- EPSS 1.96%
- Veröffentlicht 10.09.2009 21:30:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
The WebKit component in Safari in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not remove usernames and passwords from URLs sent in Referer headers, which allows remote attackers to obtain sensitive information by readi...
CVE-2009-3001
- EPSS 0.09%
- Veröffentlicht 28.08.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC...
CVE-2009-3002
- EPSS 0.3%
- Veröffentlicht 28.08.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to th...
CVE-2009-2698
- EPSS 26.12%
- Veröffentlicht 27.08.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vecto...
CVE-2009-2474
- EPSS 0.6%
- Veröffentlicht 21.08.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers vi...
CVE-2009-2848
- EPSS 0.08%
- Veröffentlicht 18.08.2009 21:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2416
- EPSS 0.5%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 1.25%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...
CVE-2009-1721
- EPSS 25.35%
- Veröffentlicht 31.07.2009 19:00:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...
CVE-2009-2408
- EPSS 1.86%
- Veröffentlicht 30.07.2009 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certif...