CVE-2009-2525
- EPSS 36.25%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote atta...
CVE-2009-2529
- EPSS 24.55%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnera...
CVE-2009-2530
- EPSS 40.12%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...
CVE-2009-2531
- EPSS 40.12%
- Published 14.10.2009 10:30:01
- Last modified 09.04.2025 00:30:58
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corru...
CVE-2009-0090
- EPSS 44.66%
- Published 14.10.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application ...
CVE-2009-0091
- EPSS 44.52%
- Published 14.10.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a craf...
CVE-2009-0555
- EPSS 31.95%
- Published 14.10.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute ar...
CVE-2009-1547
- EPSS 29.72%
- Published 14.10.2009 10:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."
CVE-2009-1920
- EPSS 49.39%
- Published 08.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a ...
- EPSS 39.87%
- Published 08.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and th...