Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-12-11 CVE-2009-4124 Buffer Errors vulnerability in Ruby-Lang Ruby 1.9.1
Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving (1) String#ljust, (2) String#center, or (3) String#rjust.
network
low complexity
ruby-lang CWE-119
critical
10.0
2009-12-11 CVE-2009-3027 Improper Authentication vulnerability in Symantec products
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.
network
low complexity
symantec CWE-287
critical
10.0
2009-12-10 CVE-2009-4292 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IIJ products
Buffer overflow in the URL filtering function in Internet Initiative Japan SEIL/X1, SEIL/X2, and SEIL/B1 firmware 2.40 through 2.51 allows remote attackers to execute arbitrary code via unspecified vectors.
network
iij CWE-119
critical
9.3
2009-12-10 CVE-2009-0898 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Stack-based buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted HTTP request.
network
low complexity
hp CWE-119
critical
10.0
2009-12-10 CVE-2009-4181 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Stack-based buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via vectors involving the sel and arg parameters to jovgraph.exe.
network
low complexity
hp CWE-119
critical
10.0
2009-12-10 CVE-2009-4180 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Stack-based buffer overflow in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.
network
low complexity
hp CWE-119
critical
10.0
2009-12-10 CVE-2009-4179 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Stack-based buffer overflow in ovalarm.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Accept-Language header in an OVABverbose action.
network
low complexity
hp CWE-119
critical
10.0
2009-12-10 CVE-2009-4178 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.
network
low complexity
hp CWE-119
critical
10.0
2009-12-10 CVE-2009-4177 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.
network
low complexity
hp CWE-119
critical
10.0
2009-12-10 CVE-2009-4176 Buffer Errors vulnerability in HP Openview Network Node Manager 7.0.1/7.51/7.53
Multiple heap-based buffer overflows in ovsessionmgr.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via a long (1) userid or (2) passwd parameter to ovlogin.exe.
network
low complexity
hp CWE-119
critical
10.0