Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-10-28 CVE-2009-3819 Remote Security vulnerability in Maag Randomimage
Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors.
network
low complexity
typo3 urs-maag
critical
10.0
2009-10-28 CVE-2009-3818 Remote Security vulnerability in Sr Freecap
Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.
network
low complexity
typo3 stanislas-rolland
critical
10.0
2009-10-27 CVE-2009-3812 Buffer Errors vulnerability in Otslabs Otsav DJ, Otsav Radio and Otsav TV
Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.
network
otslabs CWE-119
critical
9.3
2009-10-27 CVE-2009-3811 Buffer Errors vulnerability in Assistanttools Music TAG Editor 1.61
Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.
network
assistanttools CWE-119
critical
9.3
2009-10-27 CVE-2009-3810 Buffer Errors vulnerability in Acoustica MP3 Audio Mixer 2.471
Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.
network
acoustica CWE-119
critical
9.3
2009-10-27 CVE-2009-3808 Unspecified vulnerability in Kramware Mixsense DJ Studio 1.0.0.1
MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file.
network
kramware
critical
9.3
2009-10-27 CVE-2009-3807 Buffer Errors vulnerability in Mixvibes 7.043
Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.
network
mixvibes CWE-119
critical
9.3
2009-10-26 CVE-2009-3790 Buffer Errors vulnerability in Cutepdf Formmax 3.5
Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file.
network
cutepdf CWE-119
critical
9.3
2009-10-23 CVE-2009-3616 Use After Free vulnerability in multiple products
Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users to execute arbitrary code on the host OS by establishing a connection from a VNC client and then (1) disconnecting during data transfer, (2) sending a message using incorrect integer data types, or (3) using the Fuzzy Screen Mode protocol, related to double free vulnerabilities.
network
low complexity
qemu redhat CWE-416
critical
9.9
2009-10-23 CVE-2009-2281 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow.
network
low complexity
osgeo umn CWE-119
critical
10.0