CVE-2009-2408
- EPSS 1.69%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
CVE-2009-0949
- EPSS 15.38%
- Veröffentlicht 09.06.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler re...
CVE-2009-1961
- EPSS 0.13%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of ...
CVE-2009-0749
- EPSS 0.41%
- Veröffentlicht 02.03.2009 20:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the r...
CVE-2009-0040
- EPSS 3.94%
- Veröffentlicht 22.02.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a cr...
- EPSS 0.63%
- Veröffentlicht 12.02.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restric...
CVE-2008-4989
- EPSS 0.39%
- Veröffentlicht 13.11.2008 01:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers t...