Severity: MEDIUM

84400 CVEs found

CVE-2009-2216
6.1 MEDIUM

Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.

Published: 2009-06-25
Products: 1
Vendors:
directadmin
CVE-2009-1388
5.5 MEDIUM

The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of servi...

Published: 2009-07-05
Products: 1
Vendors:
linux
CVE-2009-2408
5.9 MEDIUM

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the s...

Published: 2009-07-30
Products: 12
Vendors:
mozilla canonical suse debian opensuse
CVE-2009-2416
6.5 MEDIUM

Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via...

Published: 2009-08-11
Products: 38
Vendors:
vmware redhat xmlsoft apple canonical +6 more
CVE-2009-2857
5.5 MEDIUM

The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to caus...

Published: 2009-08-19
Products: 4
Vendors:
oracle
CVE-2009-3022
6.5 MEDIUM

Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change conten...

Published: 2009-08-31
Products: 2
Vendors:
itd-inc
CVE-2009-3238
5.5 MEDIUM

The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat p...

Published: 2009-09-18
Products: 8
Vendors:
linux canonical opensuse suse
CVE-2009-3278
5.5 MEDIUM

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to deter...

Published: 2009-09-21
Products: 8
Vendors:
qnap
CVE-2009-3621
5.5 MEDIUM

net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutd...

Published: 2009-10-22
Products: 15
Vendors:
vmware linux canonical suse fedoraproject +1 more
CVE-2009-4053
6.5 MEDIUM

Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (...

Published: 2009-11-23
Products: 1
Vendors:
home_ftp_server_project
CVE-2009-3897
5.5 MEDIUM

Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, r...

Published: 2009-11-24
Products: 1
Vendors:
dovecot
CVE-2009-4449
6.5 MEDIUM

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine th...

Published: 2009-12-29
Products: 1
Vendors:
mybb
CVE-2010-0467
5.8 MEDIUM

Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a...

Published: 2010-02-02
Products: 2
Vendors:
chillcreations joomla
CVE-2009-3960
6.5 MEDIUM

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8....

Published: 2010-02-15
Products: 12
Vendors:
adobe
CVE-2010-0629
6.5 MEDIUM

Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via...

Published: 2010-04-07
Products: 8
Vendors:
canonical suse fedoraproject mit opensuse
CVE-2010-0738
5.3 MEDIUM

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for th...

Published: 2010-04-28
Products: 2
Vendors:
redhat
CVE-2010-1282
6.5 MEDIUM

Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted ATOM size in a .dir (aka Director) file.

Published: 2010-05-13
Products: 3
Vendors:
apple microsoft adobe
CVE-2010-1637
6.5 MEDIUM

The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3...

Published: 2010-06-22
Products: 9
Vendors:
fedoraproject redhat apple squirrelmail
CVE-2010-2249
6.5 MEDIUM

Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing ma...

Published: 2010-06-30
Products: 24
Vendors:
vmware canonical fedoraproject suse apple +3 more
CVE-2009-4895
4.7 MEDIUM

Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or po...

Published: 2010-09-08
Products: 8
Vendors:
linux debian canonical