Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2009-3075

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and appl... Read more

    Affected Products : firefox
    • Published: Sep. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-3073

    Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more

    Affected Products : firefox
    • Published: Sep. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-3050

    Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.... Read more

    Affected Products : htmldoc
    • Published: Sep. 02, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-3027

    VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; ... Read more

    • Published: Dec. 11, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2532

    Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a craft... Read more

    Affected Products : windows_server_2008 windows_vista
    • Published: Oct. 14, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2494

    The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations aft... Read more

    • Published: Aug. 12, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2415

    Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.... Read more

    Affected Products : memcached memcached
    • Published: Aug. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2028

    Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 have unknown impact and attack vectors, related to "Adobe internally discovered iss... Read more

    Affected Products : acrobat acrobat_reader
    • Published: Jun. 11, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1925

    The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby... Read more

    • Published: Sep. 08, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1899

    Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticate... Read more

    Affected Products : websphere_application_server
    • Published: Jun. 03, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1300

    apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.... Read more

    Affected Products : advanced_package_tool apt
    • Published: Apr. 16, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-1172

    The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknow... Read more

    Affected Products : websphere_application_server
    • Published: Mar. 31, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0916

    Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."... Read more

    Affected Products : opera_browser
    • Published: Mar. 16, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0771

    The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and as... Read more

    Affected Products : firefox thunderbird seamonkey
    • Published: Mar. 05, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0650

    Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd fiel... Read more

    Affected Products : tptest
    • Published: Feb. 20, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0544

    Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.... Read more

    Affected Products : arc2
    • Published: Feb. 12, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0258

    The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is n... Read more

    Affected Products : typo3
    • Published: Jan. 22, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0208

    Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : virtual_rooms
    • Published: Feb. 26, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2019-16932

    A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.... Read more

    Affected Products : visualizer
    • Published: Sep. 30, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2008-6821

    Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-200... Read more

    Affected Products : db2
    • Published: Jun. 03, 2009
    • Modified: Apr. 09, 2025
Showing 20 of 293186 Results