Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-3563

Published Dec 9, 2009

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofe…

CVSS 6.4 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2009-4236

Published Dec 8, 2009

The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 RC1 through 2.4.1, and Community Edition r18068 through r18…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1569

Published Dec 8, 2009

Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute arbitrary code via vectors rela…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1568

Published Dec 8, 2009

Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute arbitrary code via a long targe…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1298

Published Dec 8, 2009

The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument,…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4235

Published Dec 8, 2009

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cau…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4234

Published Dec 8, 2009

Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4233

Published Dec 8, 2009

Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla! allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4232

Published Dec 8, 2009

The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages with an arbitrary account name vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4231

Published Dec 8, 2009

Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to include and execute arbitrary local files via .. (dot dot) in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4230

Published Dec 8, 2009

Multiple stack-based buffer overflows in src/Task.cc in the FastCGI program in IIPImage Server before 0.9.8 might allow remote attackers to execute arbitrary code via vectors asso…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4229

Published Dec 8, 2009

Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL commands via (1) the catid parameter in the PATH_INFO to t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4033

Published Dec 8, 2009

A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users to leverage weak permissions on…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4228

Published Dec 8, 2009

Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4227

Published Dec 8, 2009

Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4226

Published Dec 8, 2009

Race condition in the IP module in the kernel in Sun OpenSolaris snv_106 through snv_124 allows remote attackers to cause a denial of service (NULL pointer dereference and panic)…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4225

Published Dec 8, 2009

Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 326-350 of 5,732 CVEsPage 14 of 230