CVE-2009-0040
- EPSS 3.94%
- Published 22.02.2009 22:30:00
- Last modified 09.04.2025 00:30:58
The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a cr...
CVE-2008-6124
- EPSS 0.42%
- Published 13.02.2009 01:30:00
- Last modified 09.04.2025 00:30:58
SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL comma...
CVE-2008-6125
- EPSS 0.39%
- Published 13.02.2009 01:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to gain privileges via unknown vectors.
CVE-2009-0385
- EPSS 11.55%
- Published 02.02.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL p...
CVE-2009-0322
- EPSS 0.05%
- Published 28.01.2009 18:30:00
- Last modified 09.04.2025 00:30:58
drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size...
CVE-2009-0269
- EPSS 0.08%
- Published 26.01.2009 15:30:04
- Last modified 09.04.2025 00:30:58
fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, l...
CVE-2009-0255
- EPSS 5.11%
- Published 22.01.2009 23:30:00
- Last modified 09.04.2025 00:30:58
The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.
- EPSS 0.79%
- Published 15.01.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with k...
CVE-2009-0029
- EPSS 0.04%
- Published 15.01.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which ...
CVE-2008-4539
- EPSS 0.05%
- Published 29.12.2008 15:24:23
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap over...