Latest CVE Feed
-
7.2
HIGHCVE-2009-5151
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achie... Read more
Affected Products : computrace_agent- Published: May. 11, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2009-5150
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's... Read more
Affected Products : computrace_agent- Published: May. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-5144
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.... Read more
Affected Products : mod_gnutls- Published: Feb. 03, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2009-5140
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Le... Read more
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-5139
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issu... Read more
Affected Products : gizmo5- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2009-5068
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows t... Read more
Affected Products : simple_machines_forum- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-5050
konversation before 1.2.3 allows attackers to cause a denial of service.... Read more
Affected Products : konversation- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2009-5048
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.... Read more
Affected Products : jetty- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Nov. 06, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICAL- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2009-5041
overkill has buffer overflow via long player names that can corrupt data on the server machine... Read more
Affected Products : overkill- Published: Oct. 31, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-5025
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.... Read more
Affected Products : pyforum- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2009-5004
qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .... Read more
Affected Products : qpid-cpp- Published: Nov. 09, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUM- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2009-4267
The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof log entries via the numRows parameter.... Read more
Affected Products : juddi- Published: Feb. 19, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2009-4123
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.... Read more
Affected Products : jruby-openssl- Published: Dec. 12, 2023
- Modified: Nov. 21, 2024