Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2009-06-10 CVE-2009-1122 Improper Authentication vulnerability in Microsoft Internet Information Services 5.0
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.
network
low complexity
microsoft CWE-287
7.5
2009-06-10 CVE-2009-1718 Information Exposure vulnerability in Apple Safari
WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.
network
apple CWE-200
7.1
2009-06-10 CVE-2009-1713 Information Exposure vulnerability in Apple Safari
The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.
network
apple CWE-200
7.1
2009-06-10 CVE-2009-1703 Information Exposure vulnerability in Apple Safari
WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document.
network
apple CWE-200
7.1
2009-06-10 CVE-2009-1699 XXE vulnerability in multiple products
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly handle XML external entities, which allows remote attackers to read arbitrary files via a crafted DTD, as demonstrated by a file:///etc/passwd URL in an entity declaration, related to an "XXE attack."
network
low complexity
apple canonical opensuse CWE-611
7.5
2009-06-10 CVE-2009-1139 Resource Management Errors vulnerability in Microsoft Adam, Windows 2000 and Windows Server 2003
Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory consumption and service outage) via (1) LDAP or (2) LDAPS requests with unspecified OID filters, aka "Active Directory Memory Leak Vulnerability."
network
low complexity
microsoft CWE-399
7.8
2009-06-10 CVE-2009-1535 Improper Authentication vulnerability in Microsoft Internet Information Services 5.1/6.0
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position in the URI, as demonstrated by inserting %c0%af into a "/protected/" initial pathname component to bypass the password protection on the protected\ folder, aka "IIS 5.1 and 6.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1122.
network
low complexity
microsoft CWE-287
7.5
2009-06-09 CVE-2009-2025 Permissions, Privileges, and Access Controls vulnerability in Dutchmonkey DM Filemanager 3.9.2
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
network
low complexity
dutchmonkey CWE-264
7.5
2009-06-09 CVE-2009-2021 SQL Injection vulnerability in Virtuenetz Virtue Classifieds
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL commands via the category parameter.
network
low complexity
virtuenetz CWE-89
7.5
2009-06-09 CVE-2009-2019 SQL Injection vulnerability in Virtuenetz Virtue News Manager
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL commands via the nid parameter.
network
low complexity
virtuenetz CWE-89
7.5