Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4832 | 1 Deslock | 1 Deslock\+ | 2017-09-18 | 7.2 HIGH | N/A |
The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device. | |||||
CVE-2009-4799 | 1 Diskos | 1 Diskos Cms | 2017-09-18 | 5.0 MEDIUM | N/A |
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb. | |||||
CVE-2009-4760 | 1 Winn | 1 Asp Guestbook | 2017-09-18 | 5.0 MEDIUM | N/A |
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/guestbook.mdb. | |||||
CVE-2009-4545 | 1 Logoshows | 1 Logoshows Bbs | 2017-09-18 | 5.0 MEDIUM | N/A |
Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/globepersonnel.mdb. | |||||
CVE-2009-4033 | 1 Tim Hockin | 1 Acpid | 2017-09-18 | 6.9 MEDIUM | N/A |
A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file, cause a denial of service by overwriting this file, or gain privileges by executing this file. | |||||
CVE-2009-3988 | 1 Mozilla | 2 Firefox, Seamonkey | 2017-09-18 | 5.0 MEDIUM | N/A |
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values. | |||||
CVE-2009-3949 | 1 Vivaprograms | 1 Infinity Script | 2017-09-18 | 7.5 HIGH | N/A |
cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters. | |||||
CVE-2009-3939 | 1 Linux | 1 Linux Kernel | 2017-09-18 | 6.6 MEDIUM | N/A |
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | |||||
CVE-2009-3880 | 1 Sun | 2 Jre, Openjdk | 2017-09-18 | 5.0 MEDIUM | N/A |
The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512. | |||||
CVE-2009-3866 | 1 Sun | 2 Jdk, Jre | 2017-09-18 | 9.3 HIGH | N/A |
The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824. | |||||
CVE-2009-3716 | 1 Maniacomputer | 1 Mcshoutbox | 2017-09-18 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/. | |||||
CVE-2009-3597 | 1 Digitaldesign | 1 Ddcms | 2017-09-18 | 5.0 MEDIUM | N/A |
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for autoconfig.dd. | |||||
CVE-2009-3596 | 1 Joxtechnology | 1 Ajox Poll | 2017-09-18 | 7.5 HIGH | N/A |
JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypass authentication and gain administrative access via a direct request. | |||||
CVE-2009-3525 | 1 Xen | 1 Xen | 2017-09-18 | 7.2 HIGH | N/A |
The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password. | |||||
CVE-2009-3461 | 1 Adobe | 1 Acrobat | 2017-09-18 | 9.3 HIGH | N/A |
Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors. | |||||
CVE-2009-3421 | 1 Zenas | 1 Pao-bacheca Guestbook | 2017-09-18 | 6.8 MEDIUM | N/A |
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1. | |||||
CVE-2009-3385 | 1 Mozilla | 1 Seamonkey | 2017-09-18 | 7.1 HIGH | N/A |
The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation. | |||||
CVE-2009-3375 | 1 Mozilla | 1 Firefox | 2017-09-18 | 4.3 MEDIUM | N/A |
content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function. | |||||
CVE-2009-3374 | 1 Mozilla | 1 Firefox | 2017-09-18 | 7.5 HIGH | N/A |
The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects." | |||||
CVE-2009-3286 | 1 Linux | 1 Linux Kernel | 2017-09-18 | 4.6 MEDIUM | N/A |
NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails. |