Количество 63 796
Количество 63 796
CVE-2009-5056
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list.
CVE-2009-5055
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2.
CVE-2009-5054
Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.
CVE-2009-5053
Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file.
CVE-2009-5052
Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors.
CVE-2009-5050
konversation before 1.2.3 allows attackers to cause a denial of service.
CVE-2009-5049
WebApp JSP Snoop page XSS in jetty though 6.1.21.
CVE-2009-5048
Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
CVE-2009-5047
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-4611. Reason: This candidate is a duplicate of CVE-2009-4611. Notes: All CVE users should reference CVE-2009-4611 rather than this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
CVE-2009-5046
JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
CVE-2009-5045
Dump Servlet information leak in jetty before 6.1.22.
CVE-2009-5044
contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.
CVE-2009-5043
burn allows file names to escape via mishandled quotation marks
CVE-2009-5042
python-docutils allows insecure usage of temporary files
CVE-2009-5041
overkill has buffer overflow via long player names that can corrupt data on the server machine
CVE-2009-5031
ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.
CVE-2009-5030
The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free."
CVE-2009-5029
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.
CVE-2009-5028
Stack-based buffer overflow in Namazu before 2.0.20 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted request containing an empty uri field.
CVE-2009-5027
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2062. Reason: This candidate is a reservation duplicate of CVE-2010-2062. Notes: All CVE users should reference CVE-2010-2062 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2009-5056 Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrictions and read a ticket by watching this ticket, and then selecting the ticket from the watched-tickets list. | CVSS2: 2.1 | 0% Низкий | почти 15 лет назад | |
CVE-2009-5055 Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by visiting a ticket, as demonstrated by leveraging the CustomerID 12 account to read tickets that should be available only to CustomerID 1 or CustomerID 2. | CVSS2: 3.5 | 0% Низкий | почти 15 лет назад | |
CVE-2009-5054 Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations. | CVSS2: 7.5 | 0% Низкий | около 15 лет назад | |
CVE-2009-5053 Unspecified vulnerability in Smarty before 3.0.0 beta 6 allows remote attackers to execute arbitrary PHP code by injecting this code into a cache file. | CVSS2: 7.5 | 1% Низкий | около 15 лет назад | |
CVE-2009-5052 Multiple unspecified vulnerabilities in Smarty before 3.0.0 beta 6 have unknown impact and attack vectors. | CVSS2: 10 | 1% Низкий | около 15 лет назад | |
CVE-2009-5050 konversation before 1.2.3 allows attackers to cause a denial of service. | CVSS3: 7.5 | 0% Низкий | больше 6 лет назад | |
CVE-2009-5049 WebApp JSP Snoop page XSS in jetty though 6.1.21. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2009-5048 Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2009-5047 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-4611. Reason: This candidate is a duplicate of CVE-2009-4611. Notes: All CVE users should reference CVE-2009-4611 rather than this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage | около 6 лет назад | |||
CVE-2009-5046 JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. | CVSS3: 6.1 | 1% Низкий | больше 6 лет назад | |
CVE-2009-5045 Dump Servlet information leak in jetty before 6.1.22. | CVSS3: 7.5 | 3% Низкий | больше 6 лет назад | |
CVE-2009-5044 contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file. | CVSS2: 3.3 | 0% Низкий | больше 14 лет назад | |
CVE-2009-5043 burn allows file names to escape via mishandled quotation marks | CVSS3: 9.8 | 0% Низкий | больше 6 лет назад | |
CVE-2009-5042 python-docutils allows insecure usage of temporary files | CVSS3: 9.1 | 0% Низкий | больше 6 лет назад | |
CVE-2009-5041 overkill has buffer overflow via long player names that can corrupt data on the server machine | CVSS3: 9.8 | 1% Низкий | больше 6 лет назад | |
CVE-2009-5031 ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header. | CVSS2: 4.3 | 1% Низкий | больше 13 лет назад | |
CVE-2009-5030 The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via crafted tile information in a Gray16 TIFF image, which causes insufficient memory to be allocated and leads to an "invalid free." | CVSS2: 6.8 | 5% Низкий | больше 13 лет назад | |
CVE-2009-5029 Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd. | CVSS2: 6.8 | 5% Низкий | почти 13 лет назад | |
CVE-2009-5028 Stack-based buffer overflow in Namazu before 2.0.20 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted request containing an empty uri field. | CVSS2: 7.5 | 3% Низкий | около 14 лет назад | |
CVE-2009-5027 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2062. Reason: This candidate is a reservation duplicate of CVE-2010-2062. Notes: All CVE users should reference CVE-2010-2062 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage | около 11 лет назад |
Уязвимостей на страницу