CVE-2009-1721
- EPSS 25.35%
- Published 31.07.2009 19:00:01
- Last modified 09.04.2025 00:30:58
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...
CVE-2009-2408
- EPSS 1.69%
- Published 30.07.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
CVE-2009-2472
- EPSS 0.7%
- Published 22.07.2009 18:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, re...
CVE-2009-1699
- EPSS 5.63%
- Published 10.06.2009 18:00:00
- Last modified 09.04.2025 00:30:58
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files ...
CVE-2009-0949
- EPSS 15.38%
- Published 09.06.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler re...
CVE-2009-1961
- EPSS 0.13%
- Published 08.06.2009 01:00:00
- Last modified 09.04.2025 00:30:58
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of ...
CVE-2009-1630
- EPSS 0.11%
- Published 14.05.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass pe...
CVE-2009-1364
- EPSS 3.15%
- Published 01.05.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.
CVE-2009-1185
- EPSS 89.27%
- Published 17.04.2009 14:30:00
- Last modified 09.04.2025 00:30:58
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
CVE-2009-1186
- EPSS 0.09%
- Published 17.04.2009 14:30:00
- Last modified 09.04.2025 00:30:58
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.