CVE-2009-3094
- EPSS 8.57%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:55
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a mal...
- EPSS 12.56%
- Veröffentlicht 08.09.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:10:55
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as...
CVE-2009-2692
- EPSS 14.63%
- Veröffentlicht 14.08.2009 15:16:27
- Zuletzt bearbeitet 16.06.2026 23:10:01
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using ...
CVE-2009-2416
- EPSS 1.81%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:24
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 30.38%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:51
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...
CVE-2009-2687
- EPSS 4.38%
- Veröffentlicht 05.08.2009 19:30:01
- Zuletzt bearbeitet 16.06.2026 23:10:00
The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.
CVE-2009-1721
- EPSS 4.29%
- Veröffentlicht 31.07.2009 19:00:01
- Zuletzt bearbeitet 16.06.2026 23:07:54
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...
CVE-2009-2408
- EPSS 5.74%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:09:22
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...
CVE-2009-1895
- EPSS 0.44%
- Veröffentlicht 16.07.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:18
The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to l...
CVE-2009-1891
- EPSS 17.11%
- Veröffentlicht 10.07.2009 15:30:00
- Zuletzt bearbeitet 16.06.2026 23:08:17
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).