Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4494 | 1 Aol | 1 Aolserver | 2018-10-10 | 5.0 MEDIUM | N/A |
AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-4495 | 1 Yaws | 1 Yaws | 2018-10-10 | 5.0 MEDIUM | N/A |
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-4496 | 1 Boa | 1 Boa | 2018-10-10 | 5.0 MEDIUM | N/A |
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-4321 | 1 Zen-cart | 1 Zen Cart | 2018-10-10 | 5.0 MEDIUM | N/A |
extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NOTE: some of these details are obtained from third party information. | |||||
CVE-2009-4493 | 1 Orion | 1 Orion Application Server | 2018-10-10 | 5.0 MEDIUM | N/A |
Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-4490 | 1 Acme | 1 Mini Httpd | 2018-10-10 | 5.0 MEDIUM | N/A |
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |||||
CVE-2009-5135 | 1 Nextapp | 1 Echo | 2018-10-10 | 5.0 MEDIUM | N/A |
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |||||
CVE-2009-4051 | 1 Downstairs.dnsalias | 1 Home Ftp Server | 2018-10-10 | 5.0 MEDIUM | N/A |
Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands. | |||||
CVE-2009-4105 | 1 Typsoft | 1 Typsoft Ftp Server | 2018-10-10 | 3.5 LOW | N/A |
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command without sending file data in between these two commands. | |||||
CVE-2009-4114 | 1 Kaspersky | 1 Kaspersky Anti-virus | 2018-10-10 | 4.9 MEDIUM | N/A |
kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl. | |||||
CVE-2009-4098 | 1 Openx | 1 Openx | 2018-10-10 | 6.0 MEDIUM | N/A |
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory. | |||||
CVE-2009-3591 | 1 Ben Webb | 1 Dopewars | 2018-10-10 | 5.0 MEDIUM | N/A |
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with an invalid location. | |||||
CVE-2009-3962 | 1 2wire | 6 1700hg, 1701hg, 1800hw and 3 more | 2018-10-10 | 7.8 HIGH | N/A |
The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program on TCP port 50001, a related issue to CVE-2006-4523. | |||||
CVE-2009-3830 | 1 Microsoft | 1 Sharepoint Server | 2018-10-10 | 5.0 MEDIUM | N/A |
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx. | |||||
CVE-2009-2918 | 1 Thegreenbow | 1 Thegreenbow Vpn Client | 2018-10-10 | 2.1 LOW | N/A |
The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of 0. | |||||
CVE-2009-2955 | 1 Google | 1 Chrome | 2018-10-10 | 5.0 MEDIUM | N/A |
Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and application hang) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715. | |||||
CVE-2009-2534 | 1 Realnetworks | 2 Helix Server, Helix Server Mobile | 2018-10-10 | 5.0 MEDIUM | N/A |
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI. | |||||
CVE-2009-2533 | 1 Realnetworks | 2 Helix Server, Helix Server Mobile | 2018-10-10 | 5.0 MEDIUM | N/A |
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers. | |||||
CVE-2009-2431 | 1 Wordpress | 1 Wordpress | 2018-10-10 | 5.0 MEDIUM | N/A |
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source. | |||||
CVE-2009-2421 | 1 Apple | 1 Safari | 2018-10-10 | 5.0 MEDIUM | N/A |
The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an unspecified protocol. |