CVE-2009-3094
- EPSS 2.83%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a mal...
- EPSS 3.03%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2692
- EPSS 16.02%
- Veröffentlicht 14.08.2009 15:16:27
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...
CVE-2009-2416
- EPSS 0.19%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 1.56%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...
CVE-2009-2687
- EPSS 11.71%
- Veröffentlicht 05.08.2009 19:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
CVE-2009-1721
- EPSS 25.35%
- Veröffentlicht 31.07.2009 19:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...
CVE-2009-2408
- EPSS 1.48%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
CVE-2009-1895
- EPSS 0.06%
- Veröffentlicht 16.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to l...
CVE-2009-1891
- EPSS 18.85%
- Veröffentlicht 10.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).