- EPSS 1.3%
- Veröffentlicht 24.11.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier f...
CVE-2009-3080
- EPSS 0.07%
- Veröffentlicht 20.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.
CVE-2009-3553
- EPSS 9.85%
- Veröffentlicht 20.11.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash ...
CVE-2009-3939
- EPSS 0.04%
- Veröffentlicht 16.11.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.
CVE-2009-3555
- EPSS 2.84%
- Veröffentlicht 09.11.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Secu...
CVE-2009-2629
- EPSS 80.03%
- Veröffentlicht 15.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
CVE-2008-7220
- EPSS 14.81%
- Veröffentlicht 13.09.2009 22:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.
CVE-2009-3094
- EPSS 2.83%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a mal...
- EPSS 3.99%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2692
- EPSS 18.38%
- Veröffentlicht 14.08.2009 15:16:27
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...