LiveActive security incident?Get immediate response
CVE archive

July 2009

Browse CVE records published in July 2009, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 454 matching CVEs · Page 7 of 10.

Unknown · CVSS Not scored

CVE-2009-2348: Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.C...

Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.

Published Jul 17, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2352: Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses,...

Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta are also affected.

Published Jul 7, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2347: Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4....

Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.

Published Jul 14, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2351: Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows r...

Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312. NOTE: it was later reported that 10.00 Beta 3 Build 1699 is also affected.

Published Jul 7, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2300: The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly ha...

The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width and height parameters for an image, which allows remote attackers to execute arbitrary commands or cause a denial of service (resource consumption) via a crafted request.

Published Jul 2, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2316: Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote...

Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to inject arbitrary web script or HTML by entering an unspecified URL in (1) the self-service UI interface or (2) the console interface. NOTE: it was later reported that 4.6.0 is also affected by the first vector.

Published Jul 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2333: Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inclu...

Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the menu parameter to admin/admin_menu.php, and the id parameter to (2) index.php and (3) admin/admin_edit.php; and (4) delete arbitrary local files via a .. (dot dot) in the id parameter to admin/admin_delete.php. NOTE: vector 2 can be leveraged for static code injection by sending a crafted menu parameter to admin/admin_menu.php, and then sending an id=../menu.csv request to index.php.

Published Jul 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2350: Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in...

Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header, a related issue to CVE-2009-1312.

Published Jul 7, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2329: KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request...

KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin/head.php, or (2) voting_diagram.php, (3) voting.php, (4) topics_search.php, (5) topics_list.php, (6) top_part.php, (7) quick_search.php, (8) quick_reply.php, (9) moder_menu.php, (10) messages_list.php, (11) menu.php, (12) head.php, (13) forums_list.php, (14) forum_statistics.php, (15) forum_info.php, or (16) birthday.php in include_files/, which reveals the installation path in an error message.

Published Jul 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2334: wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authenticatio...

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

Published Jul 10, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2335: WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on...

WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."

Published Jul 10, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-2265: Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create e...

Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.

Published Jul 5, 2009 · Updated Aug 7, 2024