Latest CVE Feed
-
9.8
CRITICALCVE-2009-5041
overkill has buffer overflow via long player names that can corrupt data on the server machine... Read more
Affected Products : overkill- EPSS Score: %0.70
- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-5025
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.... Read more
Affected Products : pyforum- EPSS Score: %0.85
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2009-5004
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .... Read more
Affected Products : qpid-cpp- EPSS Score: %1.85
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- EPSS Score: %0.31
- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.29
- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2009-4267
The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.... Read more
Affected Products : juddi- EPSS Score: %0.21
- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-4123
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.... Read more
Affected Products : jruby-openssl- EPSS Score: %0.20
- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2009-4067
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control ... Read more
- EPSS Score: %0.61
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2009-4011
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX user on the dom0, and then access a potentially reuse an already opened VPS console.... Read more
Affected Products : dtc-xen- EPSS Score: %0.39
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.34
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2009-3724
python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.... Read more
Affected Products : python-markdown2- EPSS Score: %0.24
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGH- EPSS Score: %0.65
- Published: Oct. 29, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2009-3721
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, cr... Read more
- EPSS Score: %0.78
- Published: May. 26, 2021
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2009-3614
liboping 1.3.2 allows users reading arbitrary files upon the local system.... Read more
- EPSS Score: %0.12
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
3.1
LOWCVE-2009-3552
In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterpr... Read more
Affected Products : enterprise_virtualization_manager- EPSS Score: %0.19
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2009-2802
MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.... Read more
Affected Products : mantisbt- EPSS Score: %0.45
- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2009-20001
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a... Read more
Affected Products : mantisbt- EPSS Score: %0.14
- Published: Mar. 07, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1120
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC function -exposed via the rep_srv.exe process- where the vulnerability is caused by an error when the rep_sr... Read more
Affected Products : emc_replistor- EPSS Score: %6.10
- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2009-10004
A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the function sandbox_body_class of the file functions.php. The manipulation of the argument page leads to cross site scripting. It is possi... Read more
Affected Products : sandbox_theme- EPSS Score: %0.06
- Published: Apr. 10, 2023
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2009-10003
A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an unknown function of the file tag.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the ... Read more
Affected Products : wordcraft- EPSS Score: %0.06
- Published: Jan. 29, 2023
- Modified: Nov. 21, 2024