Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-4131

Published Dec 13, 2009

The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a c…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4296

Published Dec 11, 2009

SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers to execute arbitrary SQL commands via un…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4295

Published Dec 11, 2009

Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote at…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4294

Published Dec 11, 2009

Unspecified vulnerability in the Authentication Manager (aka utauthd) in Sun Ray Server Software 4.0 and 4.1 allows remote attackers to execute arbitrary code or cause a denial of…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4124

Published Dec 11, 2009

Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute arbitrary code via unspecified…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4238

Published Dec 10, 2009

Multiple SQL injection vulnerabilities in TestLink before 1.8.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the Test Case ID field to lib/general/na…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4237

Published Dec 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the req parameter to login.php,…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0898

Published Dec 10, 2009

Stack-based buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted HTTP request.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4181

Published Dec 10, 2009

Stack-based buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via vectors inv…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4180

Published Dec 10, 2009

Stack-based buffer overflow in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP H…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4179

Published Dec 10, 2009

Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Acce…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4178

Published Dec 10, 2009

Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic pa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4177

Published Dec 10, 2009

Buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4176

Published Dec 10, 2009

Multiple heap-based buffer overflows in ovsessionmgr.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a l…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3849

Published Dec 10, 2009

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long Template pa…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3848

Published Dec 10, 2009

Stack-based buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Temp…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3847

Published Dec 10, 2009

Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3846

Published Dec 10, 2009

Multiple heap-based buffer overflows in ovlogin.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a long (…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3845

Published Dec 10, 2009

The port-3443 HTTP server in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary commands via shell metacharacters in the h…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 5,732 CVEsPage 12 of 230