Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2009-2317

    The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.... Read more

    Affected Products : mv_410r
    • EPSS Score: %0.88
    • Published: Jul. 05, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2300

    The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width and height parameters for an image, which allows remote attackers to execute arbitrary commands or cause ... Read more

    Affected Products : airlock_web_application_firewall
    • EPSS Score: %1.71
    • Published: Jul. 02, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2227

    Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810.... Read more

    Affected Products : bopup_communication_server
    • EPSS Score: %72.38
    • Published: Jun. 26, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2271

    The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers... Read more

    Affected Products : d100
    • EPSS Score: %0.34
    • Published: Jul. 01, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2296

    The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create, and modify arbitrary files, via unspecified vectors.... Read more

    Affected Products : solaris opensolaris
    • EPSS Score: %4.56
    • Published: Jul. 02, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2193

    Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet.... Read more

    Affected Products : mac_os_x mac_os_x_server
    • EPSS Score: %24.77
    • Published: Aug. 06, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2204

    Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrate... Read more

    Affected Products : iphone_os
    • EPSS Score: %18.69
    • Published: Aug. 03, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2030

    Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."... Read more

    Affected Products : jdk os\/400
    • EPSS Score: %0.78
    • Published: Jun. 11, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2038

    Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges.... Read more

    Affected Products : oscommerce finnish_bank_payment
    • EPSS Score: %0.47
    • Published: Jun. 12, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2039

    Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.... Read more

    Affected Products : oscommerce luottokunta
    • EPSS Score: %0.42
    • Published: Jun. 12, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1916

    dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.... Read more

    Affected Products : dns_tools
    • EPSS Score: %4.68
    • Published: Jun. 04, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1943

    Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514.... Read more

    Affected Products : softremote softremote1.4
    • EPSS Score: %64.25
    • Published: Jun. 05, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1918

    Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not pr... Read more

    • EPSS Score: %62.48
    • Published: Jul. 29, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1783

    Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote attac... Read more

    • EPSS Score: %0.41
    • Published: May. 22, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1784

    The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass ma... Read more

    Affected Products : avg_anti-virus
    • EPSS Score: %0.44
    • Published: May. 22, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1669

    The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are... Read more

    Affected Products : smarty
    • EPSS Score: %19.48
    • Published: May. 18, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1611

    Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command.... Read more

    Affected Products : 32bit_ftp
    • EPSS Score: %10.78
    • Published: May. 11, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1656

    Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulner... Read more

    Affected Products : workcentre
    • EPSS Score: %6.94
    • Published: May. 16, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1477

    The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded SSL private key, which makes it easier for remote attackers to decrypt htt... Read more

    • EPSS Score: %0.82
    • Published: May. 27, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1520

    Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (a... Read more

    • EPSS Score: %1.15
    • Published: May. 05, 2009
    • Modified: Apr. 09, 2025
Showing 20 of 292485 Results