|
303631
|
- |
|
apache
|
derby
|
The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, whic…
|
CWE-310
Cryptographic Issues
|
CVE-2009-4269
|
2024-11-21 10:09 |
2010-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303632
|
7.5 |
HIGH
Network
|
jruby
|
jruby-openssl
|
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2009-4123
|
2024-11-21 10:08 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303633
|
7.8 |
HIGH
Local
|
gnome ytnef_project
|
evolution ytnef
|
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to…
|
-
|
CVE-2009-3721
|
2024-11-21 10:08 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303634
|
6.8 |
MEDIUM
Physics
|
linux redhat
|
linux_kernel enterprise_linux
|
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of…
|
CWE-120
Classic Buffer Overflow
|
CVE-2009-4067
|
2024-11-21 10:08 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303635
|
6.1 |
MEDIUM
Network
|
python-markdown2_project
|
python-markdown2
|
python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.
|
CWE-79
Cross-site Scripting
|
CVE-2009-3724
|
2024-11-21 10:08 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303636
|
8.1 |
HIGH
Network
|
dtc-xen_project
|
dtc-xen
|
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX user on the dom0, and then access a potentially reuse an already opened VPS con…
|
CWE-362
Race Condition
|
CVE-2009-4011
|
2024-11-21 10:08 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303637
|
9.8 |
CRITICAL
Network
|
ytnef_project
|
ytnef
|
ytnef has directory traversal
|
CWE-22
Path Traversal
|
CVE-2009-3887
|
2024-11-21 10:08 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303638
|
7.5 |
HIGH
Network
|
sangoma debian
|
asterisk debian_linux
|
asterisk allows calls on prohibited networks
|
CWE-863
Incorrect Authorization
|
CVE-2009-3723
|
2024-11-21 10:08 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303639
|
- |
|
nlnetlabs
|
unbound
|
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
|
CWE-399
Resource Management Errors
|
CVE-2009-4008
|
2024-11-21 10:08 |
2011-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303640
|
- |
|
artifex
|
gpl_ghostscript afpl_ghostscript ghostscript_fonts
|
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory…
|
CWE-189
Numeric Errors
|
CVE-2009-3743
|
2024-11-21 10:08 |
2010-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|