Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2009-06-11 CVE-2009-2031 Information Exposure vulnerability in SUN Opensolaris
smbfs in Sun OpenSolaris snv_84 through snv_110, when default mount permissions are used, allows local users to read arbitrary files, and list arbitrary directories, on CIFS volumes.
local
low complexity
sun CWE-200
2.1
2009-06-11 CVE-2009-2030 Security vulnerability in IBM OS/400 JVA-RUN JDK6.0 XML Digital Signature
Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."
network
low complexity
sun ibm
critical
10.0
2009-06-11 CVE-2009-1904 Numeric Errors vulnerability in Ruby-Lang Ruby 1.8.6/1.8.7
The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.
network
low complexity
ruby-lang CWE-189
5.0
2009-06-11 CVE-2009-1760 Path Traversal vulnerability in Rasterbar Software Libtorrent 0/0.12/0.12.1
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a ..
5.8
2009-06-11 CVE-2009-0202 Code Injection vulnerability in Microsoft Office Powerpoint 2000/2002
Array index error in FL21WIN.DLL in the PowerPoint Freelance Windows 2.1 Translator in Microsoft PowerPoint 2000 and 2002 allows remote attackers to execute arbitrary code via a Freelance file with unspecified "layout information" that triggers a heap-based buffer overflow.
network
microsoft CWE-94
critical
9.3
2009-06-11 CVE-2009-2029 Remote Denial Of Service vulnerability in SUN Opensolaris and Solaris
Unspecified vulnerability in rpc.nisd in Sun Solaris 8 through 10, and OpenSolaris before snv_104, allows remote authenticated users to cause a denial of service (NIS+ daemon hang) via unspecified vectors related to NIS+ callbacks.
network
low complexity
sun
5.0
2009-06-11 CVE-2009-2028 Unspecified vulnerability in Adobe Acrobat and Acrobat Reader
Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 have unknown impact and attack vectors, related to "Adobe internally discovered issues."
network
low complexity
adobe
critical
10.0
2009-06-11 CVE-2009-1861 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Multiple heap-based buffer overflows in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file with a JPX (aka JPEG2000) stream that triggers heap memory corruption.
network
adobe CWE-119
critical
9.3
2009-06-11 CVE-2009-1859 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
network
adobe CWE-399
critical
9.3
2009-06-11 CVE-2009-1858 Resource Management Errors vulnerability in Adobe Acrobat and Acrobat Reader
The JBIG2 filter in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow remote attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.
network
adobe CWE-399
critical
9.3