LiveActive security incident?Get immediate response
CVE archive

November 2009

Browse CVE records published in November 2009, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 324 matching CVEs · Page 4 of 7.

Unknown · CVSS Not scored

CVE-2009-3946: Joomla!

Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.

Published Nov 16, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3950: Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject ar...

Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to newprofile.html; the (2) firstname, (3) lastname, and (4) company parameters to signup/signup.html; and the (5) firstname, (6) lastname, and (7) address[0].street1 parameters to contact.html.

Published Nov 16, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3968: Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL com...

Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid parameter to itechd.php. NOTE: the sellers_othersitem.php, classifieds.php, and shop.php vectors are already covered by CVE-2008-3238.

Published Nov 18, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3874: Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and...

Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.

Published Nov 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3922: Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 an...

Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allow remote attackers to hijack the authentication of administrators for requests that (1) delete the editing protection of a user or (2) delete a certain type of administrative-bypass rule.

Published Nov 9, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3905: Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbit...

Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3) your-register.asp, (4) main-whyregister.asp, and (5) your.asp in home/, and other unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Nov 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3878: Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors...

Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco Pack Professional 8.12. NOTE: as of 20091105, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Published Nov 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3938: Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler...

Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.12.0, and possibly other versions, as used by the Abiword pdftoabw utility, allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PDF file.

Published Nov 13, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3879: Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5...

Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and attack vectors, related to failure to clone arrays that are returned by the getConfigurations function, aka Bug Id 6822057.

Published Nov 9, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3931: Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 a...

Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (1) .mht and (2) .mhtml files, which are automatically executed by Internet Explorer 6; (3) .svg files, which are automatically executed by Safari; (4) .xml files; (5) .htt files; (6) .xsl files; (7) .xslt files; and (8) image files that are forbidden by the victim's site policy.

Published Nov 12, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3903: Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp in ManageEngine Netflow Analyzer 7.5...

Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp in ManageEngine Netflow Analyzer 7.5 build 7500 allow remote attackers to inject arbitrary web script or HTML via the (1) view and (2) section parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Nov 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3883: Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing imp...

Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, have unknown impact and remote attack vectors, related to "information leaks in mutable variables," aka Bug Id 6657138.

Published Nov 9, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3942: Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a do...

Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

Published Nov 16, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2009-3877: Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 1...

Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.

Published Nov 5, 2009 · Updated Aug 7, 2024