CVE Cross Reference 2009

The information on this page may be obsolete. For the current documentation, please log into the mySAINT portal using your customer login and password.

Current CVEs

  CVE # CVE Description SAINT®® Tutorial SAINT®® Vuln. ID SANS Top 20
YELLOW CVE-2009-0001 Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0002 Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0003 Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0004 Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0005 Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0006 Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0007 Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0008 Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0009 Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0010 Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0011 Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0012 Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0013 dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0014 Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0015 Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0016 Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header. iTunes vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_itunes  
YELLOW CVE-2009-0017 csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0018 The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0019 Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0020 Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0021 NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
BROWN CVE-2009-0022 Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name. Samba vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
win_samba  
RED CVE-2009-0023 The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow. MacOSX vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_server_apache_version
 
YELLOW CVE-2009-0024 The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-0025 BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. DNS vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_bindver
misc_macosx_version
 
YELLOW CVE-2009-0027 The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request. JBoss Application Server

Note: Authentication is required to detect this vulnerability
web_dev_jbossasver  
YELLOW CVE-2009-0028 The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0030 A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists and configuration data in opportunistic circumstances by using the standard webmail.php interface. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3663. SquirrelMail vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel  
YELLOW CVE-2009-0031 Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree." Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0032 CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
RED CVE-2009-0033 Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header. VMWare ESX vulnerabilities
MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_esxbuild
misc_macosx_version
web_dev_tomcatver
 
RED CVE-2009-0034 parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-0037 The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL. MacOSX vulnerabilities
HP SMH vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_tool_hpsmh
 
YELLOW CVE-2009-0040 The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables. libpng vulnerabilities
MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_libpng
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-0041 IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. Asterisk vulnerabilities

Note: Authentication is required to detect this vulnerability
net_asterisk  
YELLOW CVE-2009-0042 Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file. CA Antivirus engine vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_caver  
YELLOW CVE-2009-0063 Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. Brightmail Control Center vulnerabilities
mail_misc_brightmailxss  
YELLOW CVE-2009-0064 Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions. Brightmail Control Center vulnerabilities
mail_misc_brightmailxss  
RED CVE-2009-0065 Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0075 Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-0076 Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v7
win_patch_ie_v8
 
RED CVE-2009-0077 The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability." Microsoft ISA Server

Note: Authentication is required to detect this vulnerability
web_proxy_isa_tcpstatedos  
YELLOW CVE-2009-0078 The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_msdtc  
YELLOW CVE-2009-0079 The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_msdtc  
YELLOW CVE-2009-0080 The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_msdtc  
YELLOW CVE-2009-0081 The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kernelgdi  
YELLOW CVE-2009-0082 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kernelgdi  
YELLOW CVE-2009-0083 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kernelgdi  
YELLOW CVE-2009-0084 Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later accessed, aka "MJPEG Decompression Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_directxrce09011  
YELLOW CVE-2009-0085 The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_schannelspoof  
YELLOW CVE-2009-0086 Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_winhttpund  
YELLOW CVE-2009-0087 Unspecified vulnerability in the Word 6 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and the Word 6 text converter in Microsoft Office Word 2000 SP3 and 2002 SP3; allows remote attackers to execute arbitrary code via a crafted Word 6 file that contains malformed data, aka "WordPad and Office Text Converter Memory Corruption Vulnerability." Microsoft Office vulnerabilities
Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_2000conv97
win_patch_2002conv97
win_patch_word6
 
YELLOW CVE-2009-0088 The WordPerfect 6.x Converter (WPFT632.CNV, 1998.1.27.0) in Microsoft Office Word 2000 SP3 and Microsoft Office Converter Pack does not properly validate the length of an unspecified string, which allows remote attackers to execute arbitrary code via a crafted WordPerfect 6.x file, related to an unspecified counter and control structures on the stack, aka "Word 2000 WordPerfect 6.x Converter Stack Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_2000conv97  
YELLOW CVE-2009-0089 Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Vista Gold allows remote web servers to impersonate arbitrary https web sites by using DNS spoofing to "forward a connection" to a different https web site that has a valid certificate matching its own domain name, but not a certificate matching the domain name of the host requested by the user, aka "Windows HTTP Services Certificate Name Mismatch Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_winhttpund  
YELLOW CVE-2009-0090 Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Pointer Verification Vulnerability." Microsoft Silverlight vulnerabilities
Microsoft NET Framework

Note: Authentication is required to detect this vulnerability
misc_silverlightver
win_dotnet1
 
YELLOW CVE-2009-0091 Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "Microsoft .NET Framework Type Verification Vulnerability." Microsoft Silverlight vulnerabilities
Microsoft NET Framework

Note: Authentication is required to detect this vulnerability
misc_silverlightver
win_dotnet1
 
YELLOW CVE-2009-0093 Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692. Windows DNS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_dnsspoof  
YELLOW CVE-2009-0094 The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692. WINS vulnerability

Note: Authentication is required to detect this vulnerability
win_patch_winsspoof  
YELLOW CVE-2009-0095 Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly validate object data in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Validation Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_visio2002
win_patch_visio2003
win_patch_visio2003vislib
win_patch_visio2007
 
YELLOW CVE-2009-0096 Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 does not properly perform memory copy operations for object data, which allows remote attackers to execute arbitrary code via a crafted Visio document, aka "Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_visio2002
win_patch_visio2003
win_patch_visio2003vislib
win_patch_visio2007
 
YELLOW CVE-2009-0097 Microsoft Office Visio 2002 SP2 and 2003 SP3 does not properly validate memory allocation for Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_visio2002
win_patch_visio2003
win_patch_visio2003vislib
 
RED CVE-2009-0098 Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability." Microsoft Exchange vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_smtp_exchangeiurc  
RED CVE-2009-0099 The Electronic Messaging System Microsoft Data Base (EMSMDB32) provider in Microsoft Exchange 2000 Server SP3 and Exchange Server 2003 SP2, as used in Exchange System Attendant, allows remote attackers to cause a denial of service (application outage) via a malformed MAPI command, aka "Literal Processing Vulnerability." Microsoft Exchange vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_smtp_exchangesados  
YELLOW CVE-2009-0100 Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel in Microsoft Office 2004 and 2008 for Mac; Microsoft Office Excel Viewer and Excel Viewer 2003 SP3; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 do not properly parse the Excel spreadsheet file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that contains a malformed object with "an offset and a two-byte value" that trigger a memory calculation error, aka "Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-0102 Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Project files, which allows remote attackers to execute arbitrary code via a malformed file, aka "Project Memory Validation Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_project_2000
win_patch_project_2002
win_patch_project_2003
 
YELLOW CVE-2009-0114 Unspecified vulnerability in the Settings Manager in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87, and possibly other versions, allows remote attackers to trick a user into visiting an arbitrary URL via unknown vectors, related to "a potential Clickjacking issue variant." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-0123 Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to read arbitrary files on a client machine via vectors related to the association of Safari with the (1) feed, (2) feeds, and (3) feedsearch URL types for RSS feeds. NOTE: as of 20090114, the only disclosure is a vague pre-advisory. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-0137 Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0138 servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0139 Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0140 Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0141 XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0142 Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0143 Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast. iTunes vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_itunes  
YELLOW CVE-2009-0144 CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0145 CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption. MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-0146 Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2SymbolDict::setBitmap and (2) JBIG2Stream::readSymbolDictSeg. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0147 Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) JBIG2Stream::readSymbolDictSeg, (2) JBIG2Stream::readSymbolDictSeg, and (3) JBIG2Stream::readGenericBitmap. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0148 Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0149 Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0150 Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
BROWN CVE-2009-0152 iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0153 International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode conversion, which might allow remote attackers to conduct cross-site scripting (XSS) attacks. MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-0154 Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0155 Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers a heap-based buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0156 Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0157 Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0158 Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-0159 Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response. VMWare ESX vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_macosx_version
 
YELLOW CVE-2009-0160 QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0161 The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0162 Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-0163 Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow. CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
YELLOW CVE-2009-0164 The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks. MacOSX vulnerabilities
CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
printer_cupsversion
 
YELLOW CVE-2009-0165 Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-0172 Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream. DB2 vulnerabilities
database_db2ver  
RED CVE-2009-0173 Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a crafted data stream. DB2 vulnerabilities
database_db2ver  
RED CVE-2009-0176 Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps." BlackBerry vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_blackberry_pdfdistiller  
RED
!
CVE-2009-0177 vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command. VMware vulnerabilities
VMware authd vulnerabilities

Note: Authentication is required to detect this vulnerability unless dangerous checks are enabled
misc_vmware_acever
misc_vmware_authd
misc_vmware_serverver
misc_vmwareauthddos
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED
!
CVE-2009-0183 Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request. Free Download Manager vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
misc_freedownloadmanagerbo  
YELLOW CVE-2009-0184 Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file. Free Download Manager vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_freedownloadmanagerver  
YELLOW CVE-2009-0186 Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow. Winamp vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_winamplibsndfile  
YELLOW CVE-2009-0187 Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message. Orbit Downloader vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_orbitdownloaderver  
RED CVE-2009-0192 Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow. Novell eDirectory HTTP

Note: Authentication is required to detect this vulnerability
web_tool_edirectoryimon  
YELLOW CVE-2009-0193 Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a PDF file with a malformed JBIG2 symbol dictionary segment, a different vulnerability than CVE-2009-1061 and CVE-2009-1062. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
RED CVE-2009-0195 Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers to execute arbitrary code via a PDF file with crafted JBIG2 symbol dictionary segments. CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
YELLOW CVE-2009-0198 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF file that contains JBIG2 text region segments with Huffman encoding. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0199 Heap-based buffer overflow in the VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows might allow remote attackers to execute arbitrary code via a video file with crafted dimensions (aka framebuffer parameters). VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-0200 Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice
misc_openofficewin2
 
YELLOW CVE-2009-0201 Heap-based buffer overflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via unspecified records in a crafted Word document, related to "table parsing." OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openofficewin2  
YELLOW CVE-2009-0215 Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors. IBM Access Support vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_ibmasax  
YELLOW CVE-2009-0217 The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits. Oracle vulnerabilities
Microsoft NET Framework

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias
win_dotnet2
 
RED CVE-2009-0219 The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file. BlackBerry vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_blackberry_pdfdistiller  
YELLOW CVE-2009-0220 Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a PowerPoint 4.0 native file format, related to (1) an incorrect calculation from a record header, or (2) an interget that is used to specify the number of bytes to copy, aka "Legacy File Format Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-0221 Integer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a PowerPoint file containing a crafted record type for "collaboration information for different slides" that contains a field that specifies a large number of records, which triggers an under-allocated buffer and a heap-based buffer overflow, aka "Integer Overflow Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-0222 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0223, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-0223 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0226, CVE-2009-0227, and CVE-2009-1137. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-0224 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly validate PowerPoint files, which allows remote attackers to execute arbitrary code via multiple crafted BuildList records that include ChartBuild containers, which triggers memory corruption, aka "Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_ppt2007
win_patch_pptconv2007
win_patch_pptview2003
win_patch_pptview2007
win_patch_pptxp
 
YELLOW CVE-2009-0225 Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_pptxp  
YELLOW CVE-2009-0226 Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0227, and CVE-2009-1137. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-0227 Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-1137. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
RED CVE-2009-0228 Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a crafted ShareName in a response to an RPC request, related to "printing data structures," aka "Buffer Overflow in Print Spooler Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_printspool  
YELLOW CVE-2009-0229 The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_printspool  
YELLOW CVE-2009-0230 The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an arbitrary directory, aka "Print Spooler Load Library Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_printspool  
YELLOW CVE-2009-0231 The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_opentype  
YELLOW CVE-2009-0232 Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table, aka "Embedded OpenType Font Integer Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_opentype  
YELLOW CVE-2009-0233 The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability." Windows DNS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_dnsspoof  
YELLOW CVE-2009-0234 The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability." Windows DNS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_dnsspoof  
YELLOW CVE-2009-0235 Stack-based buffer overflow in the Word 97 text converter in WordPad in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Word 97 file that triggers memory corruption, related to use of inconsistent integer data sizes for an unspecified length field, aka "WordPad Word 97 Text Converter Stack Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_word97  
YELLOW CVE-2009-0237 Cross-site scripting (XSS) vulnerability in cookieauth.dll in the HTML forms authentication component in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2006, 2006 Supportability Update, and 2006 SP1; allows remote attackers to inject arbitrary web script or HTML via "authentication input" to this component, aka "Cross-Site Scripting Vulnerability." Microsoft ISA Server

Note: Authentication is required to detect this vulnerability
web_proxy_isa_tcpstatedos  
YELLOW CVE-2009-0238 Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an invalid object, as exploited in the wild in February 2009 by Trojan.Mdropper.AC. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-0239 Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_winsearch  
RED
!
CVE-2009-0241 Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname. Ganglia Meta Daemon vulnerabilities
misc_gangliametabo  
YELLOW CVE-2009-0263 Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file. Winamp vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_winamp  
YELLOW CVE-2009-0265 Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025. DNS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_bindver  
YELLOW CVE-2009-0269 fs/ecryptfs/inode.c in the eCryptfs subsystem in the Linux kernel before 2.6.28.1 allows local users to cause a denial of service (fault or memory corruption), or possibly have unspecified other impact, via a readlink call that results in an error, leading to use of a -1 return value as an array index. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-0270 Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execute arbitrary code via a large PXE protocol request in a UDP packet. Fujitsu SystemcastWizard vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_fujitsusystemcastwizard  
YELLOW CVE-2009-0276 Cross-domain vulnerability in the V8 JavaScript engine in Google Chrome before 1.0.154.46 allows remote attackers to bypass the Same Origin Policy via a crafted script that accesses another frame and reads its full URL and possibly other sensitive information, or modifies the URL of this frame. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-0298 Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property. MW6 Barcode vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_mw6barcodeax  
YELLOW CVE-2009-0305 Multiple stack-based buffer overflows in the Research in Motion RIM AxLoader ActiveX control in AxLoader.ocx and AxLoader.dll in BlackBerry Application Web Loader 1.0 allow remote attackers to execute arbitrary code via unspecified use of the (1) load or (2) loadJad method. BlackBerry Application Web Loader vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_blackberry_webloaderax  
YELLOW CVE-2009-0306 Buffer overflow in the IBM Lotus Notes Intellisync ActiveX control in lnresobject.dll in BlackBerry Desktop Manager in Research In Motion (RIM) BlackBerry Desktop Software before 5.0.1 allows remote attackers to execute arbitrary code via a crafted web page. NOTE: some of these details are obtained from third party information. BlackBerry vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_blackberry_lotusnotesax  
YELLOW CVE-2009-0316 Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair. Vim vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_editors_vim_pysys
misc_macosx_version
 
YELLOW CVE-2009-0321 Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-0322 drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0347 Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter. Ultraseek vulnerabilities
web_tool_ultraseekredirect  
RED
!
CVE-2009-0351 Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character. WinFTP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
ftp_winftplistbo  
YELLOW CVE-2009-0352 Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0353 Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0354 Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-0355 components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-0356 Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs. NOTE: this issue exists because of an incomplete fix for CVE-2008-4582. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-0357 Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0358 Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-0375 Buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a filename length field containing a large integer, which triggers overwrite of an arbitrary memory location with a 0x00 byte value, related to use of RealPlayer through a Windows Explorer plugin. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_realplayercategory_ivr  
RED CVE-2009-0388 Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp. VNC detected

Note: Authentication is required to detect this vulnerability
misc_vncview  
RED
!
CVE-2009-0410 Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow. Novell GroupWise vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
mail_smtp_gwiarcptbo  
YELLOW CVE-2009-0411 Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls and other web script. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
BROWN CVE-2009-0432 The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enable the secure version, which allows remote attackers to obtain sensitive information via unspecified vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0433 Unspecified vulnerability in IBM WebSphere Application Server (WAS) 5.1.x before 5.1.1.19, 6.0.x before 6.0.2.29, and 6.1.x before 6.1.0.19, when Web Server plug-in content buffering is enabled, allows attackers to cause a denial of service (daemon crash) via unknown vectors, related to a mishandling of client read failures in which clients receive many 500 HTTP error responses and backend servers are incorrectly labeled as down. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0434 PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.31, 6.1.x before 6.1.0.21, and 7.0.x before 7.0.0.1, when Performance Monitoring Infrastructure (PMI) is enabled, allows local users to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2008-5413. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0435 Unspecified vulnerability in the IBM Asynchronous I/O (aka AIO or libibmaio) library in the Java Message Service (JMS) component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.17 on AIX 5.3 allows attackers to cause a denial of service (daemon crash) via vectors related to the aio_getioev2 and getEvent methods. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0436 The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0437 The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on Windows, when WAS is registered as a Windows service, allows local users to obtain sensitive information by reading the logs/instconfigifwas6.log log file. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0438 IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive information from JSP pages via a crafted request. NOTE: this is probably a duplicate of CVE-2008-5412. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
YELLOW CVE-2009-0449 Buffer overflow in klim5.sys in Kaspersky Anti-Virus for Workstations 6.0 and Anti-Virus 2008 allows local users to gain privileges via an IOCTL 0x80052110 call. Kaspersky AntiVirus vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_kaspersky_avver
misc_av_kaspersky_avworkver
 
BROWN CVE-2009-0470 Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 12.4(23) allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) level/15/exec/-/ or (2) exec/, a different vulnerability than CVE-2008-3821. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0471 Cross-site request forgery (CSRF) vulnerability in the HTTP server in Cisco IOS 12.4(23) allows remote attackers to execute arbitrary commands, as demonstrated by executing the hostname command with a level/15/configure/-/hostname request. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
RED
!
CVE-2009-0478 Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c. Squid vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
web_proxy_squid
web_proxy_squidhttpbo
 
BROWN CVE-2009-0486 Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users. Bugzilla vulnerabilities
web_prog_cgi_bugzilla  
YELLOW CVE-2009-0488 Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Phorum vulnerabilities
web_prog_php_phorumver  
YELLOW CVE-2009-0497 Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter. Openfire Jabber Server vulnerabilities
misc_openfirejabberver  
BROWN CVE-2009-0504 WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0508 The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
YELLOW CVE-2009-0509 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows remote attackers to execute arbitrary code via a crafted file that triggers memory corruption. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0510 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0511, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0511 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0512, CVE-2009-0888, and CVE-2009-0889. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0512 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0888, and CVE-2009-0889. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0519 Unspecified vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a crafted Shockwave Flash (aka .swf) file. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-0520 Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed objects during Shockwave Flash file processing, which allows remote attackers to execute arbitrary code via a crafted file, related to a "buffer overflow issue." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-0521 Untrusted search path vulnerability in Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Linux allows local users to obtain sensitive information or gain privileges via a crafted library in a directory contained in the RPATH. Flash vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash  
YELLOW CVE-2009-0522 Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 on Windows allows remote attackers to trick a user into visiting an arbitrary URL via an unspecified manipulation of the "mouse pointer display," related to a "Clickjacking attack." Flash vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash  
RED CVE-2009-0542 SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql. ProFTPD vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
ftp_proftp  
YELLOW CVE-2009-0547 Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to the user, which allows remote attackers to spoof a signature by modifying the latter copy, a different vulnerability than CVE-2008-5077. GNOME Evolution vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_evolution  
YELLOW CVE-2009-0549 Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; and Microsoft Office Excel Viewer 2003 SP3 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Record Pointer Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excel2003
win_patch_excelview
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-0550 Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008; and WinINet in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008; allows remote web servers to capture and replay NTLM credentials, and execute arbitrary code, via vectors related to absence of a "credential-reflection protections" opt-in step, aka "Windows HTTP Services Credential Reflection Vulnerability" and "WinINet Credential Reflection Vulnerability." Internet Explorer vulnerabilities
Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
win_patch_winhttpund
 
YELLOW CVE-2009-0551 Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka "Page Transition Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-0552 Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 on Windows XP SP2 and SP3, and 6 on Windows Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
 
YELLOW CVE-2009-0553 Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-0554 Microsoft Internet Explorer 5.01 SP4, 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 allows remote attackers to execute arbitrary code via a web page that triggers presence of an object in memory that was (1) not properly initialized or (2) deleted, aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-0555 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted audio file that uses the Windows Media Speech codec, aka "Windows Media Runtime Voice Sample Rate Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmacodec  
YELLOW CVE-2009-0556 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
CHECKMARK
YELLOW CVE-2009-0557 Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-0558 Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-0559 Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "String Copy Stack-Based Overrun Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excelxp
 
YELLOW CVE-2009-0560 Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-0561 Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Microsoft Office SharePoint Server 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via an Excel file with a Shared String Table (SST) record with a numeric field that specifies an invalid number of unique strings, which triggers a heap-based buffer overflow, aka "Record Integer Overflow Vulnerability." Microsoft Office vulnerabilities
Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_excel2000
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
win_patch_sharepoint2007
 
YELLOW CVE-2009-0562 The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 does not properly allocate memory, which allows remote attackers to execute arbitrary code via unspecified vectors that trigger "system state" corruption, aka "Office Web Components Memory Allocation Vulnerability." Office Web Components vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_owcrce  
YELLOW CVE-2009-0563 Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_office2004macver
win_patch_office2008macver
win_patch_word2003
win_patch_word2007
win_patch_wordcompack
win_patch_wordview2003
win_patch_wordxp
 
YELLOW CVE-2009-0565 Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a malformed record that triggers memory corruption, aka "Word Buffer Overflow Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_office2004macver
win_patch_office2008macver
win_patch_word2000
win_patch_word2007
win_patch_wordcompack
win_patch_wordxp
 
YELLOW CVE-2009-0566 Microsoft Office Publisher 2007 SP1 does not properly calculate object handler data for Publisher files, which allows remote attackers to execute arbitrary code via a crafted file in a legacy format that triggers memory corruption, aka "Pointer Dereference Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_publisher2007  
YELLOW CVE-2009-0568 The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_rpcmarshall  
RED CVE-2009-0580 Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter. VMWare ESX vulnerabilities
MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_esxbuild
misc_macosx_version
web_dev_tomcatver
 
YELLOW CVE-2009-0588 agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field. Red Hat Certificate System vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_redhatcsraver  
RED CVE-2009-0590 The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length. MacOSX vulnerabilities
OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
misc_openssl
 
BROWN CVE-2009-0591 The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid. MacOSX vulnerabilities
OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
misc_openssl
 
RED CVE-2009-0599 Buffer overflow in wiretap/netscreen.c in Wireshark 0.99.7 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed NetScreen snoop file. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-0600 Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted Tektronix K12 text capture file, as demonstrated by a file with exactly one frame. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-0601 Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on non-Windows platforms allows local users to cause a denial of service (application crash) via format string specifiers in the HOME environment variable. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-0604 SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter. PHP director vulnerabilities
web_prog_php_director  
YELLOW CVE-2009-0605 Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0611 Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter. Novell QuickFinder Server vulnerabilities
web_tool_novellquickfinderxss  
RED CVE-2009-0620 Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers before A2(1.1) uses default (1) usernames and (2) passwords for (a) the administrator and (b) web management, which makes it easier for remote attackers to perform configuration changes or obtain operating-system access. default device password
net_password  
RED CVE-2009-0621 Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device management, which makes it easier for remote attackers to perform configuration changes to the Device Manager and other components, or obtain operating-system access. default device password
net_password  
BROWN CVE-2009-0626 The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0627 Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0629 The (1) Airline Product Set (aka ALPS), (2) Serial Tunnel Code (aka STUN), (3) Block Serial Tunnel Code (aka BSTUN), (4) Native Client Interface Architecture (NCIA) support, (5) Data-link switching (aka DLSw), (6) Remote Source-Route Bridging (RSRB), (7) Point to Point Tunneling Protocol (PPTP), (8) X.25 for Record Boundary Preservation (RBP), (9) X.25 over TCP (XOT), and (10) X.25 Routing features in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (device reload) via a series of crafted TCP packets. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0630 The (1) Cisco Unified Communications Manager Express; (2) SIP Gateway Signaling Support Over Transport Layer Security (TLS) Transport; (3) Secure Signaling and Media Encryption; (4) Blocks Extensible Exchange Protocol (BEEP); (5) Network Admission Control HTTP Authentication Proxy; (6) Per-user URL Redirect for EAPoUDP, Dot1x, and MAC Authentication Bypass; (7) Distributed Director with HTTP Redirects; and (8) TCP DNS features in Cisco IOS 12.0 through 12.4 do not properly handle IP sockets, which allows remote attackers to cause a denial of service (outage or resource consumption) via a series of crafted TCP packets. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0631 Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when configured with (1) IP Service Level Agreements (SLAs) Responder, (2) Session Initiation Protocol (SIP), (3) H.323 Annex E Call Signaling Transport, or (4) Media Gateway Control Protocol (MGCP) allows remote attackers to cause a denial of service (blocked input queue on the inbound interface) via a crafted UDP packet. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
RED CVE-2009-0632 The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x. Cisco voice products

Note: Authentication is required to detect this vulnerability
net_cisco_cucmver  
BROWN CVE-2009-0633 Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0634 Multiple unspecified vulnerabilities in the home agent (HA) implementation in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via an ICMP packet, aka Bug ID CSCso05337. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0635 Memory leak in the Cisco Tunneling Control Protocol (cTCP) encapsulation feature in Cisco IOS 12.4, when an Easy VPN (aka EZVPN) server is enabled, allows remote attackers to cause a denial of service (memory consumption and device crash) via a sequence of TCP packets. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0636 Unspecified vulnerability in Cisco IOS 12.0 through 12.4, when SIP voice services are enabled, allows remote attackers to cause a denial of service (device crash) via a valid SIP message. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-0637 The SCP server in Cisco IOS 12.2 through 12.4, when Role-Based CLI Access is enabled, does not enforce the CLI view configuration for file transfers, which allows remote authenticated users with an attached CLI view to (1) read or (2) overwrite arbitrary files via an SCP command. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
YELLOW CVE-2009-0647 msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown. MSN Messenger vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_msnmessengerver  
YELLOW CVE-2009-0652 The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0658 Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
BROWN CVE-2009-0668 Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol. Zope vulnerabilities
web_dev_zope  
BROWN CVE-2009-0669 Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol. Zope vulnerabilities
web_dev_zope  
YELLOW CVE-2009-0676 The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0681 PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys. PGP Desktop vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_pgpdesktopver  
YELLOW CVE-2009-0686 The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory. Trend Micro vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_trendmicro_istmactmon  
RED CVE-2009-0688 Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c. Cyrus SASL vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_cyrussasl
misc_macosx_version
 
YELLOW CVE-2009-0689 Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number. MacOSX vulnerabilities
Mozilla vulnerabilities
Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_firefox
web_client_googlechrome
 
RED CVE-2009-0692 Stack-based buffer overflow in the script_write_params method in client/dhclient.c in ISC DHCP dhclient 4.1 before 4.1.0p1, 4.0 before 4.0.1p1, 3.1 before 3.1.2p1, 3.0, and 2.0 allows remote DHCP servers to execute arbitrary code via a crafted subnet-mask option. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-0696 The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message. DNS vulnerabilities
VMWare ESX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_bindver
misc_esxbuild
 
YELLOW CVE-2009-0737 Multiple cross-site scripting (XSS) vulnerabilities in the web-based installer (config/index.php) in MediaWiki 1.6 before 1.6.12, 1.12 before 1.12.4, and 1.13 before 1.13.4, when the installer is in active use, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. MediaWiki vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_mediawiki  
YELLOW CVE-2009-0744 Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (caret), (5) ` (backquote), or (6) | (pipe) character, followed by an & (ampersand) character. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-0771 The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0772 The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0773 The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0774 The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0775 Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0776 nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-0777 Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
RED CVE-2009-0778 The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak." Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-0781 Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." VMWare ESX vulnerabilities
MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_esxbuild
misc_macosx_version
web_dev_tomcatver
 
RED CVE-2009-0783 Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application. VMWare ESX vulnerabilities
MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_esxbuild
misc_macosx_version
web_dev_tomcatver
 
YELLOW CVE-2009-0787 The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-0789 OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the public key of a certificate, as demonstrated by an RSA public key. MacOSX vulnerabilities
OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
misc_openssl
 
RED CVE-2009-0791 Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179. CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
YELLOW CVE-2009-0796 Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI. MacOSX vulnerabilities
Apache module vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_mod_perlver
 
BROWN CVE-2009-0801 Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header. Squid vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_proxy_squid  
YELLOW CVE-2009-0819 sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure. MySQL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version  
YELLOW CVE-2009-0834 The audit_syscall_entry function in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass certain syscall audit configurations via crafted syscalls, a related issue to CVE-2009-0342 and CVE-2009-0343. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0835 The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-0844 The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote attackers to cause a denial of service (daemon crash) and possibly obtain sensitive information via a crafted length value that triggers a buffer over-read. VMWare ESX vulnerabilities
Kerberos detected
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_kerberospkg
misc_macosx_version
 
RED CVE-2009-0845 The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token. VMWare ESX vulnerabilities
Kerberos detected
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_kerberospkg
misc_macosx_version
 
RED
!
CVE-2009-0846 The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. VMWare ESX vulnerabilities
Kerberos detected
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability unless dangerous checks are enabled
misc_esxbuild
misc_kerberospkg
misc_krb5asnus
misc_macosx_version
 
RED CVE-2009-0847 The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic. Kerberos detected
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_kerberospkg
misc_macosx_version
 
YELLOW CVE-2009-0850 Cross-site scripting (XSS) vulnerability in BitDefender Internet Security 2009 allows user-assisted remote attackers to inject arbitrary web script or HTML via the filename of a virus-infected file, as demonstrated by a filename inside a (1) rar or (2) zip archive file. Bit Defender vulnerability

Note: Authentication is required to detect this vulnerability
misc_av_bitdefenderinternet  
YELLOW CVE-2009-0855 Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. WebSphere vulnerabilities
web_dev_webspherexss  
YELLOW CVE-2009-0856 Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. WebSphere vulnerabilities
web_dev_webspherexss  
BROWN CVE-2009-0859 The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED
!
CVE-2009-0879 The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI. IBM Director vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
web_tool_ibmdirectorcimdos  
RED CVE-2009-0884 Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets. FileZilla server vulnerabilities
ftp_filezilla  
YELLOW CVE-2009-0888 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0512, and CVE-2009-0889. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0889 Heap-based buffer overflow in the JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-0510, CVE-2009-0511, CVE-2009-0512, and CVE-2009-0888. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
BROWN CVE-2009-0891 The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0892 The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
RED CVE-2009-0895 Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow. Novell eDirectory

Note: Authentication is required to detect this vulnerability
misc_edirectoryver  
BROWN CVE-2009-0899 IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
YELLOW CVE-2009-0901 The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClear calls on an uninitialized VARIANT, which allows remote attackers to execute arbitrary code via a malformed stream to an ATL (1) component or (2) control, related to ATL headers and error handling, aka "ATL Uninitialized Object Vulnerability." Flash vulnerabilities
Visual Studio vulnerabilities
Windows updates needed
Microsoft outlook vulnerabilities
Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_vstudioatl
win_patch_atl
win_patch_dhtmlatl
win_patch_msoutlook09037
win_patch_office2002atl
win_patch_office2003atl
win_patch_office2007atl
win_patch_visioatl
win_patch_wmpatl
 
BROWN CVE-2009-0903 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-0904 The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XML encoding, which allows remote attackers to bypass intended access restrictions and possibly modify data via "XML fuzzing attacks" sent through SOAP requests. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
RED CVE-2009-0908 Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever  
YELLOW CVE-2009-0909 Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-0910 Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-0914 Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-0915 Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-0916 Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue." Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
RED
!
CVE-2009-0920 Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067. HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
net_ovnodemgrbo  
RED
!
CVE-2009-0921 Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww.so.4. HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
net_ovnodemgrlangbo  
YELLOW CVE-2009-0922 PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of service (stack consumption and crash) by triggering a failure in the conversion of a localized error message to a client-specified encoding, as demonstrated using mismatched encoding conversion requests. PostgreSQL vulnerabilities
HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_pgsql
net_ovnodemgriver
 
YELLOW CVE-2009-0927 Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0928 Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-0930 Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php. Horde IMP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_imp  
YELLOW CVE-2009-0931 Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Horde vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_horde  
YELLOW CVE-2009-0932 Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name. Horde vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_horde  
RED CVE-2009-0935 The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event list mutex to be unlocked twice and prevents proper synchronization of a data structure for the inotify instance. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-0942 Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0943 Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0944 The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0945 Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-0946 Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c. FreeType vulnerabilities
MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_lib_freetype
misc_macosx_version
web_client_safari
 
RED CVE-2009-0949 The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags. MacOSX vulnerabilities
CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
printer_cupsversion
 
YELLOW CVE-2009-0950 Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon. iTunes vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_itunes  
YELLOW CVE-2009-0954 Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region (CRGN) atom types. QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0955 Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue." QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_quicktime  
YELLOW CVE-2009-0967 The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument. Serv U vulnerabilities
ftp_servu  
BROWN CVE-2009-0973 Unspecified vulnerability in the Cluster Ready Services component in Oracle Database 10.1.0.5 allows remote attackers to affect availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0974 Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0983 and CVE-2009-3407. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
BROWN CVE-2009-0975 Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0978. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0976 Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to LTADM. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0977 Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the GRANT_TYPE_ACCESS procedure in the DBMS_AQADM_SYS package. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0978 Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0975. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0979 Unspecified vulnerability in the Resource Manager component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0980 Unspecified vulnerability in the SQLX Functions component in Oracle Database 10.2.0.3 and 11.1.0.6 allows remote authenticated users to affect integrity and availability, related to AGGXQIMP. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0981 Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated users to affect confidentiality, related to APEX. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue allows remote authenticated users to obtain APEX password hashes from the WWV_FLOW_USERS table via a SELECT statement. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0983 Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-3407. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
BROWN CVE-2009-0984 Unspecified vulnerability in the Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_SYS_SQL. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0985 Unspecified vulnerability in the Core RDBMS component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users with the IMP_FULL_DATABASE role to affect confidentiality, integrity, and availability. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0986 Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0987 Unspecified vulnerability in the Upgrade component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0988 Unspecified vulnerability in the Password Policy component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0991 Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-1970. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0992 Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_AQIN. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is SQL injection in the DEQ_EXEJOB procedure. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-0993 Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that allows remote attackers to execute arbitrary code via format string specifiers in an HTTP POST URI, which are not properly handled when logging to opmn/logs/opmn.log. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
BROWN CVE-2009-0997 Unspecified vulnerability in the Database Vault component in Oracle Database 11.1.0.6 allows remote authenticated users to affect confidentiality, related to DBMS_SYS_SQL. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1007 Unspecified vulnerability in the Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DMP_SYS. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1015 Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.05, and 10.2.04 allows remote authenticated users to affect integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1016 Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote authenticated users to affect confidentiality, integrity, and availability, related to IIS. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on claims from a reliable researcher that this is a stack-based buffer overflow involving an unspecified Server Plug-in and a crafted SSL certificate. WebLogic vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_weblogic  
BROWN CVE-2009-1018 Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LTRIC (WMSYS.LTRIC). Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1019 Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1020 Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1021 Unspecified vulnerability in the Advanced Replication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
YELLOW CVE-2009-1031 Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request. Serv U vulnerabilities
ftp_servu  
YELLOW CVE-2009-1042 Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1044 Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-1045 requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action. VLC vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vlc  
YELLOW CVE-2009-1046 The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1060 Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Charlie Miller during a PWN2OWN competition at CanSecWest 2009. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1061 Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to execute arbitrary code via unknown attack vectors related to JBIG2 and "input validation," a different vulnerability than CVE-2009-0193 and CVE-2009-1062. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1062 Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to trigger memory corruption and possibly execute arbitrary code via unknown attack vectors related to JBIG2, a different vulnerability than CVE-2009-0193 and CVE-2009-1061. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1064 Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method. Orbit Downloader vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_orbitdownloaderax  
YELLOW CVE-2009-1072 nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-1093 LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang). VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1094 Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1095 Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1096 Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1097 Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1098 Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1099 Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1100 Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1101 Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak." VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1102 Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation." VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1103 Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1104 The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1105 The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1106 The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-1107 The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
YELLOW CVE-2009-1122 The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535. IIS WebDAV vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_server_iis_webdavdir  
YELLOW CVE-2009-1123 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneldesktop  
YELLOW CVE-2009-1124 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate user-mode pointers in unspecified error conditions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Pointer Validation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneldesktop  
YELLOW CVE-2009-1125 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneldesktop  
YELLOW CVE-2009-1126 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneldesktop  
YELLOW CVE-2009-1127 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not correctly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application that triggers a NULL pointer dereference, aka "Win32k NULL Pointer Dereferencing Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneleotfont  
YELLOW CVE-2009-1128 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-1129 Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that uses a PowerPoint 95 (PPT95) native file format, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1128. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-1130 Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes PowerPoint to read more data than was allocated when creating a C++ object, leading to an overwrite of a function pointer, aka "Heap Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2003
win_patch_pptxp
 
YELLOW CVE-2009-1131 Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000  
RED CVE-2009-1132 Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wlansvc  
YELLOW CVE-2009-1133 Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified parameters, aka "Remote Desktop Connection Heap Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_rdc  
YELLOW CVE-2009-1134 Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malformed Qsir (0x806) record object, aka "Record Pointer Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
 
YELLOW CVE-2009-1135 Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, via vectors involving attempted access to a network resource behind the ISA Server, aka "Radius OTP Bypass Vulnerability." Microsoft ISA Server

Note: Authentication is required to detect this vulnerability
web_proxy_isa_authbypass  
YELLOW CVE-2009-1136 The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability." Office Web Components vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_owcrce CHECKMARK
YELLOW CVE-2009-1137 Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability," a different vulnerability than CVE-2009-0222, CVE-2009-0223, CVE-2009-0226, and CVE-2009-0227. Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ppt2000
win_patch_ppt2003
win_patch_pptxp
 
RED CVE-2009-1138 The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not released, related to a "DN AttributeValue," aka "Active Directory Invalid Free Vulnerability." NOTE: this issue is probably a memory leak. Active Directory vulnerability

Note: Authentication is required to detect this vulnerability
win_patch_activedirrs  
RED CVE-2009-1139 Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability." Active Directory vulnerability

Note: Authentication is required to detect this vulnerability
win_patch_activedirrs
win_patch_adamdos3
 
YELLOW CVE-2009-1140 Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-1141 Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trigger memory corruption when the window is destroyed, aka "DHTML Object Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6  
YELLOW CVE-2009-1146 Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-1147 Unspecified vulnerability in vmci.sys in the Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 2.0.x before 2.0.1 build 156745 allows local users to gain privileges via unknown vectors. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED CVE-2009-1151 Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action. phpMyAdmin vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_myadminver  
BROWN CVE-2009-1168 Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (memory corruption and device reload) by using an RFC4271 peer to send an update with a long series of AS numbers, aka Bug ID CSCsy86021. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_bgp  
YELLOW CVE-2009-1169 The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
BROWN CVE-2009-1172 The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-1173 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-1174 The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
RED CVE-2009-1178 Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line." Tivoli Storage Manager
misc_tivolicategory_storagever  
YELLOW CVE-2009-1179 Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
RED CVE-2009-1185 udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-1191 mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request. MacOSX vulnerabilities
Apache module vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_mod_proxyajp
 
YELLOW CVE-2009-1192 The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1195 The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file. MacOSX vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_server_apache_version
 
RED CVE-2009-1196 The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw." CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
YELLOW CVE-2009-1201 Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asaxss  
YELLOW CVE-2009-1202 WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asaxss  
YELLOW CVE-2009-1203 WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asaxss  
YELLOW CVE-2009-1204 Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php. TikiWiki vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_tikiwikiver  
RED CVE-2009-1210 Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-1213 Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing. Bugzilla vulnerabilities
web_prog_cgi_bugzilla  
YELLOW CVE-2009-1218 Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml. Sun Java System Calendar Express
web_prog_php_sjscexss  
BROWN CVE-2009-1219 Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter. Sun Java System Calendar Express
web_prog_php_sjscexss  
YELLOW CVE-2009-1232 Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and earlier are also affected. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-1233 Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1234 Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-1235 XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1239 IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-1241 Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive. ClamAV vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_av_clam
misc_av_clamwinupx
misc_macosx_version
 
YELLOW CVE-2009-1244 Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED
!
CVE-2009-1252 Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field. NTP vulnerabilities
misc_ntpdbo
misc_ntpdver
 
RED CVE-2009-1267 Unspecified vulnerability in the LDAP dissector in Wireshark 0.99.2 through 1.0.6, when running on Windows, allows remote attackers to cause a denial of service (crash) via unknown attack vectors. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-1268 The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-1269 Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-1270 libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang. ClamAV vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_av_clam
misc_av_clamwinupx
misc_macosx_version
 
RED CVE-2009-1271 The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
RED CVE-2009-1272 The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-1279 Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin component, (2) com_search component when "Gather Search Statistics" is enabled, and (3) the category view in the com_content component. Joomla vulnerabilities
web_prog_php_joomlaver  
YELLOW CVE-2009-1280 Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. Joomla vulnerabilities
web_prog_php_joomlaver  
RED CVE-2009-1285 Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files. phpMyAdmin vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_myadminver  
RED CVE-2009-1286 The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities. Lotus Domino IMAP vulnerabilities
mail_imap_domino  
RED CVE-2009-1298 The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions before 2.6.32, calls IP_INC_STATS_BH with an incorrect argument, which allows remote attackers to cause a denial of service (NULL pointer dereference and hang) via long IP packets, possibly related to the ip_defrag function. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1302 The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1303 The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1304 The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving (1) js_FindPropertyHelper, related to the definitions of Math and Date; and (2) js_CheckRedeclaration. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1305 The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors involving JSOP_DEFVAR and properties that lack the JSPROP_PERMANENT attribute. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1306 The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1307 The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1308 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attackers to inject arbitrary web script or HTML via vectors involving XBL JavaScript bindings and remote stylesheets, as exploited in the wild by a March 2009 eBay listing. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1309 Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1310 Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows user-assisted remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SearchForm element. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-1311 Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1312 Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1313 The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
RED CVE-2009-1337 The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-1338 The kill_something_info function in kernel/signal.c in the Linux kernel before 2.6.28 does not consider PID namespaces when processing signals directed to PID -1, which allows local users to bypass the intended namespace isolation, and send arbitrary signals to all processes in all namespaces, via a kill command. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1340 Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-1348 The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA Server, Security for Microsoft Sharepoint, Security for Email Servers, Email Gateway, and Active Virus Defense allows remote attackers to bypass virus detection via (1) an invalid Headflags field in a malformed RAR archive, (2) an invalid Packsize field in a malformed RAR archive, or (3) an invalid Filelength field in a malformed ZIP archive. McAfee AntiVirus engine

Note: Authentication is required to detect this vulnerability
misc_av_mcafeedat  
RED CVE-2009-1350 Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of an arbitrary pointer. Novell NetIdentity Client vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_novellclient_xtagent  
RED CVE-2009-1353 Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon crash) via a long URI, related to http.c. Zervit vulnerabilities
web_server_zervitbo  
YELLOW CVE-2009-1357 CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter. HTTP Response Splitting
web_tool_sundeladmin  
RED CVE-2009-1360 The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-1365 Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests. Flash Media Server vulnerabilities
web_server_flashmedia  
RED CVE-2009-1371 The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding. ClamAV vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_av_clam
misc_av_clamwinupx
misc_macosx_version
 
RED CVE-2009-1372 Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL. ClamAV vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_av_clam
misc_av_clamwinupx
misc_macosx_version
 
YELLOW CVE-2009-1373 Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-1374 Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-1375 The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-1376 Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
RED CVE-2009-1377 The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug." OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_openssl  
RED CVE-2009-1378 Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or (2) have sequence numbers much greater than current sequence numbers, aka "DTLS fragment handling memory leak." OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_openssl  
RED CVE-2009-1379 Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate. OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_openssl  
YELLOW CVE-2009-1380 Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via the filter parameter, related to the key property and the position of quote and colon characters. JBoss Application Server

Note: Authentication is required to detect this vulnerability
web_dev_jbossasver  
YELLOW CVE-2009-1381 The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579. SquirrelMail vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel  
RED CVE-2009-1384 pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-1385 Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size. VMWare ESX vulnerabilities
Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_linuxkernel
 
RED CVE-2009-1386 ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello. OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_openssl  
RED CVE-2009-1387 The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug." VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-1388 The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-1389 Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attackers to cause a denial of service (kernel memory corruption and crash) via a long packet. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1392 The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
RED CVE-2009-1394 Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe. Timbuktu vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_timbuktu_ver  
YELLOW CVE-2009-1412 Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-1413 Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site. NOTE: this can be leveraged for a remote attack by exploiting a chromehtml: argument-injection vulnerability. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-1414 Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for attackers to conduct Universal XSS attacks via unspecified vectors. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-1418 Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. HP SMH vulnerabilities
web_tool_hpsmh  
RED CVE-2009-1420 Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when used with SNMP (aka HPOvNNM.HPOVSNMP) before 1.30.009 and MIB (aka HPOvNNM.HPOVMIB) before 1.30.009, allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors. HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
net_ovnodemgrrpingbo  
RED CVE-2009-1430 Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allow remote attackers to execute arbitrary code via (1) a crafted packet or (2) data that ostensibly arrives from the MsgSys.exe process. Symantec vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_symantec_alertbo  
BROWN CVE-2009-1431 XFR.EXE in the Intel File Transfer service in the console in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary code by placing the code on a (1) share or (2) WebDAV server, and then sending the UNC share pathname to this service. Symantec vulnerabilities
misc_av_symantec_alertxfr  
YELLOW CVE-2009-1435 NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information. Trend Micro OfficeScan

Note: Authentication is required to detect this vulnerability
misc_av_trendmicro_ziplongfile  
RED CVE-2009-1439 Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a denial of service (crash) via a long nativeFileSystem field in a Tree Connect response to an SMB mount request. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
BROWN CVE-2009-1444 PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter. IDA Pro vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_idaprover  
YELLOW CVE-2009-1467 Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php. IceWarp vulnerabilities
mail_smtp_merak  
YELLOW CVE-2009-1468 Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query. IceWarp vulnerabilities
mail_smtp_merak  
YELLOW CVE-2009-1469 CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message. IceWarp vulnerabilities
mail_smtp_merak  
RED CVE-2009-1490 Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long X- header, as demonstrated by an X-Testing header. Sendmail vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_smtp_sendmail  
YELLOW CVE-2009-1492 The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1493 The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acroread  
YELLOW CVE-2009-1514 Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-1516 Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method. IceWarp vulnerabilities
mail_smtp_merak  
RED CVE-2009-1520 Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors. Tivoli Storage Manager

Note: Authentication is required to detect this vulnerability
misc_tivolicategory_storageclientver  
RED CVE-2009-1521 Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors. Tivoli Storage Manager

Note: Authentication is required to detect this vulnerability
misc_tivolicategory_storageclientver  
RED CVE-2009-1522 The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors. Tivoli Storage Manager

Note: Authentication is required to detect this vulnerability
misc_tivolicategory_storageclientver  
RED CVE-2009-1523 Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI. Jetty vulnerabilities
web_dev_jetty  
YELLOW CVE-2009-1524 Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character. Jetty vulnerabilities
web_dev_jetty  
YELLOW CVE-2009-1527 Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to locking an incorrect cred_exec_mutex object. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1528 Microsoft Internet Explorer 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly synchronize AJAX requests, which allows allows remote attackers to execute arbitrary code via a large number of concurrent, asynchronous XMLHttpRequest calls, aka "HTML Object Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-1529 Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCapture method on a collection of crafted objects, aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v7  
YELLOW CVE-2009-1530 Use-after-free vulnerability in Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code by repeatedly adding HTML document nodes and calling event handlers, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Objects Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v7  
YELLOW CVE-2009-1531 Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code via frequent calls to the getElementsByTagName function combined with the creation of an object during reordering of elements, followed by an onreadystatechange event, which triggers an access of an object that (1) was not properly initialized or (2) is deleted, aka "HTML Object Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v7  
YELLOW CVE-2009-1532 Microsoft Internet Explorer 8 for Windows XP SP2 and SP3; 8 for Server 2003 SP2; 8 for Vista Gold, SP1, and SP2; and 8 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via "malformed row property references" that trigger an access of an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Objects Memory Corruption Vulnerability" or "HTML Object Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v8  
YELLOW CVE-2009-1533 Buffer overflow in the Works for Windows document converters in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, Office 2007 SP1, and Works 8.5 and 9 allows remote attackers to execute arbitrary code via a crafted Works .wps file that triggers memory corruption, aka "File Converter Buffer Overflow Vulnerability." Microsoft Works vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_msworkscnv  
YELLOW CVE-2009-1534 Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3, Office XP Web Components SP3, BizTalk Server 2002, and Visual Studio .NET 2003 SP1 allows remote attackers to execute arbitrary code via crafted property values, aka "Office Web Components Buffer Overflow Vulnerability." Office Web Components vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_owcrce  
YELLOW CVE-2009-1535 The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122. IIS WebDAV vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_server_iis_webdavdir  
RED CVE-2009-1536 ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS 7.0, does not properly manage request scheduling, which allows remote attackers to cause a denial of service (daemon outage) via a series of crafted HTTP requests, aka "Remote Unauthenticated Denial of Service in ASP.NET Vulnerability." Microsoft NET Framework

Note: Authentication is required to detect this vulnerability
win_dotnet2008
win_dotnetvista
 
YELLOW CVE-2009-1537 Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited in the wild in May 2009, aka "DirectX NULL Byte Overwrite Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_directxquicktime CHECKMARK
YELLOW CVE-2009-1538 The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 performs updates to pointers without properly validating unspecified data values, which allows remote attackers to execute arbitrary code via a crafted QuickTime media file, aka "DirectX Pointer Validation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_directxquicktime  
YELLOW CVE-2009-1539 The QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 does not properly validate unspecified size fields in QuickTime media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "DirectX Size Validation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_directxquicktime  
YELLOW CVE-2009-1542 The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CPU privilege-level requirements for all machine instructions, which allows guest OS users to execute arbitrary kernel-mode code and gain privileges within the guest OS via a crafted application, aka "Virtual PC and Virtual Server Privileged Instruction Decoding Vulnerability." Microsoft Virtual PC

Note: Authentication is required to detect this vulnerability
win_patch_virtualpcpe
win_patch_virtualserverpe
 
YELLOW CVE-2009-1544 Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_workstationlocal  
YELLOW CVE-2009-1545 Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed header in a crafted AVI file, aka "Malformed AVI Header Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmfproc  
YELLOW CVE-2009-1546 Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote attackers to execute arbitrary code on a Windows 2000 SP4 system via a crafted AVI file, or cause a denial of service on a Windows XP SP2 or SP3, Server 2003 SP2, Vista Gold, SP1, or SP2, or Server 2008 Gold or SP2 system via a crafted AVI file, aka "AVI Integer Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmfproc  
YELLOW CVE-2009-1547 Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-1564 Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-1565 vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted HexTile-encoded video chunks that trigger heap-based buffer overflows, related to "integer truncation errors." VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-1568 Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows remote attackers to execute arbitrary code via a long target-frame parameter. Novell Print Services vulnerabilities

Note: Authentication is required to detect this vulnerability
printer_novelliprtax  
YELLOW CVE-2009-1569 Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow remote attackers to execute arbitrary code via vectors related to (1) Date and (2) Time. Novell Print Services vulnerabilities

Note: Authentication is required to detect this vulnerability
printer_novelliprtax  
YELLOW CVE-2009-1571 Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
RED CVE-2009-1574 racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1575 Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows remote attackers to inject arbitrary web script or HTML via crafted UTF-8 byte sequences before the Content-Type meta tag, which are treated as UTF-7 by Internet Explorer 6 and 7. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-1576 Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-assisted remote attackers to obtain sensitive information by tricking victims into visiting the front page of the site with a crafted URL and causing form data to be sent to an attacker-controlled site, possibly related to multiple / (slash) characters that are not properly handled by includes/bootstrap.inc, as demonstrated using the search box. NOTE: this vulnerability can be leveraged to conduct cross-site request forgery (CSRF) attacks. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-1578 Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) certain encrypted strings in e-mail headers, related to contrib/decrypt_headers.php; (2) PHP_SELF; and (3) the query string (aka QUERY_STRING). SquirrelMail vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel
misc_macosx_version
 
YELLOW CVE-2009-1579 The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. SquirrelMail vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel
misc_macosx_version
 
YELLOW CVE-2009-1580 Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafted cookie. SquirrelMail vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel
misc_macosx_version
 
YELLOW CVE-2009-1581 functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message. SquirrelMail vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel
misc_macosx_version
 
YELLOW CVE-2009-1595 The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action. Openfire Jabber Server vulnerabilities
misc_openfirejabberver  
RED CVE-2009-1601 The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory. ClamAV vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_av_clam
misc_av_clamwinupx
 
YELLOW CVE-2009-1616 Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505. Coppermine Photo Gallery vulnerabilities
web_prog_php_cpg  
RED
!
CVE-2009-1628 Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet. Unisys Business Information Server vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
misc_unisysbisbo  
YELLOW CVE-2009-1630 The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1631 The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and certain directories and files under .evolution/ related to local mail, which allows local users to obtain sensitive information by reading these files. GNOME Evolution vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_evolution  
RED CVE-2009-1632 Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-1633 Multiple buffer overflows in the cifs subsystem in the Linux kernel before 2.6.29.4 allow remote CIFS servers to cause a denial of service (memory corruption) and possibly have unspecified other impact via (1) a malformed Unicode string, related to Unicode string area alignment in fs/cifs/sess.c; or (2) long Unicode characters, related to fs/cifs/cifssmb.c and the cifs_readdir function in fs/cifs/readdir.c. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-1635 Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values. Novell GroupWise vulnerabilities
mail_web_groupwisewebacc  
RED
!
CVE-2009-1636 Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command. Novell GroupWise vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
mail_smtp_gwiaemailbo  
RED CVE-2009-1656 Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability." Xerox MicroServer vulnerabilities
web_tool_xerox_workcentrever  
YELLOW CVE-2009-1668 TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer. TYPSoft FTP vulnerabilities
ftp_typsoft  
RED CVE-2009-1671 Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method. Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
web_client_javadeploytk  
RED CVE-2009-1672 The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method. Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
web_client_javadeploytk  
YELLOW CVE-2009-1681 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1682 Apple Safari before 4.0 does not properly check for revoked Extended Validation (EV) certificates, which makes it easier for remote attackers to trick a user into accepting an invalid certificate. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1684 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via an event handler that triggers script execution in the context of the next loaded document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1685 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML by overwriting the document.implementation property of (1) an embedded document or (2) a parent document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1686 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle constant (aka const) declarations in a type-conversion operation during JavaScript exception handling, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1687 The JavaScript garbage collector in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle allocation failures, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document that triggers write access to an "offset of a NULL pointer." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1688 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to determining a security context through an approach that is not the "HTML 5 standard method." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1689 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving submission of a form to the about:blank URL, leading to security-context replacement. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1690 Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome 1.0.154.53, and possibly other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by setting an unspecified property of an HTML tag that causes child elements to be freed and later accessed when an HTML error occurs, related to "recursion in certain DOM event handlers." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1691 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to insufficient access control for standard JavaScript prototypes in other domains. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1693 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to read images from arbitrary web sites via a CANVAS element with an SVG image, related to a "cross-site image capture issue." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1694 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read images from arbitrary web sites via vectors involving a CANVAS element and redirection, related to a "cross-site image capture issue." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1695 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving access to frame contents after completion of a page transition. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1696 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in JavaScript applications, which makes it easier for remote web servers to track the behavior of a Safari user during a session. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1697 CRLF injection vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject HTTP headers and bypass the Same Origin Policy via a crafted HTML document, related to cross-site scripting (XSS) attacks that depend on communication with arbitrary web sites on the same server through use of XMLHttpRequest without a Host header. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1698 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not initialize a pointer during handling of a Cascading Style Sheets (CSS) attr function call with a large numerical argument, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1699 The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1700 The XSLT implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle redirects, which allows remote attackers to read XML content from arbitrary web pages via a crafted document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1701 Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by destroying a document.body element that has an unspecified XML container with elements that support the dir attribute. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1702 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to improper handling of Location and History objects. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1703 WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1704 CFNetwork in Apple Safari before 4.0 misinterprets downloaded image files as local HTML documents in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript code by placing it in an image file. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1705 CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted font data. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1706 The Private Browsing feature in Apple Safari before 4.0 on Windows does not remove cookies from the alternate cookie store in unspecified circumstances upon (1) disabling of the feature or (2) exit of the application, which makes it easier for remote web servers to track users via a cookie. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1707 Race condition in the Reset Safari implementation in Apple Safari before 4.0 on Windows might allow local users to read stored web-site passwords via unspecified vectors. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1708 Apple Safari before 4.0 does not prevent calls to the open-help-anchor URL handler by web sites, which allows remote attackers to open arbitrary local help files, and execute arbitrary code or obtain sensitive information, via a crafted call. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1709 Use-after-free vulnerability in the garbage-collection implementation in WebCore in WebKit in Apple Safari before 4.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via an SVG animation element, related to SVG set objects, SVG marker elements, the targetElement attribute, and unspecified "caches." Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1710 WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser's display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1711 WebKit in Apple Safari before 4.0 does not properly initialize memory for Attr DOM objects, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1712 WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1713 The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1714 Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to the improper escaping of HTML attributes. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1715 Cross-site scripting (XSS) vulnerability in Web Inspector in WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to inject arbitrary web script or HTML, and read local files, via vectors related to script execution with incorrect privileges. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1716 CFNetwork in Apple Safari before 4.0 on Windows does not properly protect the temporary files created for downloads, which allows local users to obtain sensitive information by reading these files. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1718 WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1719 The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer. Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
web_client_jre  
YELLOW CVE-2009-1720 Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1721 The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1722 Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1723 CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1724 Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1725 WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-1726 Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile. MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-1727 Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-1728 Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-1730 Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command. TFTP file access
ftp_tftptrav  
RED
!
CVE-2009-1761 The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error. ARCserve vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
misc_arcservecategory_msgengdos  
YELLOW CVE-2009-1762 Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter. Novell GroupWise vulnerabilities
mail_web_groupwisewebacc  
YELLOW CVE-2009-1777 CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter. HTTP Response Splitting
web_prog_cgi_formmailsplit  
YELLOW CVE-2009-1782 Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive. FSecure vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_fsecurebp  
YELLOW CVE-2009-1805 Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, when the Descheduled Time Accounting Service is not running, allows guest OS users on Windows to cause a denial of service via unknown vectors. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED CVE-2009-1829 Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-1831 The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow. Winamp vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_winampver  
YELLOW CVE-2009-1832 Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction." Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1833 The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) js_LeaveSharpObject, (2) ParseXMLSource, and (3) a certain assertion in jsinterp.c; and other vectors. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1834 Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1835 Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assisted remote attackers to read arbitrary cookies via a crafted HTML document, as demonstrated by a URL with file://example.com/C:/ at the beginning. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1836 Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1837 Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transition during Java applet loading, related to a use-after-free vulnerability for memory associated with a destroyed Java object. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-1838 The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1839 Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-1840 Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-1841 js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_firefox
web_client_seamonkey
 
RED CVE-2009-1842 SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header. SQL injection
web_prog_sql_nukeuserlog  
YELLOW CVE-2009-1844 Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6 and 7, which are not properly handled in the "HTML exports of books" feature; and (2) allow remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via the help text of an arbitrary vocabulary. NOTE: vector 1 exists because of an incomplete fix for CVE-2009-1575. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-1855 Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1856 Integer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allows attackers to cause a denial of service or possibly execute arbitrary code via a PDF file containing unspecified parameters to the FlateDecode filter, which triggers a heap-based buffer overflow. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1857 Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a PDF document with a crafted TrueType font. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1858 The JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors that trigger memory corruption. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1859 Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1860 Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-1861 Multiple heap-based buffer overflows in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file with a JPX (aka JPEG2000) stream that triggers heap memory corruption. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-1862 Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009. Adobe Acrobat vulnerabilities
Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1863 Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a "privilege escalation vulnerability." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1864 Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1865 Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a "null pointer vulnerability." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1866 Stack-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1867 Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "clickjacking vulnerability." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1868 Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1869 Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1870 Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to obtain sensitive information via vectors involving saving an SWF file to a hard drive, related to a "local sandbox vulnerability." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-1872 Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm. http Cold Fusion

Note: Authentication is recommended to improve the accuracy of this check
web_prog_cfm_mx  
YELLOW CVE-2009-1873 Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter. JRun vulnerabilities

Note: Authentication is required to detect this vulnerability
web_dev_jrun_jmcapp  
YELLOW CVE-2009-1874 Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Adobe JRun 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. JRun vulnerabilities

Note: Authentication is required to detect this vulnerability
web_dev_jrun_jmcapp  
YELLOW CVE-2009-1875 Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877. http Cold Fusion

Note: Authentication is recommended to improve the accuracy of this check
web_prog_cfm_mx  
YELLOW CVE-2009-1876 Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability." http Cold Fusion

Note: Authentication is recommended to improve the accuracy of this check
web_prog_cfm_mx  
YELLOW CVE-2009-1877 Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875. http Cold Fusion

Note: Authentication is recommended to improve the accuracy of this check
web_prog_cfm_mx  
YELLOW CVE-2009-1878 Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors. http Cold Fusion

Note: Authentication is recommended to improve the accuracy of this check
web_prog_cfm_mx  
YELLOW CVE-2009-1882 Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information. ImageMagick vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_imagemagick  
RED CVE-2009-1887 agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309. VMWare ESX vulnerabilities
Net SNMP vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_snmp_snmprh
 
RED CVE-2009-1888 The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-1889 The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-1890 The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests. MacOSX vulnerabilities
Apache module vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_mod_proxyver
 
YELLOW CVE-2009-1891 The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption). MacOSX vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_server_apache_version
 
RED CVE-2009-1892 dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests. dhcpd vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_dhcpver  
RED CVE-2009-1893 The configtest function in the Red Hat dhcpd init script for DHCP 3.0.1 in Red Hat Enterprise Linux (RHEL) 3 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file, related to the "dhcpd -t" command. dhcpd vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_dhcpver  
RED CVE-2009-1895 The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR). VMWare ESX vulnerabilities
Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_linuxkernel
 
YELLOW CVE-2009-1897 The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
BROWN CVE-2009-1898 The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-1899 Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin." WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-1900 The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-1901 The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
YELLOW CVE-2009-1904 The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
BROWN CVE-2009-1905 The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-1907 Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header. Claroline vulnerabilities
web_prog_php_clarolinever  
YELLOW CVE-2009-1917 Microsoft Internet Explorer 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-1918 Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle table operations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption by adding malformed elements to an empty DIV element, related to the getElementsByTagName method, aka "HTML Objects Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-1919 Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properly handle attempts to access deleted objects in memory, which allows remote attackers to execute arbitrary code via an HTML document containing embedded style sheets that modify unspecified rule properties that cause the behavior element to be "improperly processed," aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-1920 The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted web site that triggers memory corruption, aka "JScript Remote Code Execution Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_jssbo  
YELLOW CVE-2009-1922 The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_msmq4  
RED CVE-2009-1923 Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length calculation, aka "WINS Heap Overflow Vulnerability." WINS vulnerability

Note: Authentication is required to detect this vulnerability
win_patch_winsbo  
RED CVE-2009-1924 Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability." WINS vulnerability

Note: Authentication is required to detect this vulnerability
win_patch_winsbo  
RED
!
CVE-2009-1925 The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby triggering misinterpretation of an unspecified field as a function pointer, aka "TCP/IP Timestamps Code Execution Vulnerability." Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
win_patch_tcpiprce3
win_patch_tcpiptimestamp
 
RED CVE-2009-1926 Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability." Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
win_patch_tcpiprce3  
RED CVE-2009-1928 Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2; and Active Directory Lightweight Directory Service (AD LDS) on Windows Server 2008 Gold and SP2 allows remote attackers to cause a denial of service (system hang) via a malformed (1) LDAP or (2) LDAPS request, aka "LSASS Recursive Stack Overflow Vulnerability." Active Directory vulnerability

Note: Authentication is required to detect this vulnerability
win_patch_activedirdos4
win_patch_adadlds
win_patch_adamdos4
 
YELLOW CVE-2009-1929 Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Remote Desktop Connection ActiveX Control Heap Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_rdc  
YELLOW CVE-2009-1930 The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, aka "Telnet Credential Reflection Vulnerability," a related issue to CVE-2000-0834. Microsoft Telnet Server

Note: Authentication is required to detect this vulnerability
shell_telnet_reflect  
RED CVE-2009-1955 The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564. MacOSX vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_server_apache_version
 
RED CVE-2009-1956 Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input. MacOSX vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_server_apache_version
 
YELLOW CVE-2009-1961 The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
BROWN CVE-2009-1963 Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated users to affect integrity and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1964 Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1965 Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1966 Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1967. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1967 Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-1966. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
YELLOW CVE-2009-1968 Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_secureentxss
database_oracle_version
 
BROWN CVE-2009-1969 Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1970 Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2009-0991. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1971 Unspecified vulnerability in the Data Pump component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.7 allows remote authenticated users to affect integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1972 Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect integrity, related to DBMS_SYS_SQL and DBMS_SQL. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1973 Unspecified vulnerability in the Virtual Private Database component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to VPD policies. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1975 Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality, integrity, and availability, related to the WLS Console Package. WebLogic vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_weblogic  
BROWN CVE-2009-1976 Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows remote attackers to affect integrity via unknown vectors. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
YELLOW CVE-2009-1977 Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows attackers to bypass authentication via unknown vectors involving the username parameter and login.php. Oracle Secure Backup vulnerabilities

Note: Authentication is required to detect this vulnerability
database_oracle_backupver  
YELLOW CVE-2009-1978 Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the July 2009 Oracle CPU. Oracle has not commented on claims from an independent researcher that this vulnerability allows remote authenticated users to execute arbitrary code with SYSTEM privileges via vectors involving property_box.php. Oracle Secure Backup vulnerabilities

Note: Authentication is required to detect this vulnerability
database_oracle_backupver  
BROWN CVE-2009-1979 Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1985 Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1990 Unspecified vulnerability in the Business Intelligence Enterprise Edition component in Oracle Application Server 10.1.3.4.1 allows local users to affect confidentiality via unknown vectors. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
BROWN CVE-2009-1991 Unspecified vulnerability in the Oracle Text component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to CTXSYS.DRVXTABC. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an established researcher that this is for multiple SQL injection vulnerabilities via the (1) idx_owner or (2) idx_name parameters to the create_tables procedure. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1992 Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1993 Unspecified vulnerability in the Application Express component in Oracle Database 3.0.1 allows remote authenticated users to affect confidentiality and integrity, related to FLOWS_030000.WWV_EXECUTE_IMMEDIATE. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1994 Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability, related to MDSYS.PRVT_CMT_CBK. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1995 Unspecified vulnerability in the Advanced Queuing component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_AQ_INV. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1996 Unspecified vulnerability in the Logical Standby component in Oracle Database allows remote authenticated users to affect integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1997 Unspecified vulnerability in the Authentication component in Oracle Database 10.2.0.3 and 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-1999 Unspecified vulnerability in the Business Intelligence Enterprise Edition component in unspecified Oracle Application Server versions allows remote attackers to affect integrity via unknown vectors. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
BROWN CVE-2009-2000 Unspecified vulnerability in the Authentication component in Oracle Database 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-2001 Unspecified vulnerability in the PL/SQL component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
YELLOW CVE-2009-2004 Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902. Claroline vulnerabilities
web_prog_php_dokeosver  
YELLOW CVE-2009-2005 Cross-site request forgery (CSRF) vulnerability in Dokeos 1.8.5, and possibly earlier, allows remote attackers to hijack the authentication of unspecified victims and add new personal agenda items via unknown vectors. Claroline vulnerabilities
web_prog_php_dokeosver  
YELLOW CVE-2009-2006 Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) search_term parameter to main/auth/courses.php; the (2) frm_title and (3) frm_content parameters in a new personal agenda item action; the (4) title and (5) tutor_name parameters in a new course action; and the (6) student and (7) course parameters to main/mySpace/myStudents.php. NOTE: vectors 2 and 3 might only be exploitable via a separate CSRF vulnerability. Claroline vulnerabilities
web_prog_php_dokeosver  
YELLOW CVE-2009-2007 Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a ..\ (dot dot backslash) in the lang parameter to main/exercice/hotspot_lang_conversion.php and (2) read arbitrary files via a .. (dot dot) in the doc_url parameter to main/exercice/Hpdownload.php. Claroline vulnerabilities
web_prog_php_dokeosver  
YELLOW CVE-2009-2008 Multiple SQL injection vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) uInfo parameter to main/tracking/userLog.php and the (2) course parameter to main/mySpace/lp_tracking.php, a different vector than CVE-2009-2006.2. Claroline vulnerabilities
web_prog_php_dokeosver  
YELLOW CVE-2009-2009 Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath parameter to main/document/slideshow.php and the (2) file parameter to main/exercice/testheaderpage.php. Claroline vulnerabilities
web_prog_php_dokeosver  
RED CVE-2009-2026 Stack-based buffer overflow in a token searching function in the dtscore library in Data Transport Services in CA Software Delivery r11.2 C1, C2, C3, and SP4; Unicenter Software Delivery 4.0 C3; CA Advantage Data Transport 3.0 C1; and CA IT Client Manager r12 allows remote attackers to execute arbitrary code via crafted data. CA Multiple Product vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_cadtscore  
YELLOW CVE-2009-2027 The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the application after installation, related to an unspecified compression method. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2042 libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file. MacOSX vulnerabilities
VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
YELLOW CVE-2009-2043 nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
BROWN CVE-2009-2049 Cisco IOS 12.0(32)S12 through 12.0(32)S13 and 12.0(33)S3 through 12.0(33)S4, 12.0(32)SY8 through 12.0(32)SY9, 12.2(33)SXI1 through 12.2(33)SXI2, 12.2XNC before 12.2(33)XNC2, 12.2XND before 12.2(33)XND1, and 12.4(24)T1; and IOS XE 2.3 through 2.3.1t and 2.4 through 2.4.0; when RFC4893 BGP routing is enabled, allows remote attackers to cause a denial of service (device reload) by using an RFC4271 peer to send a malformed update, aka Bug ID CSCta33973. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_bgp  
RED CVE-2009-2050 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466. Cisco voice products

Note: Authentication is required to detect this vulnerability
net_cisco_cucmver  
RED CVE-2009-2051 Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987. Cisco voice products
Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_cucmver
net_cisco_ios
 
RED CVE-2009-2052 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371. Cisco voice products

Note: Authentication is required to detect this vulnerability
net_cisco_cucmver  
RED CVE-2009-2053 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2) allows remote attackers to cause a denial of service (file-descriptor exhaustion and SCCP outage) via a flood of TCP packets, aka Bug ID CSCsx32236. Cisco voice products

Note: Authentication is required to detect this vulnerability
net_cisco_cucmver  
RED CVE-2009-2054 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689. Cisco voice products

Note: Authentication is required to detect this vulnerability
net_cisco_cucmver  
YELLOW CVE-2009-2061 Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2062 Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2063 Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-2070 Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-2071 Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-2072 Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2079 Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via (1) vocabulary names, (2) synonyms, and (3) term names. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
BROWN CVE-2009-2085 The Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5 does not properly handle use of Identity Assertion with CSIv2 Security, which allows remote attackers to bypass intended CSIv2 access restrictions via vectors involving Enterprise JavaBeans (EJB). WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2087 The Web Services functionality in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, in certain circumstances involving the ibm-webservicesclient-bind.xmi file and custom password encryption, uses weak password obfuscation, which allows local users to cause a denial of service (deployment failure) via unspecified vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2088 The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when SPNEGO Single Sign-on (SSO) and disableSecurityPreInvokeOnFilters are configured, allows remote attackers to bypass authentication via a request for a "secure URL," related to a certain invokefilterscompatibility property. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2089 The Migration component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 and 7.0 before 7.0.0.5, when tracing is enabled and a 6.1 to 7.0 migration has occurred, allows remote authenticated users to obtain sensitive information by reading a Migration Trace file. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2090 Unspecified vulnerability in wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 allows remote attackers to bypass intended Java Management Extensions (JMX) Management Beans (aka MBeans) access restrictions, and cause a denial of service (daemon stop), via unknown vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2092 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.5 does not properly read the portletServingEnabled parameter in ibm-portlet-ext.xmi, which allows remote attackers to bypass intended access restrictions via unknown vectors. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
YELLOW CVE-2009-2118 Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow. IrfanView vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_irfanviewver  
YELLOW CVE-2009-2121 Buffer overflow in the browser kernel in Google Chrome before 2.0.172.33 allows remote HTTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted response. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-2139 Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice
misc_openofficewin1
 
YELLOW CVE-2009-2186 Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465." Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-2188 Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with crafted EXIF metadata. MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_safari
 
RED CVE-2009-2190 launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connections to an inetd-based launchd service. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-2191 Format string vulnerability in Login Window in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in an application name. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2192 MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-2193 Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2194 Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which allows local users to cause a denial of service (system crash) by placing file descriptors in messages sent to a socket that has no receiver, related to a "synchronization issue." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2195 Buffer overflow in WebKit in Apple Safari before 4.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted floating-point numbers. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2196 Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2197 Apple Safari before 9.1 allows remote attackers to spoof the user interface via a web page that places text in a crafted context, leading to unintended use of that text within a Safari dialog. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2199 Incomplete blacklist vulnerability in WebKit in Apple Safari before 4.0.3, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to spoof domain names in URLs, and possibly conduct phishing attacks, via unspecified homoglyphs. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2200 WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2202 Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file. MacOSX vulnerabilities
QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
misc_quicktime
 
YELLOW CVE-2009-2203 Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file. MacOSX vulnerabilities
QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
misc_quicktime
 
YELLOW CVE-2009-2210 Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type. Mozilla Thunderbird vulnerabilities
Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_thunderbird
web_client_seamonkey
 
RED CVE-2009-2230 SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter. MyBB vulnerabilities
web_prog_php_mybb  
RED CVE-2009-2256 The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg. Administration File Access
web_prog_file_netgear  
RED CVE-2009-2257 The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/. Administration File Access
web_prog_file_netgear  
RED CVE-2009-2258 Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter. Administration File Access
web_prog_file_netgear  
YELLOW CVE-2009-2267 VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED CVE-2009-2277 Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data." VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-2283 Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Java Web Console vulnerabilities
web_tool_javawebconsolever  
YELLOW CVE-2009-2284 Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark. phpMyAdmin vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_myadminver  
YELLOW CVE-2009-2285 Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327. MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-2287 The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-2288 statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters. Nagios vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_tool_nagiosstatuswml
web_tool_nagiosver
 
YELLOW CVE-2009-2334 wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2335 WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience." WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2336 The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience." WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
RED CVE-2009-2346 The IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.1.6; Business Edition B.x.x before B.2.5.10, C.2.x before C.2.4.3, and C.3.x before C.3.1.1; and s800i 1.3.x before 1.3.0.3 allows remote attackers to cause a denial of service (call-number exhaustion) by initiating many IAX2 message exchanges, a related issue to CVE-2008-3263. Asterisk vulnerabilities

Note: Authentication is required to detect this vulnerability
net_asterisk  
YELLOW CVE-2009-2351 Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-2352 Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-2360 Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote attackers to inject arbitrary web script or HTML via the backend parameter. Horde application vulnerabilities
web_prog_php_hordepasswd  
YELLOW CVE-2009-2372 Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-2373 Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-2374 Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-2404 Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-2405 Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web script or HTML via the (1) monitorName, (2) objectName, (3) attribute, or (4) period parameter to createSnapshot.jsp, or the (5) monitorName, (6) objectName, (7) attribute, (8) threshold, (9) period, or (10) enabled parameter to createThresholdMonitor.jsp. NOTE: some of these details are obtained from third party information. JBoss Application Server

Note: Authentication is required to detect this vulnerability
web_dev_jbossasver  
YELLOW CVE-2009-2406 Stack-based buffer overflow in the parse_tag_11_packet function in fs/ecryptfs/keystore.c in the eCryptfs subsystem in the Linux kernel before 2.6.30.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving a crafted eCryptfs file, related to not ensuring that the key signature length in a Tag 11 packet is compatible with the key signature buffer size. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-2408 Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5. SSL certificates
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_cipher_nullcommonname
misc_macosx_version
 
YELLOW CVE-2009-2409 The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large. SSL hashes
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_cipher_weakhash
misc_macosx_version
 
YELLOW CVE-2009-2411 Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-2412 Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information. MacOSX vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_server_apache_version
 
RED CVE-2009-2414 Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework. VMWare ESX vulnerabilities
MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_macosx_version
web_client_safari
 
RED CVE-2009-2416 Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework. VMWare ESX vulnerabilities
MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-2417 lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2419 Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2420 Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue to CVE-2009-1703. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2421 The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an unspecified protocol. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2422 The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2431 WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2432 WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2445 Oracle iPlanet Web Server (formerly Sun Java System Web Server or Sun ONE Web Server) 6.1 before SP12, and 7.0 through Update 6, when running on Windows, allows remote attackers to read arbitrary JSP files via an alternate data stream syntax, as demonstrated by a .jsp::$DATA URI. Sun ONE Application Server
web_dev_sunoneads  
YELLOW CVE-2009-2446 Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request. NOTE: some of these details are obtained from third party information. MySQL vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version
misc_macosx_version
 
YELLOW CVE-2009-2455 Multiple cross-site scripting (XSS) vulnerabilities in webadmin/admin.php in @mail 5.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) type and (2) func parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. AtMail vulnerabilities
mail_web_atmail  
YELLOW CVE-2009-2462 The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2463 Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2464 The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2465 Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2466 The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2467 Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2468 Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194. MacOSX vulnerabilities
Mozilla vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_firefox
web_client_safari
 
YELLOW CVE-2009-2469 Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2470 Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a long domain name in a reply. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2471 The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2472 Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass." Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2473 neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2474 neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2477 js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2484 Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file. VLC vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vlc  
YELLOW CVE-2009-2493 The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability." Flash vulnerabilities
Visual Studio vulnerabilities
Windows updates needed
Internet Explorer vulnerabilities
Microsoft outlook vulnerabilities
Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_vstudioatl
win_patch_atl
win_patch_atlax
win_patch_dhtmlatl
win_patch_ie_v5
win_patch_ie_v6
win_patch_msoutlook09037
win_patch_office2002atl
win_patch_office2003atl
win_patch_office2007atl
win_patch_visioatl
win_patch_wmpatl
 
YELLOW CVE-2009-2494 The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after reading a variant from a stream and deleting this variant, aka "ATL Object Type Mismatch Vulnerability." Windows updates needed
Microsoft outlook vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_atl
win_patch_dhtmlatl
win_patch_msoutlook09037
win_patch_wmpatl
 
YELLOW CVE-2009-2495 The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML document with an ATL (1) component or (2) control that triggers a buffer over-read, related to ATL headers and buffer allocation, aka "ATL Null String Vulnerability." Flash vulnerabilities
Visual Studio vulnerabilities
Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_vstudioatl
win_patch_office2002atl
win_patch_office2003atl
win_patch_office2007atl
win_patch_visioatl
 
YELLOW CVE-2009-2496 Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability." Office Web Components vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_owcrce  
YELLOW CVE-2009-2497 The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted Silverlight application, (3) a crafted ASP.NET application, or (4) a crafted .NET Framework application, aka "Microsoft Silverlight and Microsoft .NET Framework CLR Vulnerability." Microsoft Silverlight vulnerabilities
Microsoft NET Framework

Note: Authentication is required to detect this vulnerability
misc_silverlightver
win_dotnet1
 
YELLOW CVE-2009-2498 Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmfhdr  
YELLOW CVE-2009-2499 Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmfhdr  
YELLOW CVE-2009-2500 Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability." Microsoft SQL Server
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_mssql_mssql
win_patch_gdiplus09062
 
YELLOW CVE-2009-2501 Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Heap Overflow Vulnerability." Microsoft SQL Server
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_mssql_mssql
win_patch_gdiplus09062
 
YELLOW CVE-2009-2502 Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka "GDI+ TIFF Buffer Overflow Vulnerability." Microsoft SQL Server
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_mssql_mssql
win_patch_gdiplus09062
 
YELLOW CVE-2009-2503 GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 does not properly allocate an unspecified buffer, which allows remote attackers to execute arbitrary code via a crafted TIFF image file that triggers memory corruption, aka "GDI+ TIFF Memory Corruption Vulnerability." Microsoft SQL Server
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_mssql_mssql
win_patch_gdiplus09062
 
YELLOW CVE-2009-2504 Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allow remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP), (2) a crafted ASP.NET application, or (3) a crafted .NET Framework application, aka "GDI+ .NET API Vulnerability." Microsoft SQL Server
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_mssql_mssql
win_patch_gdiplus09062
 
RED CVE-2009-2505 The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_authsrv  
YELLOW CVE-2009-2506 Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with an invalid number of property names in the DocumentSummaryInformation stream, which triggers a heap-based buffer overflow. Microsoft Works vulnerabilities
Microsoft Office vulnerabilities
Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_msworkscnv
win_patch_office2002conv97
win_patch_office2003conv97
win_patch_winconv97
 
YELLOW CVE-2009-2507 A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_indexingmemory  
YELLOW CVE-2009-2508 The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_fds09070  
YELLOW CVE-2009-2509 Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_fds09070  
YELLOW CVE-2009-2510 The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408. SSL certificates
Windows updates needed

Note: Authentication is required to detect this vulnerability
misc_cipher_nullcommonname
win_patch_msasn1spoof
 
YELLOW CVE-2009-2511 Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_msasn1spoof  
RED CVE-2009-2512 The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, aka "Web Services on Devices API Memory Corruption Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wsdapi  
YELLOW CVE-2009-2513 The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneleotfont  
YELLOW CVE-2009-2514 win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kerneleotfont  
YELLOW CVE-2009-2515 Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application that triggers an incorrect truncation of a 64-bit integer to a 32-bit integer, aka "Windows Kernel Integer Underflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kern09058  
YELLOW CVE-2009-2516 The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kern09058  
YELLOW CVE-2009-2517 The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition occurs, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Exception Handler Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_kern09058  
YELLOW CVE-2009-2518 Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office document with a bitmap (aka BMP) image that triggers memory corruption, aka "Office BMP Integer Overflow Vulnerability." Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
win_patch_gdiplus09062  
YELLOW CVE-2009-2519 The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_dhtml09046  
RED CVE-2009-2521 Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability." IIS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
win_patch_iisftpbo  
YELLOW CVE-2009-2523 The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability." License Logging Service

Note: Authentication is required to detect this vulnerability
win_patch_lls  
RED CVE-2009-2524 Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (reboot) via a malformed packet, aka "Local Security Authority Subsystem Service Integer Overflow Vulnerability." Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
win_patch_lsassdos
win_patch_lsassrpc
 
YELLOW CVE-2009-2525 Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to execute arbitrary code via (1) a crafted media file or (2) crafted streaming content, aka "Windows Media Runtime Heap Corruption Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmacodec  
RED CVE-2009-2526 Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability." Windows updates needed
win_patch_smbv2ms09050  
YELLOW CVE-2009-2527 Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (1) a crafted ASF file or (2) crafted streaming content, aka "WMP Heap Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_wmpasf  
YELLOW CVE-2009-2528 GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Memory Corruption Vulnerability." Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
win_patch_gdiplus09062  
YELLOW CVE-2009-2529 Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Component Handling Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v5
win_patch_ie_v6
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-2530 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2531. Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-2531 Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530. Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
win_patch_ie_v8
 
RED CVE-2009-2532 Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability." Windows updates needed
win_patch_smbv2ms09050  
RED CVE-2009-2533 rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers. RealServer vulnerabilities
misc_helixserver  
RED CVE-2009-2534 RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI. RealServer vulnerabilities
misc_helixmobileserver
misc_helixserver
 
YELLOW CVE-2009-2555 Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-2556 Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
RED CVE-2009-2559 Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error. NOTE: some of these details are obtained from third party information. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-2560 Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-2561 Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-2562 Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-2563 Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-2564 NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
RED CVE-2009-2584 Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via a crafted count argument, which triggers a stack-based buffer overflow. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED
!
CVE-2009-2620 src/remote/server.cpp in fbserver.exe in Firebird SQL 1.5 before 1.5.6, 2.0 before 2.0.6, 2.1 before 2.1.3, and 2.5 before 2.5 Beta 2 allows remote attackers to cause a denial of service (daemon crash) via a malformed op_connect_request message that triggers an infinite loop or NULL pointer dereference. Firebird vulnerabilities

Note: Authentication is required to detect this vulnerability unless dangerous checks are enabled
database_firebird_ver
database_firebirddos
 
RED CVE-2009-2621 Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc. Squid vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_proxy_squid  
RED CVE-2009-2622 Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc. Squid vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_proxy_squid  
YELLOW CVE-2009-2624 The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression. gzip vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_compress_gzip
misc_macosx_version
 
RED CVE-2009-2625 XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-2626 The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents) and cause a PHP crash by using the ini_set function to declare a variable, then using the ini_restore function to restore the variable. PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_version  
YELLOW CVE-2009-2628 The VMnc media codec in vmnc.dll in VMware Movie Decoder before 6.5.3 build 185404, VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, and VMware ACE 2.5.x before 2.5.3 build 185404 on Windows does not properly handle certain small heights in video content, which might allow remote attackers to execute arbitrary code via a crafted AVI file that triggers heap memory corruption. VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED CVE-2009-2629 Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests. nginx HTTP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_server_nginx  
YELLOW CVE-2009-2632 Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. Cyrus imap version
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_imap_cyrus
misc_macosx_version
 
YELLOW CVE-2009-2636 Cross-site scripting (XSS) vulnerability in the Integration page in the WebMail component in Kerio MailServer 6.6.0, 6.6.1, 6.6.2, and 6.7.0 allows remote attackers to inject arbitrary web script or HTML via an e-mail message. Kerio MailServer vulnerabilities
mail_web_kerioxss  
YELLOW CVE-2009-2647 Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to "an external script." Kaspersky AntiVirus vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_kaspersky_avver2k10  
YELLOW CVE-2009-2654 Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2662 The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2663 libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2664 The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2665 The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle a Link HTTP header, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted web page, related to an incorrect security wrapper. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-2666 socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-2670 The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-2671 The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-2672 The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-2673 The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
YELLOW CVE-2009-2674 Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow. Java Web Start

Note: Authentication is required to detect this vulnerability
misc_javawebstart  
RED CVE-2009-2675 Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-2676 Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED
!
CVE-2009-2685 Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable. HP Power Manager vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
misc_powermanager  
RED CVE-2009-2687 The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353. PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_version  
YELLOW CVE-2009-2691 The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-2692 The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socket operations in proto_ops structures, which allows local users to trigger a NULL pointer dereference and gain privileges by using mmap to map page zero, placing arbitrary code on this page, and then invoking an unavailable operation, as demonstrated by the sendpage operation (sock_sendpage function) on a PF_PPPOX socket. VMWare ESX vulnerabilities
Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_linuxkernel
 
RED CVE-2009-2693 Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry. MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_dev_tomcatver
 
YELLOW CVE-2009-2694 The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
RED CVE-2009-2695 The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory addresses, which allows local users to gain privileges by exploiting NULL pointer dereference vulnerabilities, related to (1) the default configuration of the allow_unconfined_mmap_low boolean in SELinux on Red Hat Enterprise Linux (RHEL) 5, (2) an error that causes allow_unconfined_mmap_low to be ignored in the unconfined_t domain, (3) lack of a requirement for the CAP_SYS_RAWIO capability for these mmap operations, and (4) interaction between the mmap_min_addr protection mechanism and certain application programs. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2698 The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket. VMWare ESX vulnerabilities
Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_linuxkernel
 
RED CVE-2009-2699 The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs. Apache vulnerabilities
web_server_apache_dos  
YELLOW CVE-2009-2703 libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
RED CVE-2009-2716 The plugin functionality in Sun Java SE 6 before Update 15 does not properly implement version selection, which allows context-dependent attackers to leverage vulnerabilities in "old zip and certificate handling" and have unspecified other impact via unknown vectors. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2718 The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from the window border to the Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2719 The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlp_file/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching Protocol (JNLP). VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2720 Unspecified vulnerability in the javax.swing.plaf.synth.SynthContext.isSubregion method in the Swing implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException in the Jemmy library) via unknown vectors. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2721 Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6406003. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2722 Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6429594. NOTE: this issue exists because of an incorrect fix for BugId 6406003. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2723 Unspecified vulnerability in deserialization in the Provider class in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, aka BugId 6444262. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2724 Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, related to a "3Y Race condition in reflection checks." VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2725 Asterisk vulnerabilities

Note: Authentication is required to detect this vulnerability
net_asterisk  
RED CVE-2009-2726 The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and 1.6.1.x before 1.6.1.4; Asterisk Business Edition A.x.x, B.x.x before B.2.5.9, C.2.x before C.2.4.1, and C.3.x before C.3.1; and Asterisk Appliance s800i 1.2.x before 1.3.0.3 does not use a maximum width when invoking sscanf style functions, which allows remote attackers to cause a denial of service (stack memory consumption) via SIP packets containing large sequences of ASCII decimal characters, as demonstrated via vectors related to (1) the CSeq value in a SIP header, (2) large Content-Length value, and (3) SDP. Asterisk vulnerabilities

Note: Authentication is required to detect this vulnerability
net_asterisk  
RED CVE-2009-2730 libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2732 The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string. ntop server vulnerability
web_tool_ntopver  
BROWN CVE-2009-2742 Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2743 IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2744 Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25." WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
BROWN CVE-2009-2747 The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 does not properly restrict access to UserRegistry object methods, which allows remote attackers to obtain sensitive information via a crafted method call. WebSphere vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_dev_webspherever  
RED CVE-2009-2753 Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3, allow remote attackers to execute arbitrary code via a crafted parameter size. INFORMIX vulnerabilities

Note: Authentication is required to detect this vulnerability
database_informix_idsver  
RED CVE-2009-2754 Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow. INFORMIX vulnerabilities
Legato NetWorker vulnerabilities

Note: Authentication is required to detect this vulnerability
database_informix_idsver
rpc_legatocategory_version
 
YELLOW CVE-2009-2762 wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2767 The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (OOPS) or possibly gain privileges via a CLOCK_MONOTONIC_RAW clock_nanosleep call that triggers a NULL pointer dereference. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-2768 The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by executing a shared flat binary, which triggers an access of an "uninitialized cred pointer." Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-2798 Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file. MacOSX vulnerabilities
QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
misc_quicktime
 
YELLOW CVE-2009-2799 Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file. MacOSX vulnerabilities
QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
misc_quicktime
 
YELLOW CVE-2009-2800 Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-2801 The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass intended access restrictions via packet data, related to a "timing issue." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2803 CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2804 Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow. MacOSX vulnerabilities
Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_client_safari
 
YELLOW CVE-2009-2805 Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2807 Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2808 Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-middle attackers to send a crafted help:runscript link, and thereby execute arbitrary code, via a spoofed response. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2809 ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PixarFilm encoded TIFF image, related to "multiple memory corruption issues." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2810 Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quarantined folder, which allows user-assisted remote attackers to execute arbitrary code via a quarantined application that does not trigger a "potentially unsafe" warning message. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2811 Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a .fileloc file, which does not trigger a "potentially unsafe" warning message in the Quarantine feature. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2812 Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
BROWN CVE-2009-2813 Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2814 Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script or HTML via a search request containing data that does not use UTF-8 encoding. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2816 The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web page. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2817 Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .pls file. iTunes vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_itunes  
YELLOW CVE-2009-2818 Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote attackers to obtain login access via a brute-force attack (aka dictionary attack). MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2819 AFP Client in Apple Mac OS X 10.5.8 allows remote AFP servers to execute arbitrary code or cause a denial of service (memory corruption and system crash) via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2820 The web interface in CUPS before 1.4.2, as used on Apple Mac OS X before 10.6.2 and other platforms, does not properly handle (1) HTTP headers and (2) HTML templates, which allows remote attackers to conduct cross-site scripting (XSS) attacks and HTTP response splitting attacks via vectors related to (a) the product's web interface, (b) the configuration of the print system, and (c) the titles of printed jobs, as demonstrated by an XSS attack that uses the kerberos parameter to the admin program, and leverages attribute injection and HTTP Parameter Pollution (HPP) issues. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2823 The Apache HTTP Server in Apple Mac OS X before 10.6.2 enables the HTTP TRACE method, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software. MacOSX vulnerabilities
Cross site tracing

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_server_trace
 
YELLOW CVE-2009-2824 Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code via a crafted embedded font in a document. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2825 Certificate Assistant in Apple Mac OS X before 10.6.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2826 Multiple integer overflows in CoreGraphics in Apple Mac OS X 10.5.8 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers a heap-based buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2827 Heap-based buffer overflow in Disk Images in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FAT filesystem on a disk image. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2828 The server in DirectoryService in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2829 Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2830 Multiple buffer overflows in Christos Zoulas file before 5.03 in Apple Mac OS X 10.6.x before 10.6.2 allow user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Common Document Format (CDF) file. NOTE: this might overlap CVE-2009-1515. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2831 Dictionary in Apple Mac OS X 10.5.8 allows remote attackers to create arbitrary files with any contents, and thereby execute arbitrary code, via crafted JavaScript, related to a "design issue." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2832 Buffer overflow in FTP Server in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a CWD command specifying a pathname in a deeply nested hierarchy of directories, related to a "CWD command line tool." MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2833 Buffer overflow in the UCCompareTextDefault API in International Components for Unicode in Apple Mac OS X 10.5.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2834 IOKit in Apple Mac OS X before 10.6.2 allows local users to modify the firmware of a (1) USB or (2) Bluetooth keyboard via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2835 The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2836 Race condition in Login Window in Apple Mac OS X 10.6.x before 10.6.2, when at least one account has a blank password, allows attackers to bypass password authentication and obtain login access to an arbitrary account via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2837 Heap-based buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image. MacOSX vulnerabilities
QuickTime vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
misc_quicktime
 
YELLOW CVE-2009-2838 Integer overflow in QuickLook in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document that triggers a buffer overflow. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2839 Screen Sharing in Apple Mac OS X 10.5.8 allows remote VNC servers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2840 Spotlight in Apple Mac OS X 10.5.8 does not properly handle temporary files, which allows local users to overwrite arbitrary files in the context of a different user's privileges via unspecified vectors. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-2841 The HTMLMediaElement::loadResource function in html/HTMLMediaElement.cpp in WebCore in WebKit before r49480, as used in Apple Safari before 4.0.4 on Mac OS X, does not perform the expected callbacks for HTML 5 media elements that have external URLs for media resources, which allows remote attackers to trigger sub-resource requests to arbitrary web sites via a crafted HTML document, as demonstrated by an HTML e-mail message that uses a media element for X-Confirm-Reading-To functionality, aka rdar problem 7271202. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-2842 Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
RED CVE-2009-2844 cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-2848 The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a clone system call with CLONE_CHILD_SETTID or CLONE_CHILD_CLEARTID enabled, which is not properly handled during thread creation and exit. VMWare ESX vulnerabilities
Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_linuxkernel
 
YELLOW CVE-2009-2851 Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2853 Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-2854 Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
RED
!
CVE-2009-2855 The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function. Squid vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
web_proxy_squid
web_proxy_squidstrlistdos
 
RED CVE-2009-2858 Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-2859 IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command. DB2 vulnerabilities
database_db2ver  
RED CVE-2009-2860 Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets." DB2 vulnerabilities
database_db2ver  
BROWN CVE-2009-2862 The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47076, CSCsv48603, CSCsy54122, and CSCsu50252. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2863 Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
RED CVE-2009-2864 Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423. Cisco voice products

Note: Authentication is required to detect this vulnerability
net_cisco_cucmver  
BROWN CVE-2009-2866 Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2867 Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2868 Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2869 Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2870 Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2871 Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2872 Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-2873 Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via malformed packets, aka Bug ID CSCsx70889. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
YELLOW CVE-2009-2880 Buffer overflow in atrpui.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and Linux allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WebEx Recording Format (WRF) file. Cisco WebEx Player vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ciscowrf  
RED CVE-2009-2901 The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests. MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_dev_tomcatver
 
RED CVE-2009-2902 Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename. MacOSX vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_dev_tomcatver
 
RED CVE-2009-2903 Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-2905 Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-2906 smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-2908 The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-2909 Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-2910 arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-2935 Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
RED CVE-2009-2948 mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option. Samba vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
win_samba  
YELLOW CVE-2009-2949 Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
YELLOW CVE-2009-2950 Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
RED CVE-2009-2957 Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request. Dnsmasq TFTP vulnerabilities
ftp_dnsmasqtftp  
YELLOW CVE-2009-2964 Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, allow remote attackers to hijack the authentication of unspecified victims via features such as send message and change preferences, related to (1) functions/mailbox_display.php, (2) src/addrbook_search_html.php, (3) src/addressbook.php, (4) src/compose.php, (5) src/folders.php, (6) src/folders_create.php, (7) src/folders_delete.php, (8) src/folders_rename_do.php, (9) src/folders_rename_getname.php, (10) src/folders_subscribe.php, (11) src/move_messages.php, (12) src/options.php, (13) src/options_highlight.php, (14) src/options_identities.php, (15) src/options_order.php, (16) src/search.php, and (17) src/vcard.php. SquirrelMail vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_web_squirrel
misc_macosx_version
 
YELLOW CVE-2009-2966 avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters. Kaspersky AntiVirus vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_kaspersky_avver2k10  
YELLOW CVE-2009-2979 Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2980 Integer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2981 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to bypass intended Trust Manager restrictions via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2982 An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers to conduct a "social engineering attack" via unknown vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2983 Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2984 Unspecified vulnerability in the image decoder in Adobe Acrobat 9.x before 9.2, and possibly 7.x through 7.1.4 and 8.x through 8.1.7, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2985 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2996. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2986 Multiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2987 Unspecified vulnerability in an ActiveX control in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Windows allows remote attackers to cause a denial of service via unknown vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2988 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which allows attackers to cause a denial of service via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2989 Integer overflow in Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2990 Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2991 Unspecified vulnerability in the Mozilla plug-in in Adobe Reader and Acrobat 8.x before 8.1.7, and possibly 7.x before 7.1.4 and 9.x before 9.2, might allow remote attackers to execute arbitrary code via unknown vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2992 An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2993 The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2994 Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2995 Integer overflow in Adobe Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows attackers to cause a denial of service via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2996 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2985. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2997 Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-2998 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3001 The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-3002 The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-3009 Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-3023 Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability." IIS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
win_patch_iisftpbo  
YELLOW CVE-2009-3025 Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-3026 protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-3028 The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method. Altiris vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_symantec_altirisdl  
YELLOW CVE-2009-3031 Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument. Altiris vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_symantecaltirisconsole  
YELLOW CVE-2009-3032 Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow. Lotus Notes email client vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_noteskvole  
YELLOW CVE-2009-3037 Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment. Lotus Notes email client vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_notesxlssr  
YELLOW CVE-2009-3043 The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via certain pseudo-terminal I/O activity, as demonstrated by KernelTtyTest.c. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3044 Opera before 10.00 does not properly handle a (1) '\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3045 Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted server certificate. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3046 Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote SSL servers to bypass validation of the certificate chain via a revoked certificate. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3047 Opera before 10.00, when a collapsed address bar is used, does not properly update the domain name from the previously visited site to the currently visited site, which might allow remote attackers to spoof URLs. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3048 Opera before 10.00 on Linux, Solaris, and FreeBSD does not properly implement the "INPUT TYPE=file" functionality, which allows remote attackers to trick a user into uploading an unintended file via vectors involving a "dropped file." Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3049 Opera before 10.00 does not properly display all characters in Internationalized Domain Names (IDN) in the address bar, which allows remote attackers to spoof URLs and conduct phishing attacks, related to Unicode and Punycode. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
RED CVE-2009-3068 Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11. Adobe RoboHelp Server vulnerabilities
misc_adobe_robohelpserverfile  
YELLOW CVE-2009-3069 Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3070 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3071 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3072 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3073 Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3074 Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3075 Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3076 Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3077 Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability." Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3078 Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3079 Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3080 Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3083 The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-3084 The msn_slp_process_msg function in libpurple/protocols/msn/slpcall.c in the MSN protocol plugin in libpurple 2.6.0 and 2.6.1, as used in Pidgin before 2.6.2, allows remote attackers to cause a denial of service (application crash) via a handwritten (aka Ink) message, related to an uninitialized variable and the incorrect "UTF16-LE" charset name. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
YELLOW CVE-2009-3085 The XMPP protocol plugin in libpurple in Pidgin before 2.6.2 does not properly handle an error IQ stanza during an attempted fetch of a custom smiley, which allows remote attackers to cause a denial of service (application crash) via XHTML-IM content with cid: images. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
RED CVE-2009-3087 Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. Lotus Domino HTTP vulnerability
web_server_lotus_domino  
YELLOW CVE-2009-3094 The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. Apache module vulnerabilities
web_mod_proxyftp  
YELLOW CVE-2009-3095 The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. MacOSX vulnerabilities
Apache module vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_mod_proxyftp
 
RED CVE-2009-3103 Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information. Windows updates needed
win_patch_smbv2ms09050  
YELLOW CVE-2009-3107 Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service. Altiris vulnerabilities
misc_av_symantec_altirisver  
YELLOW CVE-2009-3108 The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program. Altiris vulnerabilities
misc_av_symantec_altirisver  
YELLOW CVE-2009-3109 Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed. Altiris vulnerabilities
misc_av_symantec_altirisver  
YELLOW CVE-2009-3110 Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does. Altiris vulnerabilities
misc_av_symantec_altirisver  
RED CVE-2009-3111 The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967. RADIUS vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_freeradius
misc_macosx_version
 
YELLOW CVE-2009-3114 The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K. Lotus Notes RSS reader client vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_lotusnotesrss  
RED CVE-2009-3125 SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters. Bugzilla vulnerabilities
web_prog_cgi_bugzilla  
YELLOW CVE-2009-3126 Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka "GDI+ PNG Integer Overflow Vulnerability." Microsoft SQL Server
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_mssql_mssql
win_patch_gdiplus09062
 
YELLOW CVE-2009-3127 Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Cache Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2003
win_patch_excelview
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3128 Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel SxView Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2003
win_patch_excelview
win_patch_excelxp
 
YELLOW CVE-2009-3129 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3130 Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a spreadsheet containing a malformed Binary File Format (aka BIFF) record that triggers memory corruption, aka "Excel Document Parsing Heap Overflow Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3131 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet with a crafted formula embedded in a cell, aka "Excel Formula Parsing Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3132 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed formula, related to a "pointer corruption" issue, aka "Excel Index Parsing Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3133 Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3134 Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel Field Sanitization Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_excel2003
win_patch_excel2007
win_patch_excelcpack
win_patch_excelview
win_patch_excelview2007
win_patch_excelxp
win_patch_office2004macver
win_patch_office2008macver
 
YELLOW CVE-2009-3135 Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word document with a malformed File Information Block (FIB) structure, aka "Microsoft Office Word File Information Memory Corruption Vulnerability." Microsoft Office vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_office2004macver
win_patch_office2008macver
win_patch_word2003
win_patch_wordview2003
win_patch_wordxp
 
RED CVE-2009-3165 SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters. Bugzilla vulnerabilities
web_prog_cgi_bugzilla  
YELLOW CVE-2009-3166 token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. Bugzilla vulnerabilities
web_prog_cgi_bugzilla  
RED CVE-2009-3228 The tc_fill_tclass function in net/sched/sch_api.c in the tc subsystem in the Linux kernel 2.4.x before 2.4.37.6 and 2.6.x before 2.6.31-rc9 does not initialize certain (1) tcm__pad1 and (2) tcm__pad2 structure members, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-3229 The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory. PostgreSQL vulnerabilities
HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_pgsql
net_ovnodemgriver
 
YELLOW CVE-2009-3230 The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600. PostgreSQL vulnerabilities
HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_pgsql
net_ovnodemgriver
 
YELLOW CVE-2009-3231 The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. PostgreSQL vulnerabilities
HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_pgsql
net_ovnodemgriver
 
YELLOW CVE-2009-3234 Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3235 Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-3236 The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements. Horde vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_horde  
YELLOW CVE-2009-3237 Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or HTML via the (1) crafted number preferences that are not properly handled in the preference system (services/prefs.php), as demonstrated by the sidebar_width parameter; or (2) crafted unknown MIME "text parts" that are not properly handled in the MIME viewer library (config/mime_drivers.php). Horde vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_horde  
RED CVE-2009-3241 Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-3242 Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-3243 Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-3244 Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
RED CVE-2009-3245 OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors. MacOSX vulnerabilities
OpenSSL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
misc_openssl
 
YELLOW CVE-2009-3263 Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content." Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-3264 The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
YELLOW CVE-2009-3265 Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the vendor reportedly considers this behavior a "design feature," not a vulnerability. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3266 Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content." Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3270 Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821. iTunes vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_itunes  
YELLOW CVE-2009-3272 Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
RED CVE-2009-3274 Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-3280 Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel before 2.6.31.1-rc1 allows remote attackers to cause a denial of service (soft lockup) via malformed packets. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3286 NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3288 The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstrated by using xcdroast to duplicate a CD. NOTE: this is only exploitable by users who can open the cdrom device. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3290 The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions before 2.6.31, when running on x86 systems, does not prevent access to MMU hypercalls from ring 0, which allows local guest OS users to cause a denial of service (guest kernel crash) and read or write guest kernel memory via unspecified "random addresses." Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3291 The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-3292 Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing." MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-3293 Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index." MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
RED CVE-2009-3294 The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function. PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_version  
RED CVE-2009-3295 The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request. Kerberos detected

Note: Authentication is required to detect this vulnerability
misc_kerberospkg  
YELLOW CVE-2009-3301 Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
YELLOW CVE-2009-3302 filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw." OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
RED CVE-2009-3340 Unspecified vulnerability in FreeSSHD 1.2.4 allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. wodSSHServer vulnerabilities
shell_ssh_wod  
YELLOW CVE-2009-3370 Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3371 Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3372 Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3373 Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3374 The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects." Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3375 content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3376 Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3377 Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3378 The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3379 Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3380 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3381 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3382 layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3383 Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3384 Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply. Safari vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_safari  
YELLOW CVE-2009-3388 liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues." Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3389 Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
BROWN CVE-2009-3407 Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-0983. Oracle vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias  
BROWN CVE-2009-3410 Unspecified vulnerability in the RDBMS component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-3411 Unspecified vulnerability in the Oracle Data Pump component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-3412 Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5; and Oracle Application Server 10.1.2.3; allows local users to affect confidentiality via unknown vectors. Oracle vulnerabilities
Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_ias
database_oracle_version
 
BROWN CVE-2009-3413 Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3414. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-3414 Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3413. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
BROWN CVE-2009-3415 Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. Oracle Database vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version  
YELLOW CVE-2009-3431 Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
RED CVE-2009-3436 Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417. SQL injection
web_prog_sql_maxwebportal  
RED CVE-2009-3445 Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command. Ability Server mail vulnerabilities
mail_imap_abilityver  
RED CVE-2009-3448 npvmgr.exe in BakBone NetVault Backup 8.22 Build 29 allows remote attackers to cause a denial of service (daemon crash) via a packet to (1) TCP or (2) UDP port 20031 with a large value in an unspecified size field, which is not properly handled in a malloc operation. NOTE: some of these details are obtained from third party information. NetVault vulnerabilities
misc_netvault  
YELLOW CVE-2009-3458 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3459 Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained from third party information. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3460 Adobe Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3461 Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3462 Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 on Unix, when Debug mode is enabled, allow attackers to execute arbitrary code via unspecified vectors, related to a "format bug." Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3463 Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-3464 Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3465. NOTE: some of these details are obtained from third party information. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-3465 Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site, related to an "invalid pointer vulnerability," a different issue than CVE-2009-3464. NOTE: some of these details are obtained from third party information. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-3466 Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption, related to an "invalid string length vulnerability." NOTE: some of these details are obtained from third party information. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-3469 Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. Lotus Connections vulnerabilities
web_server_lotusconnections  
RED CVE-2009-3470 IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows remote attackers to cause a denial of service (memory corruption, assertion failure, and daemon crash) by sending a long password over a JDBC connection. INFORMIX vulnerabilities

Note: Authentication is required to detect this vulnerability
database_informix_idsver  
YELLOW CVE-2009-3471 IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain table functions upon a loss of privileges by the functions' definers, which has unspecified impact and remote attack vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-3472 IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-3473 IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-3485 Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI. Cross site scripting
web_server_css  
YELLOW CVE-2009-3518 Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname. IBM InstallationManager vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ibmim  
YELLOW CVE-2009-3522 Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018. Avast vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_avasthomepro  
YELLOW CVE-2009-3523 aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625. Avast vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_avasthomepro  
YELLOW CVE-2009-3524 Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors. Avast vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_avasthomepro  
RED CVE-2009-3545 DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command. FtpXQ vulnerabilities
ftp_ftpxq  
BROWN CVE-2009-3546 The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information. PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_version  
RED CVE-2009-3547 Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname. VMWare ESX vulnerabilities
Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_linuxkernel
 
RED CVE-2009-3548 The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges. HP Performance Manager vulnerabilities
Apache Tomcat vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_hpperformancebypass
web_dev_tomcatpass
web_dev_tomcatver
 
RED CVE-2009-3549 packet-paltalk.c in the Paltalk dissector in Wireshark 1.2.0 through 1.2.2, on SPARC and certain other platforms, allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-3550 The DCERPC/NT dissector in Wireshark 0.10.10 through 1.0.9 and 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained from third party information. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-3551 Off-by-one error in the dissect_negprot_response function in packet-smb.c in the SMB dissector in Wireshark 1.2.0 through 1.2.2 allows remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace. NOTE: some of these details are obtained from third party information. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-3553 Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information. MacOSX vulnerabilities
CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
printer_cupsversion
 
YELLOW CVE-2009-3554 Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file. HP Openview vulnerabilities
JBoss Application Server

Note: Authentication is required to detect this vulnerability
net_ovnodemgriver
web_dev_jbossasver
 
RED CVE-2009-3555 The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue. Oracle Database vulnerabilities
MacOSX vulnerabilities
OpenSSL vulnerabilities
TLS Renegotiation vulnerability
HP Openview vulnerabilities
Java Plugin vulnerability
WebLogic vulnerabilities
HP Systems Insight Manager
Windows updates needed

Note: Authentication is recommended to improve the accuracy of this check
database_oracle_version
misc_macosx_version
misc_openssl
misc_opensslrenegotiation
net_ovnodemgriver
web_client_jre
web_dev_jdk
web_dev_weblogic
web_tool_hpsim
win_patch_schannelexe
 
RED CVE-2009-3556 A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-3557 The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
RED CVE-2009-3558 The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass open_basedir restrictions, and create FIFO files, via the pathname and mode arguments, as demonstrated by creating a .htaccess file. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-3559 main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which allows context-dependent attackers to have an unknown impact by triggering the failure of PHP scripts that perform include or require operations, as demonstrated by a script that attempts to perform a require_once on a file in a standard library directory. NOTE: a reliable third party reports that this is not a vulnerability, because it results in a more restrictive security policy. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
RED CVE-2009-3560 The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in lib/xmlparse.c, a different vulnerability than CVE-2009-2625 and CVE-2009-3720. VMWare ESX vulnerabilities
iTunes vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_esxbuild
misc_itunes
web_server_apache_version
 
RED CVE-2009-3563 ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons. VMWare ESX vulnerabilities
NTP vulnerabilities
misc_esxbuild
misc_ntpdver
 
BROWN CVE-2009-3566 McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability. HTTPOnly Cookies
web_security_httponly  
YELLOW CVE-2009-3569 Stack-based buffer overflow in OpenOffice.org (OOo) allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side stack overflow exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
YELLOW CVE-2009-3570 Unspecified vulnerability in OpenOffice.org (OOo) has unspecified impact and remote attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9. NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
YELLOW CVE-2009-3571 Unspecified vulnerability in OpenOffice.org (OOo) has unknown impact and client-side attack vector, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, aka "Client-side exploit." NOTE: as of 20091005, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. OpenOffice vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openoffice  
RED CVE-2009-3586 Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2007-4060. CoreHTTP vulnerabilities
web_server_corehttp  
YELLOW CVE-2009-3587 Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted RAR archive file that triggers heap corruption, a different vulnerability than CVE-2009-3588. CA Multiple Product vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_arclib  
YELLOW CVE-2009-3588 Unspecified vulnerability in the arclib component in the Anti-Virus engine in CA Anti-Virus for the Enterprise (formerly eTrust Antivirus) 7.1 through r8.1; Anti-Virus 2007 (v8) through 2009; eTrust EZ Antivirus r7.1; Internet Security Suite 2007 (v3) through Plus 2009; and other CA products allows remote attackers to cause a denial of service via a crafted RAR archive file that triggers stack corruption, a different vulnerability than CVE-2009-3587. CA Multiple Product vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_arclib  
YELLOW CVE-2009-3602 Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses. unbound vulnerabilities
dns_unbound  
YELLOW CVE-2009-3608 Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, CUPS pdftops, and teTeX, might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
YELLOW CVE-2009-3609 Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1, as used in GPdf, kdegraphics KPDF, and CUPS pdftops, allows remote attackers to cause a denial of service (application crash) via a crafted PDF document that triggers a NULL pointer dereference or buffer over-read. CUPS vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
printer_cupsversion  
RED CVE-2009-3612 The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2005-4881. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-3613 The swiotlb functionality in the r8169 driver in drivers/net/r8169.c in the Linux kernel before 2.6.27.22 allows remote attackers to cause a denial of service (IOMMU space exhaustion and system crash) by using jumbo frames for a large amount of network traffic, as demonstrated by a flood ping. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-3615 The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a denial of service (application crash) via crafted contact-list data for (1) ICQ and possibly (2) AIM, as demonstrated by the SIM IM client. Gaim vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gaim  
RED CVE-2009-3620 The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-3621 net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-3622 Algorithmic complexity vulnerability in wp-trackback.php in WordPress before 2.8.5 allows remote attackers to cause a denial of service (CPU consumption and server hang) via a long title parameter in conjunction with a charset parameter composed of many comma-separated "UTF-8" substrings, related to the mb_convert_encoding function in PHP. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-3626 Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match. perl vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_lang_perl  
RED CVE-2009-3639 The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, which allows remote attackers to bypass intended client-hostname restrictions via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. ProFTPD vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
ftp_proftp  
YELLOW CVE-2009-3646 InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name. NaviCOPA vulnerabilities
web_server_navicopaver  
RED CVE-2009-3655 Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command. Serv U vulnerabilities
ftp_servu  
RED CVE-2009-3662 FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafted NOOP commands. FileCOPA FTP vulnerabilities
ftp_filecopa  
YELLOW CVE-2009-3663 Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header. httpdx vulnerabilities
web_server_httpdx  
YELLOW CVE-2009-3671 Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3674. Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v8  
YELLOW CVE-2009-3672 Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method for the STYLE tag name, selection of the single element in the returned list, and a change to the outerHTML property of this element, related to Cascading Style Sheets (CSS) and mshtml.dll, aka "HTML Object Memory Corruption Vulnerability." NOTE: some of these details are obtained from third party information. NOTE: this issue was originally assigned CVE-2009-4054, but Microsoft assigned a duplicate identifier of CVE-2009-3672. CVE consumers should use this identifier instead of CVE-2009-4054. Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v6
win_patch_ie_v7
 
YELLOW CVE-2009-3673 Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v7
win_patch_ie_v8
 
YELLOW CVE-2009-3674 Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671. Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v8  
YELLOW CVE-2009-3675 LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote authenticated users to cause a denial of service (CPU consumption) via a malformed ISAKMP request over IPsec, aka "Local Security Authority Subsystem Service Resource Exhaustion Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_lsassdosipsec  
YELLOW CVE-2009-3676 The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_smb10020  
YELLOW CVE-2009-3677 The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_authsrv  
YELLOW CVE-2009-3678 Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability." Windows updates needed

Note: Authentication is required to detect this vulnerability
win_patch_canonicaldispdriver  
YELLOW CVE-2009-3693 Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method. HP Mercury LoadRunner vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_mercuryloadrunnerax  
YELLOW CVE-2009-3696 Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name for a MySQL table. phpMyAdmin vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_myadminver  
RED CVE-2009-3697 SQL injection vulnerability in the PDF schema generator functionality in phpMyAdmin 2.11.x before 2.11.9.6 and 3.x before 3.2.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified interface parameters. phpMyAdmin vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_myadminver  
RED CVE-2009-3699 Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd. calendar manager
rpc_cmsd  
YELLOW CVE-2009-3701 Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable. Horde vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_horde  
RED CVE-2009-3707 VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information. VMware vulnerabilities
VMware authd vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_acever
misc_vmware_authd
misc_vmware_serverver
misc_vmwareplayerver
misc_vmwarewkstnver
 
RED CVE-2009-3720 The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625. VMWare ESX vulnerabilities
iTunes vulnerabilities
Apache vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_esxbuild
misc_itunes
web_server_apache_version
 
YELLOW CVE-2009-3722 The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) on the host OS via a crafted application. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3726 The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-3727 Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames via multiple crafted REGISTER messages with inconsistent usernames in the URI in the To header and the Digest in the Authorization header. Asterisk vulnerabilities

Note: Authentication is required to detect this vulnerability
net_asterisk  
RED CVE-2009-3728 Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local International Color Consortium (ICC) profile files via a .. (dot dot) in a pathname, aka Bug Id 6631533. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3729 Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Update 17 allows remote attackers to cause a denial of service (application crash) via a certain test suite, aka Bug Id 6815780. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3733 Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors. VMWare ESX vulnerabilities
VMware vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_vmware_esxtrav
misc_vmware_servertrav
misc_vmware_serverver
 
RED CVE-2009-3736 ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-3743 Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow. Ghostscript vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ghostscriptver  
RED
!
CVE-2009-3744 rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted packet to TCP port 7144. EMC RepliStor vulnerabilities

Note: Authentication is required to detect this vulnerability unless dangerous checks are enabled
misc_emcreplistordos  
YELLOW CVE-2009-3767 libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. OpenLDAP vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_openldap  
RED CVE-2009-3791 Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (resource exhaustion) via unknown vectors. Flash Media Server vulnerabilities
web_server_flashmedia  
RED CVE-2009-3792 Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors. Flash Media Server vulnerabilities
web_server_flashmedia  
YELLOW CVE-2009-3793 Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory consumption) or possibly execute arbitrary code via unknown vectors. Flash vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash  
YELLOW CVE-2009-3794 Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3796 Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3797 Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3798 Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3799 Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers." Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3800 Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3829 Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability." Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-3831 Opera before 10.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted domain name. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3832 Opera before 10.01 on Windows does not prevent use of Web fonts in rendering the product's own user interface, which allows remote attackers to spoof the address field via a crafted web site. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-3838 Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message. Pegasus vulnerabilities

Note: Authentication is required to detect this vulnerability
mail_client_pegasus  
RED
!
CVE-2009-3840 The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service (daemon crash) via an invalid Error Code field in a packet. HP Openview vulnerabilities
net_ovnodemgrdbdos  
RED CVE-2009-3843 HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload. HP Operations Manager Server vulnerabilities
misc_hpoperationsupload  
RED CVE-2009-3846 Multiple heap-based buffer overflows in ovlogin.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a long (1) userid or (2) passwd parameter. HP Openview vulnerabilities
net_ovloginbo  
RED CVE-2009-3848 Stack-based buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Template parameter, related to the vsprintf function. HP Openview vulnerabilities
net_ovnnmrptconfig  
RED CVE-2009-3849 Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long Template parameter to nnmRptConfig.exe, related to the strcat function; or (2) a long Oid parameter to snmp.exe. HP Openview vulnerabilities
net_ovsnmpbo  
RED
!
CVE-2009-3853 Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet. Tivoli Storage Manager
misc_tivolicategory_storageclientcadbo
misc_tivolicategory_storagever
 
RED CVE-2009-3862 The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value. Novell eDirectory

Note: Authentication is required to detect this vulnerability
misc_edirectoryver  
RED CVE-2009-3864 The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3865 The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3866 The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824. VMWare ESX vulnerabilities
Java Web Start
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_javawebstart
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3867 Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3868 Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3869 Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3871 Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3872 Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3873 The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3874 Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3875 The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3876 Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3877 Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911. VMWare ESX vulnerabilities
HP Openview vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
net_ovnodemgriver
web_client_jre
web_dev_jdk
 
RED CVE-2009-3879 Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3880 The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not properly restrict the objects that may be sent to loggers, which allows attackers to obtain sensitive information via vectors related to the implementation of Component, KeyboardFocusManager, and DefaultKeyboardFocusManager, aka Bug Id 6664512. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3881 Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a resurrected ClassLoader, which allows remote attackers to gain privileges via unspecified vectors, related to an "information leak vulnerability," aka Bug Id 6636650. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3882 Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657026. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3883 Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657138. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3884 The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote attackers to determine the existence of local files via vectors related to handling of zoneinfo (aka tz) files, aka Bug Id 6824265. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3885 Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service via a BMP file containing a link to a UNC share pathname for an International Color Consortium (ICC) profile file, probably a related issue to CVE-2007-2789, aka Bug Id 6632445. VMWare ESX vulnerabilities
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
web_client_jre
web_dev_jdk
 
RED CVE-2009-3886 The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a signed JAR file and a JNLP (1) application or (2) applet, which has unspecified impact and attack vectors, related to a "regression," aka Bug Id 6870531. VMWare ESX vulnerabilities
Java Web Start
Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_javawebstart
web_client_jre
web_dev_jdk
 
YELLOW CVE-2009-3888 The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-3889 The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file. VMWare ESX vulnerabilities
misc_esxbuild  
BROWN CVE-2009-3890 Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename. WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
YELLOW CVE-2009-3891 Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable). WordPress vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_wordpress  
RED
!
CVE-2009-3896 src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI. nginx HTTP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
web_server_nginx
web_server_nginxbo
 
RED CVE-2009-3902 Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL. http server read access
web_server_read  
YELLOW CVE-2009-3910 Java Plugin vulnerability

Note: Authentication is required to detect this vulnerability
web_client_jre
web_dev_jdk
 
YELLOW CVE-2009-3934 The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail. Google Chrome vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_googlechrome  
RED CVE-2009-3939 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-3951 Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 on Windows allows remote attackers to obtain the names of local files via unknown vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4820. Flash vulnerabilities
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_flash
misc_macosx_version
 
YELLOW CVE-2009-3952 Buffer overflow in Adobe Illustrator CS3 13.0.3 and earlier and Illustrator CS4 14.0.0 allows attackers to execute arbitrary code via unspecified vectors. Adobe Illustrator vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_adobe_illustratorcs3
misc_adobe_illustratorcs4
 
YELLOW CVE-2009-3953 The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3954 The 3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to execute arbitrary code via unspecified vectors, related to a "DLL-loading vulnerability." Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3955 Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign extension that bypasses a sanity check, leading to memory corruption. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3956 The default configuration of Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, does not enable the Enhanced Security feature, which has unspecified impact and attack vectors, related to a "script injection vulnerability," as demonstrated by Acrobat Forms Data Format (FDF) behavior that allows cross-site scripting (XSS) by user-assisted remote attackers. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3957 Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow attackers to cause a denial of service (NULL pointer dereference) via unspecified vectors. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3958 Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-3959 Integer overflow in the U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a malformed PDF document. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
RED CVE-2009-3963 Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors. XOOPS vulnerabilities
web_prog_php_xoopsmydirver  
RED CVE-2009-3974 Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) search_term parameter to admin/applications/core/modules_public/search/search.php and (2) aid parameter to admin/applications/core/modules_public/global/lostpass.php. NOTE: on 20090818, the vendor patched 3.0.2 without changing the version number. Invision Power Board
web_prog_php_ipbversion  
YELLOW CVE-2009-3976 Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message). LabTam ProFTP vulnerabilities

Note: Authentication is required to detect this vulnerability
ftp_labtamproftp  
YELLOW CVE-2009-3978 The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-3979 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3980 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3981 Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3982 Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3983 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3984 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3985 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3986 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3987 The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3988 Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox
web_client_seamonkey
 
YELLOW CVE-2009-3995 Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file. NOTE: some of these details are obtained from third party information. Winamp vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_winampver  
YELLOW CVE-2009-3996 Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file. Winamp vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_winampver  
YELLOW CVE-2009-3997 Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary code via an Oktalyzer file that triggers a heap-based buffer overflow. Winamp vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_winampver  
RED
!
CVE-2009-3999 Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter. HP Power Manager vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check unless dangerous checks are enabled
misc_powermanagerbo  
RED CVE-2009-4000 Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter. HP Power Manager vulnerabilities
misc_powermanagerdt  
YELLOW CVE-2009-4002 Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
YELLOW CVE-2009-4003 Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption. Shockwave vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_shockwave  
RED CVE-2009-4006 Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string. Serv U vulnerabilities
ftp_servu  
RED CVE-2009-4009 Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets. PowerDNS vulnerabilities
dns_powerrecursor  
YELLOW CVE-2009-4010 Unspecified vulnerability in PowerDNS Recursor before 3.1.7.2 allows remote attackers to spoof DNS data via crafted zones. PowerDNS vulnerabilities
dns_powerrecursor  
RED CVE-2009-4017 PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-4018 The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable. PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_version  
YELLOW CVE-2009-4019 mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement. MySQL vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version
misc_macosx_version
 
RED CVE-2009-4020 Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-4021 The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer dereference and OOPS) via vectors possibly related to a memory-consumption attack. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
BROWN CVE-2009-4022 Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. DNS vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
dns_bindver
misc_macosx_version
 
RED CVE-2009-4026 The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA) packet, related to an erroneous "code shuffling patch." Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-4027 Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block ACK (aka DELBA) packet that triggers a certain state change in the absence of an aggregation session. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
BROWN CVE-2009-4028 The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library. MySQL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version  
YELLOW CVE-2009-4030 MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL data home directory, related to incorrect calculation of the mysql_unpacked_real_data_home value. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4098 and CVE-2008-2079. MySQL vulnerabilities
MacOSX vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version
misc_macosx_version
 
YELLOW CVE-2009-4031 The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to cause a denial of service (increased scheduling latency) on the host OS via unspecified manipulations related to SMP support. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
BROWN CVE-2009-4034 PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based PostgreSQL servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended client-hostname restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. HP Openview vulnerabilities

Note: Authentication is required to detect this vulnerability
net_ovnodemgriver  
YELLOW CVE-2009-4048 Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DELE command to a second socket. XM FTP vulnerabilities
ftp_xm  
YELLOW CVE-2009-4049 Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted arguments to IOCTL 0x80002024. Avast vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_avasthomepro  
RED CVE-2009-4051 Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands. Home FTP vulnerabilities

Note: Authentication is required to detect this vulnerability
ftp_homever  
RED CVE-2009-4053 Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Home FTP vulnerabilities

Note: Authentication is required to detect this vulnerability
ftp_homever  
RED CVE-2009-4055 rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.x before B.2.5.13, C.2.x.x before C.2.4.6, and C.3.x.x before C.3.2.3; and s800i 1.3.x before 1.3.0.6 allows remote attackers to cause a denial of service (daemon crash) via an RTP comfort noise payload with a long data length. Asterisk vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
net_asteriskver  
BROWN CVE-2009-4071 Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a different web site, which allows remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via unspecified vectors. Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-4072 Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue." Opera vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_opera9  
YELLOW CVE-2009-4074 The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability." Internet Explorer vulnerabilities

Note: Authentication is required to detect this vulnerability
win_patch_ie_v8  
YELLOW CVE-2009-4086 CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information. Xerver vulnerabilities
web_server_xerver  
RED CVE-2009-4105 TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command without sending file data in between these two commands. TYPSoft FTP vulnerabilities
ftp_typsoft  
RED CVE-2009-4108 XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of files or directories, then performing a LIST command. XM FTP vulnerabilities
ftp_xm  
YELLOW CVE-2009-4109 The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information. DotNetNuke vulnerabilities
web_prog_asp_dotnetnukever  
YELLOW CVE-2009-4110 Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page. DotNetNuke vulnerabilities
web_prog_asp_dotnetnukever  
YELLOW CVE-2009-4112 Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands. Cacti vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_cacti  
YELLOW CVE-2009-4114 kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cause a denial of service (system crash) via IOCTL requests using crafted kernel addresses that trigger memory corruption, possibly related to klavemu.kdl. Kaspersky AntiVirus vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_kaspersky_avver2k10  
RED CVE-2009-4115 Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inject arbitrary PHP code into data/category.db.php via the (1) category and (2) Icon URL fields; or (3) inject arbitrary PHP code into data/ipban.php via the add_ip parameter. CuteNews vulnerabilities
web_prog_php_cutenewsver  
YELLOW CVE-2009-4118 The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running. Cisco VPN Client vulnerabilities

Note: Authentication is required to detect this vulnerability
net_cisco_vpnclientver  
YELLOW CVE-2009-4131 The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to overwrite arbitrary files via a crafted request, related to insufficient checks for file permissions. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-4134 Buffer underflow in the rgbimg module in Python 2.5 allows remote attackers to cause a denial of service (application crash) via a large ZSIZE value in a black-and-white (aka B/W) RGB image that triggers an invalid pointer dereference. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-4136 PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not properly manage session-local state during execution of an index function by a database superuser, which allows remote authenticated users to gain privileges via a table with crafted index functions, as demonstrated by functions that modify (1) search_path or (2) a prepared statement, a related issue to CVE-2007-6600 and CVE-2009-3230. PostgreSQL vulnerabilities
HP Openview vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_pgsql
net_ovnodemgriver
 
YELLOW CVE-2009-4138 drivers/firewire/ohci.c in the Linux kernel before 2.6.32-git9, when packet-per-buffer mode is used, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unknown other impact via an unspecified ioctl associated with receiving an ISO packet that contains zero in the payload-length field. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-4141 Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
YELLOW CVE-2009-4142 The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-4143 PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive. MacOSX vulnerabilities
PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
misc_macosx_version
web_prog_php_version
 
YELLOW CVE-2009-4149 Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter. CA Service Desk vulnerabilities

Note: Authentication is required to detect this vulnerability
web_prog_casdxss  
YELLOW CVE-2009-4171 An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument. Yahoo Messenger vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_yahoomsgrver  
RED CVE-2009-4176 Multiple heap-based buffer overflows in ovsessionmgr.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a long (1) userid or (2) passwd parameter to ovlogin.exe. HP Openview vulnerabilities
net_ovsessionmgrbo  
RED CVE-2009-4178 Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter. HP Openview vulnerabilities
net_ovwebhelpbo  
RED
!
CVE-2009-4179 Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Accept-Language header in an OVABverbose action. HP Openview vulnerabilities
net_ovnodemgralarmlangbo  
RED CVE-2009-4180 Stack-based buffer overflow in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header. HP Openview vulnerabilities
net_ovsnmpviewerbo  
RED CVE-2009-4181 Stack-based buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via vectors involving the sel and arg parameters to jovgraph.exe. HP Openview vulnerabilities
net_ovwebsnmpsrvbo  
YELLOW CVE-2009-4185 Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter. HP SMH vulnerabilities
web_tool_hpsmh  
YELLOW CVE-2009-4195 Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. NOTE: some of these details are obtained from third party information. Adobe Illustrator vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_adobe_illustratorcs3
misc_adobe_illustratorcs4
 
RED CVE-2009-4212 Multiple integer underflows in the (1) AES and (2) RC4 decryption functionality in the crypto library in MIT Kerberos 5 (aka krb5) 1.3 through 1.6.3, and 1.7 before 1.7.1, allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid. VMWare ESX vulnerabilities
Kerberos detected
MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_esxbuild
misc_kerberospkg
misc_macosx_version
 
YELLOW CVE-2009-4214 Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb. MacOSX vulnerabilities
Ruby on Rails vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version
web_dev_rubyonrails
 
YELLOW CVE-2009-4225 Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method. CA Internet Security Suite vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_caisspestpatrol  
YELLOW CVE-2009-4241 Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger heap memory corruption. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4242 Heap-based buffer overflow in the CGIFCodec::GetPacketBuffer function in datatype/image/gif/common/gifcodec.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via a GIF file with crafted chunk sizes that trigger improper memory allocation. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4243 RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to have an unspecified impact via a crafted media file that uses HTTP chunked transfer coding, related to an "overflow." RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4244 Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via an SIPR codec field with a small length value that triggers incorrect memory allocation. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4245 Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a compressed GIF file, related to gifcodec.cpp and gifimage.cpp. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4246 Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows user-assisted remote attackers to execute arbitrary code via a malformed .RJS skin file that contains a web.xmb file with crafted length values. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4247 Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an ASM RuleBook with a large number of rules, related to an "array overflow." RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4248 Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted RTSP SET_PARAMETER request. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4257 Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths. RealPlayer vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_reallinux
misc_realplayer
misc_realplayercategory_macver
 
YELLOW CVE-2009-4261 Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.0.4, and 2.1.0 before 2.1.0~rc2 allow (1) remote attackers to execute arbitrary programs via a crafted external script name supplied through the HTTP remote API (RAPI) and allow (2) local users to execute arbitrary programs and gain privileges via a crafted external script name supplied through a gnt-* command, related to "path sanitization errors." Ganeti vulnerabilities
misc_ganetiver  
RED CVE-2009-4272 A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a routing "emergency" in which a hash chain is too long. NOTE: this is related to an issue in the Linux kernel before 2.6.31, when the kernel routing cache is disabled, involving an uninitialized pointer and a panic. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-4307 The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value). Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-4321 extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NOTE: some of these details are obtained from third party information. vulnerable web program
web_prog_php_zencart  
YELLOW CVE-2009-4324 Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009. Adobe Acrobat vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_acrobat
misc_acroread
 
YELLOW CVE-2009-4325 The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers." DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4326 The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value. DB2 vulnerabilities
database_db2ver  
RED CVE-2009-4327 The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4328 Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4329 Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modifying the db2ra data stream sent in a request from the Load Utility. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4330 Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4331 The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors. DB2 vulnerabilities
database_db2ver  
RED CVE-2009-4332 db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer dereference and application termination) via unspecified vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4333 The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4334 The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4335 Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits." DB2 vulnerabilities
database_db2ver  
RED CVE-2009-4355 Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-4369 Cross-site scripting (XSS) vulnerability in the Contact module (modules/contact/contact.admin.inc or modules/contact/contact.module) in Drupal Core 5.x before 5.21 and 6.x before 6.15 allows remote authenticated users with "administer site-wide contact form" permissions to inject arbitrary web script or HTML via the contact category name. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
YELLOW CVE-2009-4370 Cross-site scripting (XSS) vulnerability in the Menu module (modules/menu/menu.admin.inc) in Drupal Core 6.x before 6.15 allows remote authenticated users with permissions to create new menus to inject arbitrary web script or HTML via a menu description, which is not properly handled in the menu administration overview. Drupal vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_cms_drupal  
RED CVE-2009-4376 Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted packet. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-4377 The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap. Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
RED CVE-2009-4378 The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (crash) via a crafted packet, related to "formatting a date/time using strftime." Ethereal vulnerabilities

Note: Authentication is required to detect this vulnerability
net_wireshark  
YELLOW CVE-2009-4410 The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y uses the wrong variable in an argument to the kunmap function, which allows local users to cause a denial of service (panic) via unknown vectors. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-4414 SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the passwd parameter to login.php. phpGroupWare vulnerabilities
web_prog_php_groupware  
RED CVE-2009-4415 Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allow remote attackers to (1) read arbitrary files via the csvfile parameter to addressbook/csv_import.php, or (2) include and execute arbitrary local files via the conv_type parameter in addressbook/inc/class.uiXport.inc.php. phpGroupWare vulnerabilities
web_prog_php_groupware  
RED CVE-2009-4416 Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter whose name begins with the "phpgw_" sequence. phpGroupWare vulnerabilities
web_prog_php_groupware  
RED CVE-2009-4418 The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resource consumption) via a deeply nested serialized variable, as demonstrated by a string beginning with a:1: followed by many {a:1: sequences. PHP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_version  
RED CVE-2009-4427 Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cmd parameter. vulnerable web program
web_prog_php_phpldapadmin  
YELLOW CVE-2009-4438 The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege requirements for access to a (1) sequence or (2) global-variable object, which allows remote authenticated users to make use of data via unspecified vectors. DB2 vulnerabilities
database_db2ver  
YELLOW CVE-2009-4439 Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (instance crash) by compiling a SQL query. DB2 vulnerabilities
database_db2ver  
RED CVE-2009-4440 Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly handle multiple client connections within a short time window, which allows remote attackers to hijack the backend connection of an authenticated user, and obtain the privileges of this user, by making a client connection in opportunistic circumstances, related to "long binds," aka Bug Ids 6828462 and 6823593. Sun Java System Directory Proxy Server vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ldapcategory_sunjsdsver  
RED CVE-2009-4441 Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not enable the SO_KEEPALIVE socket option, which makes it easier for remote attackers to cause a denial of service (connection slot exhaustion) via multiple connections, aka Bug Id 6782659. Sun Java System Directory Proxy Server vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ldapcategory_sunjsdsver  
RED CVE-2009-4442 Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no operations on these connections, aka Bug Id 6648665. Sun Java System Directory Proxy Server vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ldapcategory_sunjsdsver  
RED CVE-2009-4443 Unspecified vulnerability in the psearch (aka persistent search) functionality in Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allows remote attackers to cause a denial of service (psearch outage) by using a crafted psearch client to send requests that trigger a psearch thread loop, aka Bug Id 6855978. Sun Java System Directory Proxy Server vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_ldapcategory_sunjsdsver  
YELLOW CVE-2009-4452 Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and Internet Security 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); use weak permissions (Everyone:Full Control) for the BASES directory, which allows local users to gain SYSTEM privileges by replacing an executable or DLL with a Trojan horse. Kaspersky AntiVirus vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_av_kaspersky_avfsver
misc_av_kaspersky_avver2k10
misc_av_kaspersky_avworkver
 
RED CVE-2009-4479 LDAP3A.exe in MailSite 8.0.4 allows remote attackers to cause a denial of service (heap memory corruption and daemon crash) via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.13 through 8.11. NOTE: as of 20091229, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. Rockliffe vulnerabilities
mail_web_rockliffever  
RED CVE-2009-4483 Unspecified vulnerability in LDAP3A.exe in MailSite 8.0.4 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.13 through 8.11. NOTE: as of 20091229, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. Rockliffe vulnerabilities
mail_web_rockliffever  
RED CVE-2009-4484 Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a. MySQL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version  
YELLOW CVE-2009-4486 Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema. Novell iManager vulnerabilities

Note: Authentication is required to detect this vulnerability
web_server_novell_imanagerice  
RED CVE-2009-4487 nginx 0.7.64 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. nginx HTTP vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_server_nginx  
RED CVE-2009-4489 header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. Cherokee vulnerabilities
web_server_cherokee  
RED CVE-2009-4491 thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. thttpd vulnerabilities
web_server_thttpd  
RED CVE-2009-4492 WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. Ruby vulnerabilities

Note: Authentication is required to detect this vulnerability
web_dev_ruby  
RED CVE-2009-4496 Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. Boa web server vulnerabilities
web_server_boa  
YELLOW CVE-2009-4531 httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI. httpdx vulnerabilities
web_server_httpdxver  
RED CVE-2009-4536 drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel 2.6.32.3 and earlier handles Ethernet frames that exceed the MTU by processing certain trailing payload data as if it were a complete frame, which allows remote attackers to bypass packet filters via a large packet with a crafted payload. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1385. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-4537 drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing '\0' characters, related to the value of the status register and erroneous behavior associated with the RxMaxSize register. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-1389. Linux Kernel vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_linuxkernel  
RED CVE-2009-4538 drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a related issue to CVE-2009-4537. VMWare ESX vulnerabilities
misc_esxbuild  
YELLOW CVE-2009-4554 Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag. Snitz Forums 2000 vulnerabilities
web_prog_asp_snitzsqli  
YELLOW CVE-2009-4565 sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-middle attackers to spoof arbitrary SSL-based SMTP servers via a crafted server certificate issued by a legitimate Certification Authority, and (2) allows remote attackers to bypass intended access restrictions via a crafted client certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. Sendmail vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
mail_smtp_sendmail  
YELLOW CVE-2009-4568 Cross-site scripting (XSS) vulnerability in Webmin before 1.500 and Usermin before 1.430 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Webmin vulnerabilities

Note: Authentication is required to detect this vulnerability
web_tool_webminpkg
web_tool_webminver
 
YELLOW CVE-2009-4589 Cross-site scripting (XSS) vulnerability in the Special:Block implementation in the getContribsLink function in SpecialBlockip.php in MediaWiki 1.14.0 and 1.15.0 allows remote attackers to inject arbitrary web script or HTML via the ip parameter. MediaWiki vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_mediawiki  
RED CVE-2009-4593 The bftpdutmp_log function in bftpdutmp.c in Bftpd before 2.4 does not place a '\0' character at the end of the string value of the ut.bu_host structure member, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors. NOTE: some of these details are obtained from third party information. bftpd vulnerabilities
ftp_bftpdver  
YELLOW CVE-2009-4605 scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors. phpMyAdmin vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
web_prog_php_myadminver  
YELLOW CVE-2009-4612 Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp. Jetty vulnerabilities
web_dev_jetty  
RED CVE-2009-4653 Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to cause a denial of service (dhost.exe crash) and possibly execute arbitrary code via a long string to /dhost/modules?I:. Novell eDirectory

Note: Authentication is required to detect this vulnerability
misc_edirectoryver  
YELLOW CVE-2009-4654 Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk. Novell eDirectory HTTP

Note: Authentication is required to detect this vulnerability
web_tool_edirectoryhttpstk  
YELLOW CVE-2009-4655 The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie. Novell eDirectory

Note: Authentication is required to detect this vulnerability
misc_edirectoryver  
YELLOW CVE-2009-4741 Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors. Skype vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_skypever  
YELLOW CVE-2009-4769 Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component. httpdx vulnerabilities
web_server_httpdxver  
YELLOW CVE-2009-4775 Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response. WS FTP Client vulnerabilities

Note: Authentication is required to detect this vulnerability
ftp_wsftpclientpro  
RED CVE-2009-4778 Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.7 and 5.0.0, and BlackBerry Professional Software 4.1.4, allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246, CVE-2009-0176, CVE-2009-0219, CVE-2009-2643, and CVE-2009-2646. BlackBerry vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_blackberry_pdfdistiller  
YELLOW CVE-2009-4795 Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command. Xlight FTP Server
ftp_xlight  
RED CVE-2009-4809 Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter. Easy File Sharing Web Server
web_server_efswsver  
BROWN CVE-2009-4811 VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\x90 sequence in the USER and PASS commands, a related issue to CVE-2009-3707. NOTE: some of these details are obtained from third party information. VMware authd vulnerabilities
misc_vmware_authd  
YELLOW CVE-2009-4813 Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action. MyBB vulnerabilities
web_prog_php_mybbxss  
RED CVE-2009-4815 Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors. Serv U vulnerabilities
ftp_servu  
YELLOW CVE-2009-4823 Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter. Cross site scripting
web_prog_cgi_cpanelxssfileop  
RED
!
CVE-2009-4873 Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie. Serv U vulnerabilities
ftp_servuhttpbo  
YELLOW CVE-2009-4879 The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions. Novell Access Manager vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_novellaccessmanager  
YELLOW CVE-2009-4910 Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78418. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4911 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device crash) via vectors involving SSL VPN and PPPoE transactions, aka Bug ID CSCsm77958. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4912 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this client is unauthorized, which might allow remote attackers to bypass intended access restrictions via an HTTPS session, aka Bug ID CSCso10876. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4913 The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) exposes IP services on the "far side of the box," which might allow remote attackers to bypass intended access restrictions via IPv6 packets, aka Bug ID CSCso58622. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4914 Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4915 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via unknown network traffic, as demonstrated by a "connection stress test," aka Bug ID CSCsq68451. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4916 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (console hang) via a login action during failover replication, aka Bug ID CSCsq80095. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4917 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via a high volume of SIP traffic, aka Bug ID CSCsr65901. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4918 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4919 Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to have an unspecified impact via long IKE attributes, aka Bug ID CSCsu43121. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4921 Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (traceback) via malformed TCP packets, aka Bug ID CSCsm84110. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4922 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (traceback) by establishing many IPsec L2L tunnels from remote peer IP addresses, aka Bug ID CSCso15583. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-4923 Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162. Cisco ASA vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_asa5580xss  
YELLOW CVE-2009-5017 Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210. Mozilla vulnerabilities

Note: Authentication is required to detect this vulnerability
web_client_firefox  
YELLOW CVE-2009-5022 Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file. IrfanView vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_irfanviewver  
YELLOW CVE-2009-5026 The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave configurations in which the slave is running a newer version than the master, allows remote attackers to execute arbitrary SQL commands via custom comments. MySQL vulnerabilities

Note: Authentication is recommended to improve the accuracy of this check
database_mysql_version  
YELLOW CVE-2009-5029 Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd. VMWare ESX vulnerabilities
misc_esxbuild  
BROWN CVE-2009-5038 Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a certain IRC server, related to a "corrupted magic value," aka Bug ID CSCso05336. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
BROWN CVE-2009-5040 CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555. Cisco vulnerabilities

Note: A valid SNMP read community string is required to detect this vulnerability
net_cisco_ios  
RED CVE-2009-5044 contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
YELLOW CVE-2009-5064 ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc. VMWare ESX vulnerabilities
misc_esxbuild  
RED CVE-2009-5078 contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document. MacOSX vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_macosx_version  
BROWN CVE-2009-5138 GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates, a different vulnerability than CVE-2014-1959. GnuTLS vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_gnutls  
RED CVE-2009-5155 In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match. glibc vulnerabilities

Note: Authentication is required to detect this vulnerability
misc_glibcver  

!: A dangerous check is available for this vulnerability.