Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2009-09-24 CVE-2009-3347 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in D-Link Dir-400
Buffer overflow on the D-Link DIR-400 wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11.
network
low complexity
d-link CWE-119
critical
10.0
2009-09-24 CVE-2009-3346 Remote Security vulnerability in SAP Crystal Reports Server 2008
Unspecified vulnerability in SAP Crystal Reports Server 2008 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11.
network
low complexity
sap
critical
10.0
2009-09-24 CVE-2009-3345 Buffer Errors vulnerability in SAP Crystal Reports Server 2008
Heap-based buffer overflow in SAP Crystal Reports Server 2008 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11.
network
low complexity
sap CWE-119
critical
10.0
2009-09-24 CVE-2009-3344 Remote vulnerability in SAP Crystal Reports Server 2008
Unspecified vulnerability in SAP Crystal Reports Server 2008 on Windows XP allows attackers to cause a denial of service (infinite loop) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.3 through 8.11.
network
low complexity
microsoft sap
5.0
2009-09-24 CVE-2009-3343 SQL Injection vulnerability in Hotwebscripts Hotweb Rentals
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands via the PropId parameter.
network
low complexity
hotwebscripts CWE-89
7.5
2009-09-24 CVE-2009-3342 SQL Injection vulnerability in Alphaplug COM Alphauserpoints 1.5.2
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) component 1.5.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the username2points parameter.
network
low complexity
joomla alphaplug CWE-89
7.5
2009-09-24 CVE-2009-3341 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Linksys Wrt54Gl
Buffer overflow on the Linksys WRT54GL wireless router allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.10 through 8.11.
network
low complexity
linksys CWE-119
critical
10.0
2009-09-24 CVE-2009-3340 Denial-Of-Service vulnerability in Freesshd 1.2.4
Unspecified vulnerability in FreeSSHD 1.2.4 allows remote attackers to cause a denial of service via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
network
low complexity
freesshd
5.0
2009-09-24 CVE-2009-3339 Remote Security vulnerability in Mcafee Email and web Security Appliance 5.1
Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11.
network
low complexity
mcafee
7.8
2009-09-24 CVE-2009-3338 Buffer Errors vulnerability in Effectmatrix Magic Morph 1.95B
Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.
network
effectmatrix CWE-119
critical
9.3