Vulnerabilities (CVE)

Total 398400 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-5053 1 Smarty 1 Smarty 2026-06-16 7.5 HIGH N/A
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
CVE-2009-5052 1 Smarty 1 Smarty 2026-06-16 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
CVE-2009-5051 1 Hastymail 1 Hastymail2 2026-06-16 5.0 MEDIUM N/A
Hastymail2 before RC 8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
CVE-2009-5050 1 Konversation 1 Konversation 2026-06-16 5.0 MEDIUM 7.5 HIGH
konversation before 1.2.3 allows attackers to cause a denial of service.
CVE-2009-5049 2 Debian, Mortbay 2 Debian Linux, Jetty 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
WebApp JSP Snoop page XSS in jetty though 6.1.21.
CVE-2009-5048 1 Mortbay 1 Jetty 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
CVE-2009-5046 2 Debian, Eclipse 2 Debian Linux, Jetty 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
CVE-2009-5045 2 Debian, Eclipse 2 Debian Linux, Jetty 2026-06-16 5.0 MEDIUM 7.5 HIGH
Dump Servlet information leak in jetty before 6.1.22.
CVE-2009-5044 2 Apple, Gnu 2 Mac Os X, Groff 2026-06-16 3.3 LOW N/A
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
CVE-2009-5043 2 Burn Project, Debian 2 Burn, Debian Linux 2026-06-16 7.5 HIGH 9.8 CRITICAL
burn allows file names to escape via mishandled quotation marks
CVE-2009-5042 2 Debian, Python-docutils Project 2 Debian Linux, Python-docutils 2026-06-16 6.4 MEDIUM 9.1 CRITICAL
python-docutils allows insecure usage of temporary files
CVE-2009-5041 1 Debian 1 Overkill 2026-06-16 7.5 HIGH 9.8 CRITICAL
overkill has buffer overflow via long player names that can corrupt data on the server machine
CVE-2009-5040 1 Cisco 1 Ios 2026-06-16 6.8 MEDIUM N/A
CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.
CVE-2009-5039 1 Cisco 1 Ios 2026-06-16 5.0 MEDIUM N/A
Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535.
CVE-2009-5038 1 Cisco 1 Ios 2026-06-16 7.8 HIGH N/A
Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, which allows remote attackers to cause a denial of service (device reload) via an attempted connection to a certain IRC server, related to a "corrupted magic value," aka Bug ID CSCso05336.
CVE-2009-5037 1 Cisco 3 5500 Series Adaptive Security Appliance, Adaptive Security Appliance Software, Asa 5500 2026-06-16 5.0 MEDIUM N/A
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allow remote attackers to cause a denial of service (ASDM syslog outage) via a long URL, aka Bug IDs CSCsm11264 and CSCtb92911.
CVE-2009-5036 1 Ibm 1 Lotus Notes Traveler 2026-06-16 4.0 MEDIUM N/A
traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation.
CVE-2009-5035 1 Ibm 1 Lotus Notes Traveler 2026-06-16 4.3 MEDIUM N/A
The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages.
CVE-2009-5034 1 Ibm 1 Lotus Notes Traveler 2026-06-16 4.0 MEDIUM N/A
IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating on the data.
CVE-2009-5033 1 Ibm 1 Lotus Notes Traveler 2026-06-16 4.0 MEDIUM N/A
IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread.