00 byte to an arbitrary memory location, after an allocation failure.

    Published: 16 Jan 2009
    9.3
    Critical

    CVE-2009-0134

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

    Published: 16 Jan 2009
    7.5
    High

    CVE-2008-5902

    Last Modified: 23 Apr 2026

    Buffer overflow in the xrdp_bitmap_invalidate function in xrdp/xrdp_bitmap.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via a crafted request.

    Published: 15 Jan 2009
    6.8
    Medium

    CVE-2008-5906

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface's PHP scripts.

    Published: 15 Jan 2009
    4.3
    Medium

    CVE-2008-5905

    Last Modified: 23 Apr 2026

    The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.

    Published: 15 Jan 2009
    5
    Medium

    CVE-2009-0128

    Last Modified: 23 Apr 2026

    plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 15 Jan 2009
    4.9
    Medium

    CVE-2009-0132

    Last Modified: 23 Apr 2026

    Integer overflow in the aio_suspend function in Sun Solaris 8 through 10 and OpenSolaris, when 32-bit mode is enabled, allows local users to cause a denial of service (panic) via a large integer value in the second argument (aka nent argument).

    Published: 15 Jan 2009
    7.5
    High

    CVE-2008-5903

    Last Modified: 23 Apr 2026

    Array index error in the xrdp_bitmap_def_proc function in xrdp/funcs.c in xrdp 0.4.1 and earlier allows remote attackers to execute arbitrary code via vectors that manipulate the value of the edit_pos structure member.

    Published: 15 Jan 2009
    4.9
    Medium

    CVE-2009-0131

    Last Modified: 23 Apr 2026

    The UFS implementation in the kernel in Sun OpenSolaris snv_29 through snv_90 allows local users to cause a denial of service (panic) via the single posix_fallocate test in the SUSv3 POSIX test suite, related to an F_ALLOCSP fcntl call.

    Published: 15 Jan 2009
    7.5
    High

    CVE-2008-5904

    Last Modified: 23 Apr 2026

    The rdp_rdp_process_color_pointer_pdu function in rdp/rdp_rdp.c in xrdp 0.4.1 and earlier allows remote RDP servers to have an unknown impact via input data that sets crafted values for certain length variables, leading to a buffer overflow.

    Published: 15 Jan 2009
    6.9
    Medium

    CVE-2009-0122

    Last Modified: 23 Apr 2026

    hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via unspecified manipulations in advance of an HPLIP installation or upgrade by an administrator, related to the product's attempt to correct the ownership of its configuration files within home directories.

    Published: 15 Jan 2009
    7.1
    High

    CVE-2009-0123

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds. NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 15 Jan 2009
    7.5
    High

    CVE-2009-0130

    Last Modified: 23 Apr 2026

    lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a package maintainer disputes this issue, reporting that there is a proper check within the only code that uses the applicable part of crypto_drv.c, and thus "this report is invalid.

    Published: 15 Jan 2009
    10
    Critical

    CVE-2009-0133

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.

    Published: 15 Jan 2009
    7.6
    High

    CVE-1999-1593

    Last Modified: 23 Apr 2026

    Windows Internet Naming Service (WINS) allows remote attackers to cause a denial of service (connectivity loss) or steal credentials via a 1Ch registration that causes WINS to change the domain controller to point to a malicious server. NOTE: this problem may be limited when Windows 95/98 clients are used, or if the primary domain controller becomes unavailable.

    Published: 15 Jan 2009
    7.5
    High

    CVE-2003-1567

    Last Modified: 28 May 2026

    The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by using TRACK to read the contents of the HTTP headers that are returned in the response, a technique that is similar to cross-site tracing (XST) using HTTP TRACE.

    Published: 15 Jan 2009
    5
    Medium

    CVE-2009-3026

    Last Modified: 23 Apr 2026

    protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.

    Published: 15 Jan 2009
    2.1
    Low

    CVE-2008-2367

    Last Modified: 23 Apr 2026

    Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by reading these files.

    Published: 15 Jan 2009
    2.1
    Low

    CVE-2008-2368

    Last Modified: 23 Apr 2026

    Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permissions for these files, which allows local users to discover passwords by reading the files.

    Published: 15 Jan 2009
    6.5
    Medium

    CVE-2009-0030

    Last Modified: 23 Apr 2026

    A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663.

    Published: 15 Jan 2009
    7.8
    High

    CVE-2009-0120

    Last Modified: 23 Apr 2026

    The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.

    Published: 15 Jan 2009
    5
    Medium

    CVE-2003-1566

    Last Modified: 23 Apr 2026

    Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

    Published: 15 Jan 2009
    7.5
    High

    CVE-2009-0121

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Jan 2009
    10
    Critical

    CVE-2009-0119

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.

    Published: 14 Jan 2009
    10
    Critical

    CVE-2008-4834

    Last Modified: 23 Apr 2026

    Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans request, aka "SMB Buffer Overflow Remote Code Execution Vulnerability."

    Published: 14 Jan 2009
    9.8
    Critical

    CVE-2008-4835

    Last Modified: 23 Apr 2026

    SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in an NT Trans2 request, related to "insufficiently validating the buffer size," aka "SMB Validation Remote Code Execution Vulnerability."

    Published: 14 Jan 2009
    2.1
    Low

    CVE-2008-2623

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    4
    Medium

    CVE-2008-4016

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Collaborative Workspaces component in Oracle Collaboration Suite 10.1.2 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-4017

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the OC4J component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    4.3
    Medium

    CVE-2008-5438

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.

    Published: 14 Jan 2009
    3.5
    Low

    CVE-2008-5446

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows remote authenticated users to affect confidentiality via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is related to unrestricted guest access to the "About Us Page" in the Oracle Applications Framework (OAF), which allows attackers to obtain sensitive system and application environment information.

    Published: 14 Jan 2009
    4.9
    Medium

    CVE-2008-5454

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the iProcurement component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    4.9
    Medium

    CVE-2008-5455

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS - ePerformance component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    4.9
    Medium

    CVE-2008-5456

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 and 9.0.8 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-5459

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    2.6
    Low

    CVE-2008-5460

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    6.8
    Medium

    CVE-2008-5462

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jan 2009
    4.9
    Medium

    CVE-2008-5463

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise Campus Solutions component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 and 9.0.8 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-5445

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect availability via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service in observiced.exe via malformed private Protocol data that triggers a NULL pointer dereference.

    Published: 14 Jan 2009
    1.2
    Low

    CVE-2008-5450

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Platform Engineering component in Oracle E-Business Suite 11.5.10 CU2 and 12.0.6 allows local users to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    6.5
    Medium

    CVE-2008-4007

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise Components component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-4014

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle BPEL Process Manager component in Oracle Application Server allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-5443

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2008-5441 and CVE-2008-5442.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-5447

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Enterprise Manager component in Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009