Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.1

    MEDIUM
    CVE-2009-5152

    Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation statu... Read more

    Affected Products : computrace_agent
    • EPSS Score: %0.05
    • Published: May. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2009-5151

    The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achie... Read more

    Affected Products : computrace_agent
    • EPSS Score: %0.06
    • Published: May. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2009-5150

    Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's... Read more

    Affected Products : computrace_agent
    • EPSS Score: %0.06
    • Published: May. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2009-5144

    mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.... Read more

    Affected Products : mod_gnutls
    • EPSS Score: %0.16
    • Published: Feb. 03, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2009-5140

    The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Le... Read more

    Affected Products : spa2102_firmware spa2102
    • EPSS Score: %0.48
    • Published: Feb. 12, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2009-5139

    The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issu... Read more

    Affected Products : gizmo5
    • EPSS Score: %0.20
    • Published: Feb. 12, 2020
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2009-5068

    There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows t... Read more

    Affected Products : simple_machines_forum
    • EPSS Score: %3.27
    • Published: Jan. 15, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2009-5050

    konversation before 1.2.3 allows attackers to cause a denial of service.... Read more

    Affected Products : konversation
    • EPSS Score: %0.37
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-5049

    WebApp JSP Snoop page XSS in jetty though 6.1.21.... Read more

    Affected Products : debian_linux jetty
    • EPSS Score: %1.11
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-5048

    Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.... Read more

    Affected Products : jetty
    • EPSS Score: %1.09
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-5046

    JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.... Read more

    Affected Products : debian_linux jetty
    • EPSS Score: %0.95
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2009-5045

    Dump Servlet information leak in jetty before 6.1.22.... Read more

    Affected Products : debian_linux jetty
    • EPSS Score: %1.87
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2009-5043

    burn allows file names to escape via mishandled quotation marks... Read more

    Affected Products : debian_linux burn
    • EPSS Score: %0.43
    • Published: Oct. 31, 2019
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2009-5042

    python-docutils allows insecure usage of temporary files... Read more

    Affected Products : debian_linux python-docutils
    • EPSS Score: %0.37
    • Published: Oct. 31, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2009-5041

    overkill has buffer overflow via long player names that can corrupt data on the server machine... Read more

    Affected Products : overkill
    • EPSS Score: %0.70
    • Published: Oct. 31, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2009-5025

    A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.... Read more

    Affected Products : pyforum
    • EPSS Score: %0.85
    • Published: Jan. 15, 2020
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2009-5004

    qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .... Read more

    Affected Products : qpid-cpp
    • EPSS Score: %1.85
    • Published: Nov. 09, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-4900

    pixelpost 1.7.1 has XSS... Read more

    Affected Products : pixelpost
    • EPSS Score: %0.31
    • Published: Oct. 28, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2009-4899

    pixelpost 1.7.1 has SQL injection... Read more

    Affected Products : pixelpost
    • EPSS Score: %0.29
    • Published: Oct. 28, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2009-4267

    The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.... Read more

    Affected Products : juddi
    • EPSS Score: %0.21
    • Published: Feb. 19, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291728 Results