Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-11-18 CVE-2009-3969 Buffer Errors vulnerability in Faslo Player 7.0
Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.
network
faslo CWE-119
critical
9.3
2009-11-17 CVE-2009-3841 Remote Code Execution vulnerability in HP Discovery and Dependency Mapping Inventory
Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors.
network
low complexity
hp microsoft
critical
9.0
2009-11-16 CVE-2009-3947 Buffer Errors vulnerability in Tandberg MXP Endpoints F7.0
Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many space characters.
network
tandberg CWE-119
critical
9.3
2009-11-13 CVE-2009-3384 Unspecified vulnerability in Apple Safari
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.
network
apple microsoft
critical
9.3
2009-11-13 CVE-2009-1570 Integer Overflow or Wraparound vulnerability in Gimp 2.6.7
Integer overflow in the ReadImage function in plug-ins/file-bmp/bmp-read.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow.
network
gimp CWE-190
critical
9.3
2009-11-12 CVE-2009-3935 Security vulnerability in IBM BladeCenter Advanced Management Module
Multiple unspecified vulnerabilities in the Advanced Management Module firmware before 2.50G for the IBM BladeCenter T 8720-2xx and 8730-2xx have unknown impact and attack vectors.
network
low complexity
ibm
critical
10.0
2009-11-12 CVE-2009-3932 Denial-Of-Service vulnerability in Chrome
The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting "SQL metadata into a bad state."
network
google
critical
9.3
2009-11-12 CVE-2009-3931 Improper Input Validation vulnerability in Google Chrome
Incomplete blacklist vulnerability in browser/download/download_exe.cc in Google Chrome before 3.0.195.32 allows remote attackers to force the download of certain dangerous files via a "Content-Disposition: attachment" designation, as demonstrated by (1) .mht and (2) .mhtml files, which are automatically executed by Internet Explorer 6; (3) .svg files, which are automatically executed by Safari; (4) .xml files; (5) .htt files; (6) .xsl files; (7) .xslt files; and (8) image files that are forbidden by the victim's site policy.
network
google CWE-20
critical
9.3
2009-11-11 CVE-2009-3134 Code Injection vulnerability in Microsoft products
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a spreadsheet with a malformed record object, aka "Excel Field Sanitization Vulnerability."
network
microsoft CWE-94
critical
9.3
2009-11-11 CVE-2009-3133 Code Injection vulnerability in Microsoft products
Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a spreadsheet containing a malformed object that triggers memory corruption, related to "loading Excel records," aka "Excel Document Parsing Memory Corruption Vulnerability."
network
microsoft CWE-94
critical
9.3