LiveActive security incident?Get immediate response
CVE archive

December 2009

Browse CVE records published in December 2009, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 449 matching CVEs · Page 3 of 9.

Unknown · CVSS Not scored

CVE-2009-4480: Buffer overflow in the web service in AzeoTech DAQFactory 5.77 might allow remote attackers to execute arbi...

Buffer overflow in the web service in AzeoTech DAQFactory 5.77 might allow remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.16 through 8.11. NOTE: as of 20091229, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

Published Dec 30, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4373: Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Se...

Unrestricted file upload vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in ossiminstall/uploads/.

Published Dec 21, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4217: SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla!

SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 7, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4444: Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (s...

Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) character to determine the file extension, which allows remote attackers to bypass intended extension restrictions of third-party upload applications via a filename with a (1) .asp, (2) .cer, or (3) .asa first extension, followed by a semicolon and a safe extension, as demonstrated by the use of asp.dll to handle a .asp;.jpg file.

Published Dec 29, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4387: The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password...

The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (PMP) before 6.1 Build 6104 uses case-sensitive checks for malicious inputs, which allows remote attackers to inject arbitrary web script or HTML via the searchtext parameter and other unspecified inputs.

Published Dec 22, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4188: HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remot...

HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098.

Published Dec 3, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4118: The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows be...

The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTROLLER_CONNECT error, which allows local users to cause a denial of service (service crash and VPN connection loss) via a manual start of cvpnd.exe while the cvpnd service is running.

Published Dec 1, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2009-4117: Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in Sum...

Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of service and possibly execute arbitrary code via a /Decode array for certain types of shading that are not properly handled by the (1) pdf_loadtype4shade, (2) pdf_loadtype5shade, (3) pdf_loadtype6shade, and (4) pdf_loadtype7shade functions. NOTE: some of these details are obtained from third party information.

Published Dec 1, 2009 · Updated Sep 16, 2024