CVE-2009-2474
- EPSS 0.6%
- Veröffentlicht 21.08.2009 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers vi...
CVE-2009-2848
- EPSS 0.08%
- Veröffentlicht 18.08.2009 21:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone ...
CVE-2009-2416
- EPSS 0.5%
- Veröffentlicht 11.08.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute...
- EPSS 1.25%
- Veröffentlicht 06.08.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop a...
CVE-2009-1721
- EPSS 25.35%
- Veröffentlicht 31.07.2009 19:00:01
- Zuletzt bearbeitet 23.04.2026 00:35:47
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of a...
CVE-2009-2472
- EPSS 0.7%
- Veröffentlicht 22.07.2009 18:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, re...
CVE-2009-1891
- EPSS 18.85%
- Veröffentlicht 10.07.2009 15:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
CVE-2009-1890
- EPSS 37.87%
- Veröffentlicht 05.07.2009 16:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which al...
CVE-2009-1837
- EPSS 2.18%
- Veröffentlicht 12.06.2009 21:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading,...
CVE-2009-1955
- EPSS 2.33%
- Veröffentlicht 08.06.2009 01:00:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via ...