LiveActive security incident?Get immediate response
CVE archive

July 2009

Browse CVE records published in July 2009, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 454 matching CVEs · Page 6 of 10.

Unknown · CVSS Not scored

CVE-2009-2467: Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (ap...

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.

Published Jul 22, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2468: Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and...

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

Published Jul 22, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2385: SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards compo...

SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

Published Jul 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2374: Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that...

Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache.

Published Jul 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2369: Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attacke...

Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Jul 8, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2336: The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a p...

The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."

Published Jul 10, 2009 · Updated Aug 7, 2024