Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2009-0773

    The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-... Read more

    Affected Products : firefox thunderbird seamonkey
    • Published: Mar. 05, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0721

    Unspecified vulnerability in Easy Login in the Sender module in HP Remote Graphics Software (RGS) 4.0.0 through 5.2.4 allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : remote_graphics_software
    • Published: May. 18, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0893

    Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MB... Read more

    Affected Products : xvid
    • Published: Jun. 02, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0616

    Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials ... Read more

    Affected Products : application_networking_manager
    • Published: Feb. 26, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0568

    The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory l... Read more

    • Published: Jun. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0621

    Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device management, which makes it easier for remote attackers to perform configuration ch... Read more

    Affected Products : ace_4710
    • Published: Feb. 26, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0492

    Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."... Read more

    Affected Products : simpleircbot
    • Published: Feb. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0414

    Unspecified vulnerability in Tor before 0.2.0.33 has unspecified impact and remote attack vectors that trigger heap corruption.... Read more

    Affected Products : tor tor
    • Published: Feb. 03, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0388

    Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a messag... Read more

    Affected Products : tightvnc ultravnc
    • Published: Feb. 04, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0323

    Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML... Read more

    Affected Products : amaya
    • Published: Jan. 28, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0344

    Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) ... Read more

    Affected Products : fire_x2100_m2 fire_x2200_m2
    • Published: Jan. 29, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0263

    Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file.... Read more

    Affected Products : winamp
    • Published: Jan. 23, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0210

    Buffer overflow in the MLF application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service (system crash) via unspecified vectors, aka PD28578.... Read more

    Affected Products : e-terrahabitat
    • Published: Feb. 08, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0345

    Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) ... Read more

    Affected Products : fire_x2100_m2 fire_x2200_m2
    • Published: Jan. 29, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0216

    GE Fanuc iFIX 5.0 and earlier relies on client-side authentication involving a weakly encrypted local password file, which allows remote attackers to bypass intended access restrictions and start privileged server login sessions by recovering a password o... Read more

    Affected Products : ifix
    • Published: Feb. 13, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0178

    Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.... Read more

    Affected Products : hardware_management_console
    • Published: Jan. 20, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0183

    Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request.... Read more

    • Published: Feb. 03, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0119

    Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.... Read more

    Affected Products : windows_xp
    • Published: Jan. 14, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0311

    The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.... Read more

    Affected Products : autostart
    • Published: Jan. 27, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0043

    The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.... Read more

    • Published: Jan. 08, 2009
    • Modified: Apr. 09, 2025
Showing 20 of 293329 Results