Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2009-04-13 CVE-2008-4420 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Multiple stack-based buffer overflows in DZIP32.DLL before 5.0.0.8 in DynaZip Max and DZIPS32.DLL before 6.0.0.5 in DynaZip Max Secure; as used in HP OpenView Performance Agent C.04.60, HP Performance Agent C.04.70 and C.04.72, TurboZIP 6.0, and other products; allow user-assisted attackers to execute arbitrary code via a long filename in a ZIP archive during a (1) Fix (aka Repair), (2) Add, (3) Update, or (4) Freshen action, a related issue to CVE-2006-3985.
9.3
2009-04-10 CVE-2008-6711 Multiple Security vulnerability in Avaya Communication Manager
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknown vectors related to "viewing system logs."
network
low complexity
avaya
critical
9.0
2009-04-10 CVE-2008-6710 Multiple Security vulnerability in Avaya Communication Manager
Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unknown vectors related to "configuring data viewing or restoring credentials."
network
low complexity
avaya
critical
9.0
2009-04-10 CVE-2008-6709 Multiple Security vulnerability in Avaya Communication Manager and SIP Enablement Services
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters."
network
low complexity
avaya
critical
9.0
2009-04-10 CVE-2008-6708 Multiple Security vulnerability in Avaya Communication Manager and SIP Enablement Services
Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain root privileges via unknown vectors related to configuration of "data viewing or restoring parameters."
network
low complexity
avaya
critical
9.0
2009-04-10 CVE-2008-6703 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Stalker-Game S.T.A.L.K.E.R.: Shadow of Chernobyl
Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.
network
low complexity
stalker-game CWE-119
critical
10.0
2009-04-09 CVE-2009-0197 Numeric Errors vulnerability in Irfanview Formats 4.00/4.10/4.20
Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.
network
irfanview CWE-189
critical
9.3
2009-04-09 CVE-2009-1251 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.
network
low complexity
unix openafs CWE-119
critical
10.0
2009-04-07 CVE-2009-1260 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Ezbsystems Ultraiso
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.
network
ezbsystems CWE-119
critical
9.3
2009-04-07 CVE-2009-1257 Buffer Errors vulnerability in Magic ISO Maker Magic ISO Maker 5.5
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file.
network
low complexity
magic-iso-maker CWE-119
critical
9.0