LiveActive security incident?Get immediate response
CVE archive

June 2009

Browse CVE records published in June 2009, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 476 matching CVEs · Page 6 of 10.

Unknown · CVSS Not scored

CVE-2009-2046: The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allo...

The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP Server, aka Bug IDs CSCsu05515 and CSCsr96497.

Published Jun 24, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2065: Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the...

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

Published Jun 15, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2041: Cross-site scripting (XSS) vulnerability in A51 D.O.O.

Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab 0.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1772.

Published Jun 12, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2042: libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisib...

libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

Published Jun 12, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2006: Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote att...

Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) search_term parameter to main/auth/courses.php; the (2) frm_title and (3) frm_content parameters in a new personal agenda item action; the (4) title and (5) tutor_name parameters in a new course action; and the (6) student and (7) course parameters to main/mySpace/myStudents.php. NOTE: vectors 2 and 3 might only be exploitable via a separate CSRF vulnerability.

Published Jun 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2066: Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows...

Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

Published Jun 15, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2010: Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow...

Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) thread parameter to messageboard.php, (2) member parameter to profile.php, (3) pid parameter to gallery/index.php, and the (4) fcms_login_id cookie parameter.

Published Jun 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2011: Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, whe...

Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.

Published Jun 16, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1962: Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1)...

Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.

Published Jun 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2007: Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers...

Multiple directory traversal vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to (1) read portions of arbitrary files via a .. (dot dot) and a ..\ (dot dot backslash) in the lang parameter to main/exercice/hotspot_lang_conversion.php and (2) read arbitrary files via a .. (dot dot) in the doc_url parameter to main/exercice/Hpdownload.php.

Published Jun 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1953: IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Orac...

IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web Services listener has a certain WSEAF configuration, does not properly restrict use of a cached Subject, which allows remote attackers to obtain access with the credentials of a recently authenticated user via unspecified vectors.

Published Jun 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1960: inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allo...

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.

Published Jun 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1955: The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used i...

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity references, as demonstrated by a PROPFIND request, a similar issue to CVE-2003-1564.

Published Jun 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1961: The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 befor...

The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

Published Jun 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1938: Cross-site scripting (XSS) vulnerability in Joomla!

Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output and the frontend administrative panel.

Published Jun 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1932: Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task...

Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.

Published Jun 4, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-1935: Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimiza...

Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.

Published Jun 18, 2009 · Updated Aug 7, 2024