/
cyberknowledge
/
CVE
ОбзорДокументацияВойти
/
cyberknowledge
/
CVE
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
CI/CD
Аналитика
ДокументацияПоддержка
Политика конфиденциальностиПользовательское соглашениеПолитика использования «cookies»Согласие субъекта персональных данных
2026 ©
samples/debian_oval.csv
101 строка153 KB

Zeros312

Rename sample/ to samples/; remove README from samples
30 июн 2026, 21:21
30 июн 2026, 21:2183c96cb
100 строк
bookworm
oval:org.debian:def:17150963541325650009340851204767583853
CVE-2008-3834 dbus
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.
['CVE-2008-3834']
['Debian GNU/Linux 12', 'dbus']
['CVE-2008-3834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834']
{'cves': '["CVE-2008-3834"]', 'title': 'CVE-2008-3834 dbus', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dbus"]', 'severity': None, 'references': '["CVE-2008-3834", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834"]', 'description': 'The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.', 'definition_id': 'oval:org.debian:def:17150963541325650009340851204767583853', 'package_criteria': [{'cve_id': 'CVE-2008-3834', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dbus', 'fixed_version': '1.2.1-4', 'affected_version_range': '< 1.2.1-4'}]}
e624a6649886da1cd2b6f075c4e8676292b9712d980146141c906caddab92b1b
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:176701901440535772456826615525043252343
CVE-2009-1721 openexr
The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
['CVE-2009-1721']
['Debian GNU/Linux 12', 'openexr']
['CVE-2009-1721', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1721']
{'cves': '["CVE-2009-1721"]', 'title': 'CVE-2009-1721 openexr', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "openexr"]', 'severity': None, 'references': '["CVE-2009-1721", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1721"]', 'description': 'The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.', 'definition_id': 'oval:org.debian:def:176701901440535772456826615525043252343', 'package_criteria': [{'cve_id': 'CVE-2009-1721', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openexr', 'fixed_version': '1.6.1-4.1', 'affected_version_range': '< 1.6.1-4.1'}]}
079a5eef48c046e1162e359ccf653609be2360ed78f182859a3cefb3f77051f4
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:316741602078639721803970548724118741389
CVE-2009-1722 openexr
Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.
['CVE-2009-1722']
['Debian GNU/Linux 12', 'openexr']
['CVE-2009-1722', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1722']
{'cves': '["CVE-2009-1722"]', 'title': 'CVE-2009-1722 openexr', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "openexr"]', 'severity': None, 'references': '["CVE-2009-1722", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1722"]', 'description': 'Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.', 'definition_id': 'oval:org.debian:def:316741602078639721803970548724118741389', 'package_criteria': [{'cve_id': 'CVE-2009-1722', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openexr', 'fixed_version': '1.6.1-1', 'affected_version_range': '< 1.6.1-1'}]}
b5e41fc3c2fee4c4694ad98a8f01dab2e2f1059eb47b3d1b37dbe0b1c5871299
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:100315230763869213438215337750009774565
CVE-2009-1757 transmission
Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
['CVE-2009-1757']
['Debian GNU/Linux 12', 'transmission']
['CVE-2009-1757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1757']
{'cves': '["CVE-2009-1757"]', 'title': 'CVE-2009-1757 transmission', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "transmission"]', 'severity': None, 'references': '["CVE-2009-1757", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1757"]', 'description': 'Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.', 'definition_id': 'oval:org.debian:def:100315230763869213438215337750009774565', 'package_criteria': [{'cve_id': 'CVE-2009-1757', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'transmission', 'fixed_version': '1.61-1', 'affected_version_range': '< 1.61-1'}]}
91cbbcc71649282f2c8aada6721eddfc5673a37aed776074ffc0290138064c11
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:110594252090381341836912233080357839237
CVE-2009-1759 ctorrent
Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.
['CVE-2009-1759']
['Debian GNU/Linux 12', 'ctorrent']
['CVE-2009-1759', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1759']
{'cves': '["CVE-2009-1759"]', 'title': 'CVE-2009-1759 ctorrent', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ctorrent"]', 'severity': None, 'references': '["CVE-2009-1759", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1759"]', 'description': 'Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.', 'definition_id': 'oval:org.debian:def:110594252090381341836912233080357839237', 'package_criteria': [{'cve_id': 'CVE-2009-1759', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ctorrent', 'fixed_version': '1.3.4-dnh3.2-1.1', 'affected_version_range': '< 1.3.4-dnh3.2-1.1'}]}
62ad217dd0f766b3b93c4121b4edfaa2cf5c8b8b2b05bf8cdd18d41efe204d37
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:114313775752707857027208698847116106805
CVE-2009-1760 libtorrent-rasterbar
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.
['CVE-2009-1760']
['Debian GNU/Linux 12', 'libtorrent-rasterbar']
['CVE-2009-1760', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760']
{'cves': '["CVE-2009-1760"]', 'title': 'CVE-2009-1760 libtorrent-rasterbar', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libtorrent-rasterbar"]', 'severity': None, 'references': '["CVE-2009-1760", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760"]', 'description': 'Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.', 'definition_id': 'oval:org.debian:def:114313775752707857027208698847116106805', 'package_criteria': [{'cve_id': 'CVE-2009-1760', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libtorrent-rasterbar', 'fixed_version': '0.14.4-1', 'affected_version_range': '< 0.14.4-1'}]}
2f6c3c722b8c06af414c563ab871cf21ebd667cffd631f32afbb9751def9fbf1
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:226511505271699374456681548240454886850
CVE-2009-1788 libsndfile
Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.
['CVE-2009-1788']
['Debian GNU/Linux 12', 'libsndfile']
['CVE-2009-1788', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788']
{'cves': '["CVE-2009-1788"]', 'title': 'CVE-2009-1788 libsndfile', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libsndfile"]', 'severity': None, 'references': '["CVE-2009-1788", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788"]', 'description': 'Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.', 'definition_id': 'oval:org.debian:def:226511505271699374456681548240454886850', 'package_criteria': [{'cve_id': 'CVE-2009-1788', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libsndfile', 'fixed_version': '1.0.20-1', 'affected_version_range': '< 1.0.20-1'}]}
25f966cc730993601809b5b808464a69bce677821acbd268aeb0f2d4895d78c7
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:180797773148341744289330461767139605285
CVE-2009-1789 eggdrop
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.
['CVE-2009-1789']
['Debian GNU/Linux 12', 'eggdrop']
['CVE-2009-1789', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1789']
{'cves': '["CVE-2009-1789"]', 'title': 'CVE-2009-1789 eggdrop', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "eggdrop"]', 'severity': None, 'references': '["CVE-2009-1789", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1789"]', 'description': 'mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.', 'definition_id': 'oval:org.debian:def:180797773148341744289330461767139605285', 'package_criteria': [{'cve_id': 'CVE-2009-1789', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'eggdrop', 'fixed_version': '1.6.19-1.2', 'affected_version_range': '< 1.6.19-1.2'}]}
7224e66dcc0f0c8e3dd8209906711649fc470d99e3c31bbb78f5e728053cbff1
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:233582373034493297591578929406707608538
CVE-2009-1829 wireshark
Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.
['CVE-2009-1829']
['Debian GNU/Linux 12', 'wireshark']
['CVE-2009-1829', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829']
{'cves': '["CVE-2009-1829"]', 'title': 'CVE-2009-1829 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-1829", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829"]', 'description': 'Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.', 'definition_id': 'oval:org.debian:def:233582373034493297591578929406707608538', 'package_criteria': [{'cve_id': 'CVE-2009-1829', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.0.8-1', 'affected_version_range': '< 1.0.8-1'}]}
56839ae57964cf229870fae0f93756d7880ccd240832c780b9e62012eaaca02d
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:226733781467473222940862071199261044135
CVE-2009-1882 graphicsmagick
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
['CVE-2009-1882']
['Debian GNU/Linux 12', 'graphicsmagick']
['CVE-2009-1882', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882']
{'cves': '["CVE-2009-1882"]', 'title': 'CVE-2009-1882 graphicsmagick', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "graphicsmagick"]', 'severity': None, 'references': '["CVE-2009-1882", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882"]', 'description': 'Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:226733781467473222940862071199261044135', 'package_criteria': [{'cve_id': 'CVE-2009-1882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'graphicsmagick', 'fixed_version': '1.3.5-5.1', 'affected_version_range': '< 1.3.5-5.1'}]}
686ee4ce8da41b820ceb1b8629a08b77045dd86f37f16a5a37ebb217dc949a38
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:149927110986321008188992046286919145652
CVE-2009-1882 imagemagick
Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.
['CVE-2009-1882']
['Debian GNU/Linux 12', 'imagemagick']
['CVE-2009-1882', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882']
{'cves': '["CVE-2009-1882"]', 'title': 'CVE-2009-1882 imagemagick', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "imagemagick"]', 'severity': None, 'references': '["CVE-2009-1882", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882"]', 'description': 'Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:149927110986321008188992046286919145652', 'package_criteria': [{'cve_id': 'CVE-2009-1882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '7:6.5.1.0-1.1', 'affected_version_range': '< 7:6.5.1.0-1.1'}]}
a7fc484ee621c0c3d18d97ead63306ad51e2d421b1a09fd05a730c8114d93328
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:336421291198663336624963504504667777509
CVE-2009-1884 libcompress-raw-bzip2-perl
Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.
['CVE-2009-1884']
['Debian GNU/Linux 12', 'libcompress-raw-bzip2-perl']
['CVE-2009-1884', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1884']
{'cves': '["CVE-2009-1884"]', 'title': 'CVE-2009-1884 libcompress-raw-bzip2-perl', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libcompress-raw-bzip2-perl"]', 'severity': None, 'references': '["CVE-2009-1884", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1884"]', 'description': 'Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.', 'definition_id': 'oval:org.debian:def:336421291198663336624963504504667777509', 'package_criteria': [{'cve_id': 'CVE-2009-1884', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcompress-raw-bzip2-perl', 'fixed_version': '2.018-1', 'affected_version_range': '< 2.018-1'}]}
b1f8c6689ba0acfd8d2e931a79f6eabad7f8a754ce612c1dc7f5721b5013f4d1
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:325796050154074568679461610359218879764
CVE-2009-1885 xerces-c
Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.
['CVE-2009-1885']
['Debian GNU/Linux 12', 'xerces-c']
['CVE-2009-1885', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1885']
{'cves': '["CVE-2009-1885"]', 'title': 'CVE-2009-1885 xerces-c', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "xerces-c"]', 'severity': None, 'references': '["CVE-2009-1885", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1885"]', 'description': 'Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.', 'definition_id': 'oval:org.debian:def:325796050154074568679461610359218879764', 'package_criteria': [{'cve_id': 'CVE-2009-1885', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xerces-c', 'fixed_version': '3.0.1-2', 'affected_version_range': '< 3.0.1-2'}]}
eea6b66c7cf410888aeaea9c6c65857e740e7653c82f54908fe8fdd8a01cef0b
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:217059961636896520459072842491256885194
CVE-2009-1886 samba
Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.
['CVE-2009-1886']
['Debian GNU/Linux 12', 'samba']
['CVE-2009-1886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886']
{'cves': '["CVE-2009-1886"]', 'title': 'CVE-2009-1886 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-1886", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886"]', 'description': 'Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.', 'definition_id': 'oval:org.debian:def:217059961636896520459072842491256885194', 'package_criteria': [{'cve_id': 'CVE-2009-1886', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.3.6-1', 'affected_version_range': '< 2:3.3.6-1'}]}
055f5a824e844de871fb6c43bd40a10623e5ac50999e5cbbf37397ca63787019
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:181290405743222665189904300785379164258
CVE-2009-1888 samba
The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.
['CVE-2009-1888']
['Debian GNU/Linux 12', 'samba']
['CVE-2009-1888', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888']
{'cves': '["CVE-2009-1888"]', 'title': 'CVE-2009-1888 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-1888", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888"]', 'description': 'The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.', 'definition_id': 'oval:org.debian:def:181290405743222665189904300785379164258', 'package_criteria': [{'cve_id': 'CVE-2009-1888', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.3.6-1', 'affected_version_range': '< 2:3.3.6-1'}]}
cb5cc12ca770b04cd4b4197e7680b018b0ec274394a9290ae2086b4997c9f880
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:268884902731360188882447881905316361473
CVE-2009-1889 pidgin
The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.
['CVE-2009-1889']
['Debian GNU/Linux 12', 'pidgin']
['CVE-2009-1889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889']
{'cves': '["CVE-2009-1889"]', 'title': 'CVE-2009-1889 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-1889", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889"]', 'description': 'The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.', 'definition_id': 'oval:org.debian:def:268884902731360188882447881905316361473', 'package_criteria': [{'cve_id': 'CVE-2009-1889', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.5.8-1', 'affected_version_range': '< 2.5.8-1'}]}
3b877bd49a268ddaeb0c52a9e7bd91d6b61936dbd601daae94087010adc18ac8
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:314085580784063994156934279618771546219
CVE-2009-1890 apache2
The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
['CVE-2009-1890']
['Debian GNU/Linux 12', 'apache2']
['CVE-2009-1890', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890']
{'cves': '["CVE-2009-1890"]', 'title': 'CVE-2009-1890 apache2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apache2"]', 'severity': None, 'references': '["CVE-2009-1890", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890"]', 'description': 'The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.', 'definition_id': 'oval:org.debian:def:314085580784063994156934279618771546219', 'package_criteria': [{'cve_id': 'CVE-2009-1890', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apache2', 'fixed_version': '2.2.11-7', 'affected_version_range': '< 2.2.11-7'}]}
bee7a6fcdeb7fa4978a3414f2ef0ddca3834b8ab8b3e5d2bd844c152d02a21ec
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:26317716075797878364632916812815638529
CVE-2009-1891 apache2
The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).
['CVE-2009-1891']
['Debian GNU/Linux 12', 'apache2']
['CVE-2009-1891', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891']
{'cves': '["CVE-2009-1891"]', 'title': 'CVE-2009-1891 apache2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apache2"]', 'severity': None, 'references': '["CVE-2009-1891", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891"]', 'description': 'The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).', 'definition_id': 'oval:org.debian:def:26317716075797878364632916812815638529', 'package_criteria': [{'cve_id': 'CVE-2009-1891', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apache2', 'fixed_version': '2.2.11-7', 'affected_version_range': '< 2.2.11-7'}]}
47c8bdb0bd4f709a30d3b8c3feac47505782cafddfefa8e175e225e820f28cfb
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:75431260087458950854639605098454749350
CVE-2009-1892 isc-dhcp
dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.
['CVE-2009-1892']
['Debian GNU/Linux 12', 'isc-dhcp']
['CVE-2009-1892', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1892']
{'cves': '["CVE-2009-1892"]', 'title': 'CVE-2009-1892 isc-dhcp', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "isc-dhcp"]', 'severity': None, 'references': '["CVE-2009-1892", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1892"]', 'description': 'dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.', 'definition_id': 'oval:org.debian:def:75431260087458950854639605098454749350', 'package_criteria': [{'cve_id': 'CVE-2009-1892', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'isc-dhcp', 'fixed_version': '3.1.2p1-2', 'affected_version_range': '< 3.1.2p1-2'}]}
e76c0ba9a8c03e59638c4be8cecd21c4b34dff6d8c03530ea88435cbd14811fc
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:152563419271831605449815250667138881191
CVE-2009-1956 apr-util
Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.
['CVE-2009-1956']
['Debian GNU/Linux 12', 'apr-util']
['CVE-2009-1956', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956']
{'cves': '["CVE-2009-1956"]', 'title': 'CVE-2009-1956 apr-util', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apr-util"]', 'severity': None, 'references': '["CVE-2009-1956", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956"]', 'description': 'Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.', 'definition_id': 'oval:org.debian:def:152563419271831605449815250667138881191', 'package_criteria': [{'cve_id': 'CVE-2009-1956', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apr-util', 'fixed_version': '1.3.7+dfsg-1', 'affected_version_range': '< 1.3.7+dfsg-1'}]}
339283441a66a759797de2875c5606bc0c9052585ff7baad86e4d3746d9d05be
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:126232051260083801149194372368517090769
CVE-2009-1957 strongswan
charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.
['CVE-2009-1957']
['Debian GNU/Linux 12', 'strongswan']
['CVE-2009-1957', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1957']
{'cves': '["CVE-2009-1957"]', 'title': 'CVE-2009-1957 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-1957", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1957"]', 'description': 'charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.', 'definition_id': 'oval:org.debian:def:126232051260083801149194372368517090769', 'package_criteria': [{'cve_id': 'CVE-2009-1957', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.2.14-1.1', 'affected_version_range': '< 4.2.14-1.1'}]}
c24a266c5ad9b16eeebd1a5addf6cf9cc416452a173ab4600038fe2c4a1d21b8
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:327857179248031889548856667074163370091
CVE-2009-1958 strongswan
charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.
['CVE-2009-1958']
['Debian GNU/Linux 12', 'strongswan']
['CVE-2009-1958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1958']
{'cves': '["CVE-2009-1958"]', 'title': 'CVE-2009-1958 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-1958", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1958"]', 'description': 'charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.', 'definition_id': 'oval:org.debian:def:327857179248031889548856667074163370091', 'package_criteria': [{'cve_id': 'CVE-2009-1958', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.2.14-1.1', 'affected_version_range': '< 4.2.14-1.1'}]}
ba81c767f1a4624cf25092d97c675e43f038cd3484f03560689ebe8f49150a77
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:264821896760517898830389176499916489673
CVE-2009-1959 irssi
Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.
['CVE-2009-1959']
['Debian GNU/Linux 12', 'irssi']
['CVE-2009-1959', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1959']
{'cves': '["CVE-2009-1959"]', 'title': 'CVE-2009-1959 irssi', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "irssi"]', 'severity': None, 'references': '["CVE-2009-1959", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1959"]', 'description': 'Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.', 'definition_id': 'oval:org.debian:def:264821896760517898830389176499916489673', 'package_criteria': [{'cve_id': 'CVE-2009-1959', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'irssi', 'fixed_version': '0.8.13-2', 'affected_version_range': '< 0.8.13-2'}]}
4d194dddca42d000acac9f15faddbfc3915899cf49fa82a1ce706deb69f3e0e6
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:205142739946424585275468486261834368829
CVE-2009-1960 dokuwiki
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.
['CVE-2009-1960']
['Debian GNU/Linux 12', 'dokuwiki']
['CVE-2009-1960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1960']
{'cves': '["CVE-2009-1960"]', 'title': 'CVE-2009-1960 dokuwiki', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dokuwiki"]', 'severity': None, 'references': '["CVE-2009-1960", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1960"]', 'description': 'inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.', 'definition_id': 'oval:org.debian:def:205142739946424585275468486261834368829', 'package_criteria': [{'cve_id': 'CVE-2009-1960', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dokuwiki', 'fixed_version': '0.0.20090214b-1', 'affected_version_range': '< 0.0.20090214b-1'}]}
7addf3f13764250a5d1760ea6b10f680bb11bd43344c65242ba28a6918d2f988
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:238690468956056088465320423337515418289
CVE-2009-1962 xfig
Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.
['CVE-2009-1962']
['Debian GNU/Linux 12', 'xfig']
['CVE-2009-1962', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1962']
{'cves': '["CVE-2009-1962"]', 'title': 'CVE-2009-1962 xfig', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "xfig"]', 'severity': None, 'references': '["CVE-2009-1962", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1962"]', 'description': 'Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.', 'definition_id': 'oval:org.debian:def:238690468956056088465320423337515418289', 'package_criteria': [{'cve_id': 'CVE-2009-1962', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xfig', 'fixed_version': '1:3.2.5.a-1', 'affected_version_range': '< 1:3.2.5.a-1'}]}
03c872c20e95f909aa88088330f4683b3c948071abd111c256a17d2d645535ff
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:171844929339957540114773860932096565428
CVE-2009-2166 ocsinventory-server
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.
['CVE-2009-2166']
['Debian GNU/Linux 12', 'ocsinventory-server']
['CVE-2009-2166', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2166']
{'cves': '["CVE-2009-2166"]', 'title': 'CVE-2009-2166 ocsinventory-server', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ocsinventory-server"]', 'severity': None, 'references': '["CVE-2009-2166", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2166"]', 'description': 'Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.', 'definition_id': 'oval:org.debian:def:171844929339957540114773860932096565428', 'package_criteria': [{'cve_id': 'CVE-2009-2166', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ocsinventory-server', 'fixed_version': '1.02.1-1', 'affected_version_range': '< 1.02.1-1'}]}
76ac76742260d538e32dedbb220a035a3e17c159c3d3e6ab76fa646159db7045
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:264135998950516818315799196695300167303
CVE-2009-2174 gupnp
GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message.
['CVE-2009-2174']
['Debian GNU/Linux 12', 'gupnp']
['CVE-2009-2174', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2174']
{'cves': '["CVE-2009-2174"]', 'title': 'CVE-2009-2174 gupnp', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "gupnp"]', 'severity': None, 'references': '["CVE-2009-2174", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2174"]', 'description': 'GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message.', 'definition_id': 'oval:org.debian:def:264135998950516818315799196695300167303', 'package_criteria': [{'cve_id': 'CVE-2009-2174', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gupnp', 'fixed_version': '0.12.6-3.1', 'affected_version_range': '< 0.12.6-3.1'}]}
ed87c9bb0cec8969cd92e195467784f28258dd998d0968768525e7d2cf102dfb
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:16007930785623427920233057576304284254
CVE-2009-2185 strongswan
The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.
['CVE-2009-2185']
['Debian GNU/Linux 12', 'strongswan']
['CVE-2009-2185', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185']
{'cves': '["CVE-2009-2185"]', 'title': 'CVE-2009-2185 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-2185", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185"]', 'description': 'The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.', 'definition_id': 'oval:org.debian:def:16007930785623427920233057576304284254', 'package_criteria': [{'cve_id': 'CVE-2009-2185', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.2.14-1.2', 'affected_version_range': '< 4.2.14-1.2'}]}
a2617204e80887c45a7d729bdb1f967a98e4ede5fcf92919049dd70087f614fc
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:71863795599795562682229526981736124233
CVE-2009-2281 mapserver
Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.
['CVE-2009-2281']
['Debian GNU/Linux 12', 'mapserver']
['CVE-2009-2281', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2281']
{'cves': '["CVE-2009-2281"]', 'title': 'CVE-2009-2281 mapserver', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "mapserver"]', 'severity': None, 'references': '["CVE-2009-2281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2281"]', 'description': 'Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.', 'definition_id': 'oval:org.debian:def:71863795599795562682229526981736124233', 'package_criteria': [{'cve_id': 'CVE-2009-2281', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mapserver', 'fixed_version': '5.4.2-1', 'affected_version_range': '< 5.4.2-1'}]}
9c13349ddb325054662eca23dbe20bd79ac82a4035c398c74dcdbb8aabccc713
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:239827302271764751369301443504619475531
CVE-2009-2284 phpmyadmin
Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.
['CVE-2009-2284']
['Debian GNU/Linux 12', 'phpmyadmin']
['CVE-2009-2284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2284']
{'cves': '["CVE-2009-2284"]', 'title': 'CVE-2009-2284 phpmyadmin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "phpmyadmin"]', 'severity': None, 'references': '["CVE-2009-2284", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2284"]', 'description': 'Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.', 'definition_id': 'oval:org.debian:def:239827302271764751369301443504619475531', 'package_criteria': [{'cve_id': 'CVE-2009-2284', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'phpmyadmin', 'fixed_version': '4:3.2.0.1-1', 'affected_version_range': '< 4:3.2.0.1-1'}]}
bff9136d8f9998f9c2176f46b3fe88e3e25d5eaf5fefdbd4c28d8aed616fa37d
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:157893224846972689246283406945812282558
CVE-2009-2286 libcompface
Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.
['CVE-2009-2286']
['Debian GNU/Linux 12', 'libcompface']
['CVE-2009-2286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2286']
{'cves': '["CVE-2009-2286"]', 'title': 'CVE-2009-2286 libcompface', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libcompface"]', 'severity': None, 'references': '["CVE-2009-2286", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2286"]', 'description': 'Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.', 'definition_id': 'oval:org.debian:def:157893224846972689246283406945812282558', 'package_criteria': [{'cve_id': 'CVE-2009-2286', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcompface', 'fixed_version': '1:1.5.2-5', 'affected_version_range': '< 1:1.5.2-5'}]}
7c2573a7cac30aab7417d134470d7e474d03caaf3aa526c5209ad4a296eb0bbf
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:98182656478239180621717792390402833422
CVE-2009-2294 dillo
Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG image with crafted (1) width or (2) height values.
['CVE-2009-2294']
['Debian GNU/Linux 12', 'dillo']
['CVE-2009-2294', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2294']
{'cves': '["CVE-2009-2294"]', 'title': 'CVE-2009-2294 dillo', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dillo"]', 'severity': None, 'references': '["CVE-2009-2294", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2294"]', 'description': 'Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG image with crafted (1) width or (2) height values.', 'definition_id': 'oval:org.debian:def:98182656478239180621717792390402833422', 'package_criteria': [{'cve_id': 'CVE-2009-2294', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dillo', 'fixed_version': '3.0-1', 'affected_version_range': '< 3.0-1'}]}
e5684a21dbbe3cefac083ac4155a5f05b4401892ab0b335021b9a3a10929e920
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:187759103582602074914748461749779543898
CVE-2009-2295 advi
Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.
['CVE-2009-2295']
['Debian GNU/Linux 12', 'advi']
['CVE-2009-2295', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2295']
{'cves': '["CVE-2009-2295"]', 'title': 'CVE-2009-2295 advi', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "advi"]', 'severity': None, 'references': '["CVE-2009-2295", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2295"]', 'description': 'Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.', 'definition_id': 'oval:org.debian:def:187759103582602074914748461749779543898', 'package_criteria': [{'cve_id': 'CVE-2009-2295', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'advi', 'fixed_version': '1.6.0-15', 'affected_version_range': '< 1.6.0-15'}]}
e45cc3c4bc999482781170a32961837588007cc51fc26176259355feca01d045
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:244677945050837520826360936587181700523
CVE-2009-2335 wordpress
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
['CVE-2009-2335']
['Debian GNU/Linux 12', 'wordpress']
['CVE-2009-2335', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2335']
{'cves': '["CVE-2009-2335"]', 'title': 'CVE-2009-2335 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2335", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2335"]', 'description': 'WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."', 'definition_id': 'oval:org.debian:def:244677945050837520826360936587181700523', 'package_criteria': [{'cve_id': 'CVE-2009-2335', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]}
e8ada103e870890542df0039177c87bfe9f73b336a9f07be8a3cf4c927d7ad98
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:104171003645694939709538853245143659988
CVE-2009-2336 wordpress
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
['CVE-2009-2336']
['Debian GNU/Linux 12', 'wordpress']
['CVE-2009-2336', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2336']
{'cves': '["CVE-2009-2336"]', 'title': 'CVE-2009-2336 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2336", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2336"]', 'description': 'The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."', 'definition_id': 'oval:org.debian:def:104171003645694939709538853245143659988', 'package_criteria': [{'cve_id': 'CVE-2009-2336', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]}
0aa6fe6562febe046e93e22a6c45a366fc951f0182df557787c6cbffb554e121
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:140857754136168502997010906789876043069
CVE-2009-2347 tiff
Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.
['CVE-2009-2347']
['Debian GNU/Linux 12', 'tiff']
['CVE-2009-2347', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347']
{'cves': '["CVE-2009-2347"]', 'title': 'CVE-2009-2347 tiff', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "tiff"]', 'severity': None, 'references': '["CVE-2009-2347", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347"]', 'description': 'Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.', 'definition_id': 'oval:org.debian:def:140857754136168502997010906789876043069', 'package_criteria': [{'cve_id': 'CVE-2009-2347', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'tiff', 'fixed_version': '3.8.2-13', 'affected_version_range': '< 3.8.2-13'}]}
e3e9f47cc533e321904de173618d255e38e5d9e58d8700da913bb9ef5525b7c7
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:232952009893144092919424046548705335980
CVE-2009-2404 nss
Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.
['CVE-2009-2404']
['Debian GNU/Linux 12', 'nss']
['CVE-2009-2404', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404']
{'cves': '["CVE-2009-2404"]', 'title': 'CVE-2009-2404 nss', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "nss"]', 'severity': None, 'references': '["CVE-2009-2404", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404"]', 'description': "Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.", 'definition_id': 'oval:org.debian:def:232952009893144092919424046548705335980', 'package_criteria': [{'cve_id': 'CVE-2009-2404', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nss', 'fixed_version': '3.12.3-1', 'affected_version_range': '< 3.12.3-1'}]}
acf10848f9a18f5a6681c80f4d4d06422d7e72d3a782ec91fcf5e69bf73035e7
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:316168818269827681490263873092700999730
CVE-2009-2409 nss
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
['CVE-2009-2409']
['Debian GNU/Linux 12', 'nss']
['CVE-2009-2409', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409']
{'cves': '["CVE-2009-2409"]', 'title': 'CVE-2009-2409 nss', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "nss"]', 'severity': None, 'references': '["CVE-2009-2409", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409"]', 'description': 'The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.', 'definition_id': 'oval:org.debian:def:316168818269827681490263873092700999730', 'package_criteria': [{'cve_id': 'CVE-2009-2409', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nss', 'fixed_version': '3.12.3-1', 'affected_version_range': '< 3.12.3-1'}]}
09968343c3730142eecee2a89683704f09ca8cdb7d25fff390630e87dab83bef
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:324209269217175619711341123243052652156
CVE-2009-2409 openssl
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
['CVE-2009-2409']
['Debian GNU/Linux 12', 'openssl']
['CVE-2009-2409', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409']
{'cves': '["CVE-2009-2409"]', 'title': 'CVE-2009-2409 openssl', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "openssl"]', 'severity': None, 'references': '["CVE-2009-2409", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409"]', 'description': 'The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.', 'definition_id': 'oval:org.debian:def:324209269217175619711341123243052652156', 'package_criteria': [{'cve_id': 'CVE-2009-2409', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openssl', 'fixed_version': '0.9.8k-4', 'affected_version_range': '< 0.9.8k-4'}]}
879d67e623463ad1bfc38b12e96051bf4744e84ebd6042d3ab97f94953892164
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:17939148550999958590457534619884751283
CVE-2009-2411 subversion
Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.
['CVE-2009-2411']
['Debian GNU/Linux 12', 'subversion']
['CVE-2009-2411', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2411']
{'cves': '["CVE-2009-2411"]', 'title': 'CVE-2009-2411 subversion', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "subversion"]', 'severity': None, 'references': '["CVE-2009-2411", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2411"]', 'description': 'Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.', 'definition_id': 'oval:org.debian:def:17939148550999958590457534619884751283', 'package_criteria': [{'cve_id': 'CVE-2009-2411', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'subversion', 'fixed_version': '1.6.4dfsg-1', 'affected_version_range': '< 1.6.4dfsg-1'}]}
2c0cdf999dc2f57071063e2a1a2edd27cedb7ea105f55244f61797a63bd76fea
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:226064912423586615100545849297708038638
CVE-2009-2412 apr-util
Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information.
['CVE-2009-2412']
['Debian GNU/Linux 12', 'apr-util']
['CVE-2009-2412', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412']
{'cves': '["CVE-2009-2412"]', 'title': 'CVE-2009-2412 apr-util', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apr-util"]', 'severity': None, 'references': '["CVE-2009-2412", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"]', 'description': 'Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:226064912423586615100545849297708038638', 'package_criteria': [{'cve_id': 'CVE-2009-2412', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apr-util', 'fixed_version': '1.3.9+dfsg-1', 'affected_version_range': '< 1.3.9+dfsg-1'}]}
3d5889a68b67176f774ad9cf9114fa5ab77bf280d06439c14ff6ee338e21fc07
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:86020115285173983371273126013393182284
CVE-2009-2414 libxml2
Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.
['CVE-2009-2414']
['Debian GNU/Linux 12', 'libxml2']
['CVE-2009-2414', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2414']
{'cves': '["CVE-2009-2414"]', 'title': 'CVE-2009-2414 libxml2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libxml2"]', 'severity': None, 'references': '["CVE-2009-2414", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2414"]', 'description': 'Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.', 'definition_id': 'oval:org.debian:def:86020115285173983371273126013393182284', 'package_criteria': [{'cve_id': 'CVE-2009-2414', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libxml2', 'fixed_version': '2.7.3.dfsg-2.1', 'affected_version_range': '< 2.7.3.dfsg-2.1'}]}
7fb6f010f681444f6b5576009141d7b841a7b597dd44b41fb2396e55802d4960
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:231599164768019900502804537880944292693
CVE-2009-2415 memcached
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
['CVE-2009-2415']
['Debian GNU/Linux 12', 'memcached']
['CVE-2009-2415', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2415']
{'cves': '["CVE-2009-2415"]', 'title': 'CVE-2009-2415 memcached', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "memcached"]', 'severity': None, 'references': '["CVE-2009-2415", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2415"]', 'description': 'Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.', 'definition_id': 'oval:org.debian:def:231599164768019900502804537880944292693', 'package_criteria': [{'cve_id': 'CVE-2009-2415', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'memcached', 'fixed_version': '1.4.1-1', 'affected_version_range': '< 1.4.1-1'}]}
4503903e479715dbaae3ffbbe49078790282462b8723b0eba88fd936bee1cfcb
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bullseye
oval:org.debian:def:231235182554739574276550960579961929159
CVE-2022-4603 ppp
A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.
['CVE-2022-4603']
['Debian GNU/Linux 11', 'ppp']
['CVE-2022-4603', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4603']
{'cves': '["CVE-2022-4603"]', 'title': 'CVE-2022-4603 ppp', 'issued': None, 'release': 'bullseye', 'updated': None, 'affected': '["Debian GNU/Linux 11", "ppp"]', 'severity': None, 'references': '["CVE-2022-4603", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4603"]', 'description': 'A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.', 'definition_id': 'oval:org.debian:def:231235182554739574276550960579961929159', 'package_criteria': [{'cve_id': 'CVE-2022-4603', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ppp', 'fixed_version': '0', 'affected_version_range': '< 0'}]}
89f2461eb744266bd3dcfc8bbbc4056f2d8e43f50badb7a68853edcf5c4a09b8
2026-05-30 01:53:37.894761+03:00
2026-06-29 20:16:29.792504+03:00
bookworm
oval:org.debian:def:194089816891249449228379305158527923476
CVE-2009-2417 curl
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
['CVE-2009-2417']
['Debian GNU/Linux 12', 'curl']
['CVE-2009-2417', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417']
{'cves': '["CVE-2009-2417"]', 'title': 'CVE-2009-2417 curl', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "curl"]', 'severity': None, 'references': '["CVE-2009-2417", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417"]', 'description': "lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:194089816891249449228379305158527923476', 'package_criteria': [{'cve_id': 'CVE-2009-2417', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'curl', 'fixed_version': '7.19.5-1.1', 'affected_version_range': '< 7.19.5-1.1'}]}
91217bc0db183a99da8e9e97dc46233f7f0b8538633ff41c0e8adadb036ee0df
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:185275371269894502660822889486400539218
CVE-2009-2422 rails
The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.
['CVE-2009-2422']
['Debian GNU/Linux 12', 'rails']
['CVE-2009-2422', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2422']
{'cves': '["CVE-2009-2422"]', 'title': 'CVE-2009-2422 rails', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "rails"]', 'severity': None, 'references': '["CVE-2009-2422", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2422"]', 'description': 'The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.', 'definition_id': 'oval:org.debian:def:185275371269894502660822889486400539218', 'package_criteria': [{'cve_id': 'CVE-2009-2422', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'rails', 'fixed_version': '2.3.5-1', 'affected_version_range': '< 2.3.5-1'}]}
36e036606e61219533008c68aea072dcf6ff3e78eb6cec927dc944d958c9da34
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:59876714617119638918552221386266020438
CVE-2009-2426 tor
The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via unknown vectors. NOTE: some of these details are obtained from third party information.
['CVE-2009-2426']
['Debian GNU/Linux 12', 'tor']
['CVE-2009-2426', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2426']
{'cves': '["CVE-2009-2426"]', 'title': 'CVE-2009-2426 tor', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "tor"]', 'severity': None, 'references': '["CVE-2009-2426", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2426"]', 'description': 'The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via unknown vectors. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:59876714617119638918552221386266020438', 'package_criteria': [{'cve_id': 'CVE-2009-2426', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'tor', 'fixed_version': '0.2.0.35-1', 'affected_version_range': '< 0.2.0.35-1'}]}
74ea594e2ccab7a7dcf343e7b47dbbee3e8c1bb45161e466c8f07a5c75e5cda6
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:146769292755418433207331839713877881403
CVE-2009-2459 mimetex
Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.
['CVE-2009-2459']
['Debian GNU/Linux 12', 'mimetex']
['CVE-2009-2459', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2459']
{'cves': '["CVE-2009-2459"]', 'title': 'CVE-2009-2459 mimetex', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "mimetex"]', 'severity': None, 'references': '["CVE-2009-2459", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2459"]', 'description': 'Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \\environ, (2) \\input, and (3) \\counter TeX directives.', 'definition_id': 'oval:org.debian:def:146769292755418433207331839713877881403', 'package_criteria': [{'cve_id': 'CVE-2009-2459', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mimetex', 'fixed_version': '1.50-1.1', 'affected_version_range': '< 1.50-1.1'}]}
985c27c1f6c9516bcdf3f039c20331c666e220127cb25da3d81590e1e2ebb62b
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:336524861926704887874345735549866745923
CVE-2009-2461 mathtex
mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.
['CVE-2009-2461']
['Debian GNU/Linux 12', 'mathtex']
['CVE-2009-2461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2461']
{'cves': '["CVE-2009-2461"]', 'title': 'CVE-2009-2461 mathtex', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "mathtex"]', 'severity': None, 'references': '["CVE-2009-2461", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2461"]', 'description': 'mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.', 'definition_id': 'oval:org.debian:def:336524861926704887874345735549866745923', 'package_criteria': [{'cve_id': 'CVE-2009-2461', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mathtex', 'fixed_version': '1.03-1', 'affected_version_range': '< 1.03-1'}]}
6304519fe1e0e55d8cc3773a88f87f81a1a7da7e9cfa44c6e4abc34eaf759e88
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:102011129042105680010244235469040221409
CVE-2009-2474 litmus
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
['CVE-2009-2474']
['Debian GNU/Linux 12', 'litmus']
['CVE-2009-2474', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474']
{'cves': '["CVE-2009-2474"]', 'title': 'CVE-2009-2474 litmus', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "litmus"]', 'severity': None, 'references': '["CVE-2009-2474", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474"]', 'description': "neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:102011129042105680010244235469040221409', 'package_criteria': [{'cve_id': 'CVE-2009-2474', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'litmus', 'fixed_version': '0.13-1', 'affected_version_range': '< 0.13-1'}]}
dadc7999858d3374cfe14af0f6e7a22ada2af88241256f206445bf9bcbc1c85c
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:225027218541019339831494099839634839422
CVE-2009-2474 neon27
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
['CVE-2009-2474']
['Debian GNU/Linux 12', 'neon27']
['CVE-2009-2474', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474']
{'cves': '["CVE-2009-2474"]', 'title': 'CVE-2009-2474 neon27', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "neon27"]', 'severity': None, 'references': '["CVE-2009-2474", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474"]', 'description': "neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:225027218541019339831494099839634839422', 'package_criteria': [{'cve_id': 'CVE-2009-2474', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'neon27', 'fixed_version': '0.28.6-1', 'affected_version_range': '< 0.28.6-1'}]}
0ab0ca867c961e95c7e80474169f6e23a189e28673c445c9fdc4138c6541d40f
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:240704110048227942481293648559315319161
CVE-2009-2562 wireshark
Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.
['CVE-2009-2562']
['Debian GNU/Linux 12', 'wireshark']
['CVE-2009-2562', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562']
{'cves': '["CVE-2009-2562"]', 'title': 'CVE-2009-2562 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-2562", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562"]', 'description': 'Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.', 'definition_id': 'oval:org.debian:def:240704110048227942481293648559315319161', 'package_criteria': [{'cve_id': 'CVE-2009-2562', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.2.1-1', 'affected_version_range': '< 1.2.1-1'}]}
cc3dd97494d7cd794beae68cbfc3b38e64a3fe83e75b609b6161ce134b35c640
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:283220103337291650176916273827037548443
CVE-2009-2563 wireshark
Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.
['CVE-2009-2563']
['Debian GNU/Linux 12', 'wireshark']
['CVE-2009-2563', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563']
{'cves': '["CVE-2009-2563"]', 'title': 'CVE-2009-2563 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-2563", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563"]', 'description': 'Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.', 'definition_id': 'oval:org.debian:def:283220103337291650176916273827037548443', 'package_criteria': [{'cve_id': 'CVE-2009-2563', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.2.1-1', 'affected_version_range': '< 1.2.1-1'}]}
7223abc6c9f9e35d6e33dc6e0fc0eb80b45b9f5f33baa726fbf1a022f256e0e4
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:41328305736141197989028808185452163488
CVE-2009-2624 gzip
The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.
['CVE-2009-2624']
['Debian GNU/Linux 12', 'gzip']
['CVE-2009-2624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624']
{'cves': '["CVE-2009-2624"]', 'title': 'CVE-2009-2624 gzip', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "gzip"]', 'severity': None, 'references': '["CVE-2009-2624", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624"]', 'description': 'The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.', 'definition_id': 'oval:org.debian:def:41328305736141197989028808185452163488', 'package_criteria': [{'cve_id': 'CVE-2009-2624', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gzip', 'fixed_version': '1.3.12-8', 'affected_version_range': '< 1.3.12-8'}]}
34431a8709530524fe67459bcbab014ccbf54003cf993804d66c94c23993f1a3
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:304493765716272084089962096719797339379
CVE-2009-2625 libxerces2-java
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
['CVE-2009-2625']
['Debian GNU/Linux 12', 'libxerces2-java']
['CVE-2009-2625', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625']
{'cves': '["CVE-2009-2625"]', 'title': 'CVE-2009-2625 libxerces2-java', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libxerces2-java"]', 'severity': None, 'references': '["CVE-2009-2625", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625"]', 'description': 'XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.', 'definition_id': 'oval:org.debian:def:304493765716272084089962096719797339379', 'package_criteria': [{'cve_id': 'CVE-2009-2625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libxerces2-java', 'fixed_version': '2.9.1-4.1', 'affected_version_range': '< 2.9.1-4.1'}]}
9fb1501052d140c93c47ce4add3810b41e0170f94643e1bd849a5c6819dbd786
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:277102502336591933830975325946454144364
CVE-2009-2629 nginx
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
['CVE-2009-2629']
['Debian GNU/Linux 12', 'nginx']
['CVE-2009-2629', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2629']
{'cves': '["CVE-2009-2629"]', 'title': 'CVE-2009-2629 nginx', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "nginx"]', 'severity': None, 'references': '["CVE-2009-2629", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2629"]', 'description': 'Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.', 'definition_id': 'oval:org.debian:def:277102502336591933830975325946454144364', 'package_criteria': [{'cve_id': 'CVE-2009-2629', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nginx', 'fixed_version': '0.7.61-3', 'affected_version_range': '< 0.7.61-3'}]}
943b238116c68dee02d765738d051317b4272d6d423cdb217ac1c6246e899382
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:231157586657320490967033978313572536385
CVE-2009-2632 dovecot
Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.
['CVE-2009-2632']
['Debian GNU/Linux 12', 'dovecot']
['CVE-2009-2632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632']
{'cves': '["CVE-2009-2632"]', 'title': 'CVE-2009-2632 dovecot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dovecot"]', 'severity': None, 'references': '["CVE-2009-2632", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632"]', 'description': 'Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.', 'definition_id': 'oval:org.debian:def:231157586657320490967033978313572536385', 'package_criteria': [{'cve_id': 'CVE-2009-2632', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dovecot', 'fixed_version': '1:1.2.1-1', 'affected_version_range': '< 1:1.2.1-1'}]}
5b3ce2dbee362aebd981dac512ea1b270e2924e053a228ccb5ca2c5905b69868
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:216907791962626840608289799204968505530
CVE-2009-2658 znc
Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.
['CVE-2009-2658']
['Debian GNU/Linux 12', 'znc']
['CVE-2009-2658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2658']
{'cves': '["CVE-2009-2658"]', 'title': 'CVE-2009-2658 znc', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "znc"]', 'severity': None, 'references': '["CVE-2009-2658", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2658"]', 'description': 'Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.', 'definition_id': 'oval:org.debian:def:216907791962626840608289799204968505530', 'package_criteria': [{'cve_id': 'CVE-2009-2658', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'znc', 'fixed_version': '0.074-1', 'affected_version_range': '< 0.074-1'}]}
8d31afcac6c8908755380bb88e611418016a6a49c2643850cb0a8313cdbd2849
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:218786097106123476278237714855994691260
CVE-2009-2659 python-django
The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.
['CVE-2009-2659']
['Debian GNU/Linux 12', 'python-django']
['CVE-2009-2659', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2659']
{'cves': '["CVE-2009-2659"]', 'title': 'CVE-2009-2659 python-django', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "python-django"]', 'severity': None, 'references': '["CVE-2009-2659", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2659"]', 'description': 'The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.', 'definition_id': 'oval:org.debian:def:218786097106123476278237714855994691260', 'package_criteria': [{'cve_id': 'CVE-2009-2659', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'python-django', 'fixed_version': '1.1-1', 'affected_version_range': '< 1.1-1'}]}
06980ce84ee26056ec156a4279bb59c37f5f16a40bc08e3f892887a61096a5be
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:286718974016234650223056106963057880087
CVE-2009-2660 advi
Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295.
['CVE-2009-2660']
['Debian GNU/Linux 12', 'advi']
['CVE-2009-2660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660']
{'cves': '["CVE-2009-2660"]', 'title': 'CVE-2009-2660 advi', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "advi"]', 'severity': None, 'references': '["CVE-2009-2660", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660"]', 'description': 'Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295.', 'definition_id': 'oval:org.debian:def:286718974016234650223056106963057880087', 'package_criteria': [{'cve_id': 'CVE-2009-2660', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'advi', 'fixed_version': '1.6.0-15', 'affected_version_range': '< 1.6.0-15'}]}
a00c1fc26ab0ccaba579173a1d98483b71498269f9fef4152e79ded41528c4a9
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:76624963214604227755632122478489228687
CVE-2009-2660 camlimages
Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295.
['CVE-2009-2660']
['Debian GNU/Linux 12', 'camlimages']
['CVE-2009-2660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660']
{'cves': '["CVE-2009-2660"]', 'title': 'CVE-2009-2660 camlimages', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "camlimages"]', 'severity': None, 'references': '["CVE-2009-2660", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660"]', 'description': 'Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295.', 'definition_id': 'oval:org.debian:def:76624963214604227755632122478489228687', 'package_criteria': [{'cve_id': 'CVE-2009-2660', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'camlimages', 'fixed_version': '1:3.0.1-3', 'affected_version_range': '< 1:3.0.1-3'}]}
e894dc97698047d99608c4b4c8a6880f04af1f945db3c9766efc439b3ff9a093
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:126952981833205689869088225157955580367
CVE-2009-2661 strongswan
The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.
['CVE-2009-2661']
['Debian GNU/Linux 12', 'strongswan']
['CVE-2009-2661', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2661']
{'cves': '["CVE-2009-2661"]', 'title': 'CVE-2009-2661 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-2661", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2661"]', 'description': 'The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.', 'definition_id': 'oval:org.debian:def:126952981833205689869088225157955580367', 'package_criteria': [{'cve_id': 'CVE-2009-2661', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.3.2-1.1', 'affected_version_range': '< 4.3.2-1.1'}]}
054cbb45251ef7a7e2a176dadcf7dc1177fbb0aee9e1ee4f89cb40a81d09bef7
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:314577991129111053764120338789693133316
CVE-2009-2663 libvorbis
libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
['CVE-2009-2663']
['Debian GNU/Linux 12', 'libvorbis']
['CVE-2009-2663', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663']
{'cves': '["CVE-2009-2663"]', 'title': 'CVE-2009-2663 libvorbis', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libvorbis"]', 'severity': None, 'references': '["CVE-2009-2663", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663"]', 'description': 'libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.', 'definition_id': 'oval:org.debian:def:314577991129111053764120338789693133316', 'package_criteria': [{'cve_id': 'CVE-2009-2663', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libvorbis', 'fixed_version': '1.2.0.dfsg-6', 'affected_version_range': '< 1.2.0.dfsg-6'}]}
3e5816b2ffe0ef0dc09884007d5cc9d26dcff8c069e4ad068121138cc57062d4
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:290700755601125393283248055333125902215
CVE-2009-2663 libvorbisidec
libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
['CVE-2009-2663']
['Debian GNU/Linux 12', 'libvorbisidec']
['CVE-2009-2663', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663']
{'cves': '["CVE-2009-2663"]', 'title': 'CVE-2009-2663 libvorbisidec', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libvorbisidec"]', 'severity': None, 'references': '["CVE-2009-2663", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663"]', 'description': 'libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.', 'definition_id': 'oval:org.debian:def:290700755601125393283248055333125902215', 'package_criteria': [{'cve_id': 'CVE-2009-2663', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libvorbisidec', 'fixed_version': '1.0.2+svn16259-2', 'affected_version_range': '< 1.0.2+svn16259-2'}]}
ac411ee2bbb76e1cacd7d7141a56d661a1479cf426ae3555d75d3aa4b674a525
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:159079345828843489762978237414856274919
CVE-2009-2666 fetchmail
socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
['CVE-2009-2666']
['Debian GNU/Linux 12', 'fetchmail']
['CVE-2009-2666', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666']
{'cves': '["CVE-2009-2666"]', 'title': 'CVE-2009-2666 fetchmail', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "fetchmail"]', 'severity': None, 'references': '["CVE-2009-2666", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666"]', 'description': "socket.c in fetchmail before 6.3.11 does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:159079345828843489762978237414856274919', 'package_criteria': [{'cve_id': 'CVE-2009-2666', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'fetchmail', 'fixed_version': '6.3.9~rc2-6', 'affected_version_range': '< 6.3.9~rc2-6'}]}
1e6b110dba3edf17197bb51ddcdffe0c68b16d5ecd80c10ef25b857c6b5eea50
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:33617155369063178019811165922385047453
CVE-2009-2694 pidgin
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.
['CVE-2009-2694']
['Debian GNU/Linux 12', 'pidgin']
['CVE-2009-2694', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694']
{'cves': '["CVE-2009-2694"]', 'title': 'CVE-2009-2694 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-2694", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694"]', 'description': 'The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.', 'definition_id': 'oval:org.debian:def:33617155369063178019811165922385047453', 'package_criteria': [{'cve_id': 'CVE-2009-2694', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.5.9-1', 'affected_version_range': '< 2.5.9-1'}]}
797bf03900c47243b67697e27bf29afadc7add4e429bd5fbc9f35f039ff15039
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:4517515358224261332998392134916091154
CVE-2009-2703 pidgin
libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.
['CVE-2009-2703']
['Debian GNU/Linux 12', 'pidgin']
['CVE-2009-2703', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703']
{'cves': '["CVE-2009-2703"]', 'title': 'CVE-2009-2703 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-2703", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703"]', 'description': 'libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.', 'definition_id': 'oval:org.debian:def:4517515358224261332998392134916091154', 'package_criteria': [{'cve_id': 'CVE-2009-2703', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.6.2', 'affected_version_range': '< 2.6.2'}]}
f9e328638a1fae67d10d5e5ac4a651c354c2a1786f011376d506dcdd996c2a74
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:80778328249479244916138485035650801334
CVE-2009-2851 wordpress
Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.
['CVE-2009-2851']
['Debian GNU/Linux 12', 'wordpress']
['CVE-2009-2851', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2851']
{'cves': '["CVE-2009-2851"]', 'title': 'CVE-2009-2851 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2851", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2851"]', 'description': 'Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.', 'definition_id': 'oval:org.debian:def:80778328249479244916138485035650801334', 'package_criteria': [{'cve_id': 'CVE-2009-2851', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]}
cd8f959be935faca36eea5cc3c7a4c48a7c6f9a4a8b2ae53b7d8a38fde00c800
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:72497765616078278346608473666821123983
CVE-2009-2853 wordpress
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.
['CVE-2009-2853']
['Debian GNU/Linux 12', 'wordpress']
['CVE-2009-2853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2853']
{'cves': '["CVE-2009-2853"]', 'title': 'CVE-2009-2853 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2853"]', 'description': 'Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.', 'definition_id': 'oval:org.debian:def:72497765616078278346608473666821123983', 'package_criteria': [{'cve_id': 'CVE-2009-2853', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]}
b442f72c858ea77d9134002af1a9a2ac8db0b8ec0da52fbd1749950792becd60
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:19940761191618801220961806669100976483
CVE-2009-2854 wordpress
Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.
['CVE-2009-2854']
['Debian GNU/Linux 12', 'wordpress']
['CVE-2009-2854', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2854']
{'cves': '["CVE-2009-2854"]', 'title': 'CVE-2009-2854 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2854", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2854"]', 'description': 'Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.', 'definition_id': 'oval:org.debian:def:19940761191618801220961806669100976483', 'package_criteria': [{'cve_id': 'CVE-2009-2854', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]}
7492567b63a9ba8a6bac0153154784fb30146478331724b02a52d91c84327996
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:188327652087283964038656090741838794100
CVE-2009-2855 squid
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
['CVE-2009-2855']
['Debian GNU/Linux 12', 'squid']
['CVE-2009-2855', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2855']
{'cves': '["CVE-2009-2855"]', 'title': 'CVE-2009-2855 squid', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "squid"]', 'severity': None, 'references': '["CVE-2009-2855", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2855"]', 'description': 'The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.', 'definition_id': 'oval:org.debian:def:188327652087283964038656090741838794100', 'package_criteria': [{'cve_id': 'CVE-2009-2855', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'squid', 'fixed_version': '2.7.STABLE7-1', 'affected_version_range': '< 2.7.STABLE7-1'}]}
b684bc9b2094111e207e34f23e4e1167c0fd999708d53499c59a87118f01ee71
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:243908649608121707952372316464563536635
CVE-2009-2905 newt
Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.
['CVE-2009-2905']
['Debian GNU/Linux 12', 'newt']
['CVE-2009-2905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905']
{'cves': '["CVE-2009-2905"]', 'title': 'CVE-2009-2905 newt', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "newt"]', 'severity': None, 'references': '["CVE-2009-2905", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905"]', 'description': 'Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.', 'definition_id': 'oval:org.debian:def:243908649608121707952372316464563536635', 'package_criteria': [{'cve_id': 'CVE-2009-2905', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'newt', 'fixed_version': '0.52.10-4.1', 'affected_version_range': '< 0.52.10-4.1'}]}
73ae2991f0a5173042a57e4eaf26be0a404646f80f03878792cc9c8f5e0bf337
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:104312876745457387559221790184179861226
CVE-2009-2906 samba
smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.
['CVE-2009-2906']
['Debian GNU/Linux 12', 'samba']
['CVE-2009-2906', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906']
{'cves': '["CVE-2009-2906"]', 'title': 'CVE-2009-2906 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-2906", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906"]', 'description': 'smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.', 'definition_id': 'oval:org.debian:def:104312876745457387559221790184179861226', 'package_criteria': [{'cve_id': 'CVE-2009-2906', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.4.2-1', 'affected_version_range': '< 2:3.4.2-1'}]}
a03e37b2ce43e7c109c38db2d4807dd99eb498183d984a4203c7d4a3dcb15630
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:152285594152827863579352045013097430925
CVE-2009-2911 systemtap
SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.
['CVE-2009-2911']
['Debian GNU/Linux 12', 'systemtap']
['CVE-2009-2911', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2911']
{'cves': '["CVE-2009-2911"]', 'title': 'CVE-2009-2911 systemtap', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "systemtap"]', 'severity': None, 'references': '["CVE-2009-2911", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2911"]', 'description': 'SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.', 'definition_id': 'oval:org.debian:def:152285594152827863579352045013097430925', 'package_criteria': [{'cve_id': 'CVE-2009-2911', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'systemtap', 'fixed_version': '1.0-2', 'affected_version_range': '< 1.0-2'}]}
b06c44b663c3ab9ec24288ae4e595e657ff31323e57917991618c042cb5f60b3
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:279821878024924764092435830953652341508
CVE-2009-2936 varnish
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.
['CVE-2009-2936']
['Debian GNU/Linux 12', 'varnish']
['CVE-2009-2936', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2936']
{'cves': '["CVE-2009-2936"]', 'title': 'CVE-2009-2936 varnish', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "varnish"]', 'severity': None, 'references': '["CVE-2009-2936", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2936"]', 'description': 'The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim\'s location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.', 'definition_id': 'oval:org.debian:def:279821878024924764092435830953652341508', 'package_criteria': [{'cve_id': 'CVE-2009-2936', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'varnish', 'fixed_version': '2.1.0-2', 'affected_version_range': '< 2.1.0-2'}]}
82ea2114b84ced0d318821b7590d1dda578c00c1d049e2373400080b78ea5d01
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:261788049974532640050045893387170507569
CVE-2009-2939 postfix
The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.
['CVE-2009-2939']
['Debian GNU/Linux 12', 'postfix']
['CVE-2009-2939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2939']
{'cves': '["CVE-2009-2939"]', 'title': 'CVE-2009-2939 postfix', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "postfix"]', 'severity': None, 'references': '["CVE-2009-2939", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2939"]', 'description': 'The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.', 'definition_id': 'oval:org.debian:def:261788049974532640050045893387170507569', 'package_criteria': [{'cve_id': 'CVE-2009-2939', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'postfix', 'fixed_version': '2.6.5-3', 'affected_version_range': '< 2.6.5-3'}]}
ddc2da9a43f443c076ecb39e4345511e5c8c5d6d12b973a7ebda9b18b9d30f81
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:187138185985693500662038613448769494658
CVE-2009-2944 ikiwiki
Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.
['CVE-2009-2944']
['Debian GNU/Linux 12', 'ikiwiki']
['CVE-2009-2944', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2944']
{'cves': '["CVE-2009-2944"]', 'title': 'CVE-2009-2944 ikiwiki', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ikiwiki"]', 'severity': None, 'references': '["CVE-2009-2944", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2944"]', 'description': 'Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.', 'definition_id': 'oval:org.debian:def:187138185985693500662038613448769494658', 'package_criteria': [{'cve_id': 'CVE-2009-2944', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ikiwiki', 'fixed_version': '3.1415926', 'affected_version_range': '< 3.1415926'}]}
8f631c4255e94252e2e358d2f71dd6ebb366e3785465af702d5cdb4a89d3f86f
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:13123199226128086658774104856942357902
CVE-2009-2946 devscripts
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
['CVE-2009-2946']
['Debian GNU/Linux 12', 'devscripts']
['CVE-2009-2946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2946']
{'cves': '["CVE-2009-2946"]', 'title': 'CVE-2009-2946 devscripts', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "devscripts"]', 'severity': None, 'references': '["CVE-2009-2946", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2946"]', 'description': 'Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.', 'definition_id': 'oval:org.debian:def:13123199226128086658774104856942357902', 'package_criteria': [{'cve_id': 'CVE-2009-2946', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'devscripts', 'fixed_version': '2.10.54', 'affected_version_range': '< 2.10.54'}]}
883e5dad6b689a452f66850b15c895cbd970ad3aca5703d08c71115f21888366
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:229408503795291312278205516393010876674
CVE-2009-2947 xapian-omega
Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.
['CVE-2009-2947']
['Debian GNU/Linux 12', 'xapian-omega']
['CVE-2009-2947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2947']
{'cves': '["CVE-2009-2947"]', 'title': 'CVE-2009-2947 xapian-omega', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "xapian-omega"]', 'severity': None, 'references': '["CVE-2009-2947", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2947"]', 'description': 'Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.', 'definition_id': 'oval:org.debian:def:229408503795291312278205516393010876674', 'package_criteria': [{'cve_id': 'CVE-2009-2947', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xapian-omega', 'fixed_version': '1.0.15-2', 'affected_version_range': '< 1.0.15-2'}]}
2193a9c491d1baa63a613f15c688a0efcaa7cf531409ccdc929fba143fb120b3
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:157642303863690289932742794357916730179
CVE-2009-2948 samba
mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.
['CVE-2009-2948']
['Debian GNU/Linux 12', 'samba']
['CVE-2009-2948', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948']
{'cves': '["CVE-2009-2948"]', 'title': 'CVE-2009-2948 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-2948", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948"]', 'description': 'mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.', 'definition_id': 'oval:org.debian:def:157642303863690289932742794357916730179', 'package_criteria': [{'cve_id': 'CVE-2009-2948', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.4.2-1', 'affected_version_range': '< 2:3.4.2-1'}]}
6801b7f13658e04fec1de0c8e8e50bf7ba3e73ccefcfef4a8bec4928216b292e
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:246004658159848010907889957897248462659
CVE-2009-2957 dnsmasq
Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.
['CVE-2009-2957']
['Debian GNU/Linux 12', 'dnsmasq']
['CVE-2009-2957', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957']
{'cves': '["CVE-2009-2957"]', 'title': 'CVE-2009-2957 dnsmasq', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dnsmasq"]', 'severity': None, 'references': '["CVE-2009-2957", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957"]', 'description': 'Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.', 'definition_id': 'oval:org.debian:def:246004658159848010907889957897248462659', 'package_criteria': [{'cve_id': 'CVE-2009-2957', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dnsmasq', 'fixed_version': '2.50-1', 'affected_version_range': '< 2.50-1'}]}
8507969b2fef3b4041a83778e07e5e6c661da5043ae8c1b6f457691213d0350a
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:322154306840957602060035497182225960775
CVE-2009-2958 dnsmasq
The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.
['CVE-2009-2958']
['Debian GNU/Linux 12', 'dnsmasq']
['CVE-2009-2958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958']
{'cves': '["CVE-2009-2958"]', 'title': 'CVE-2009-2958 dnsmasq', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dnsmasq"]', 'severity': None, 'references': '["CVE-2009-2958", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958"]', 'description': 'The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.', 'definition_id': 'oval:org.debian:def:322154306840957602060035497182225960775', 'package_criteria': [{'cve_id': 'CVE-2009-2958', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dnsmasq', 'fixed_version': '2.50-1', 'affected_version_range': '< 2.50-1'}]}
0ddad68288f93f4550e0dce0e5fc284fc83e5fd6a9f84a7f81e2610765340df9
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:90350963512456067148803715029076812480
CVE-2009-2959 buildbot
Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
['CVE-2009-2959']
['Debian GNU/Linux 12', 'buildbot']
['CVE-2009-2959', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2959']
{'cves': '["CVE-2009-2959"]', 'title': 'CVE-2009-2959 buildbot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "buildbot"]', 'severity': None, 'references': '["CVE-2009-2959", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2959"]', 'description': 'Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.', 'definition_id': 'oval:org.debian:def:90350963512456067148803715029076812480', 'package_criteria': [{'cve_id': 'CVE-2009-2959', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'buildbot', 'fixed_version': '0.7.11p3-1', 'affected_version_range': '< 0.7.11p3-1'}]}
18e051b1102a0ab39f05b07d538b7ae79f5f37f50d5618d6e58e884451879db1
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:151642752892950092571932649988614183750
CVE-2009-2967 buildbot
Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959.
['CVE-2009-2967']
['Debian GNU/Linux 12', 'buildbot']
['CVE-2009-2967', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2967']
{'cves': '["CVE-2009-2967"]', 'title': 'CVE-2009-2967 buildbot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "buildbot"]', 'severity': None, 'references': '["CVE-2009-2967", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2967"]', 'description': 'Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959.', 'definition_id': 'oval:org.debian:def:151642752892950092571932649988614183750', 'package_criteria': [{'cve_id': 'CVE-2009-2967', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'buildbot', 'fixed_version': '0.7.11p3-1', 'affected_version_range': '< 0.7.11p3-1'}]}
e889b81cd1c5cfd00abec9ea305467a05294532e6dd08ccf07137695b84e18de
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:163860546688502455000666444520542426149
CVE-2009-3026 pidgin
protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.
['CVE-2009-3026']
['Debian GNU/Linux 12', 'pidgin']
['CVE-2009-3026', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026']
{'cves': '["CVE-2009-3026"]', 'title': 'CVE-2009-3026 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-3026", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026"]', 'description': 'protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.', 'definition_id': 'oval:org.debian:def:163860546688502455000666444520542426149', 'package_criteria': [{'cve_id': 'CVE-2009-3026', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.6.1-1', 'affected_version_range': '< 2.6.1-1'}]}
a78c86be0fbca73bbc5186e5aec38d8ddd41ac41771ba7446c04a0f63f6ed408
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:183700420581963993296964300988610936628
CVE-2006-4253 thunderbird
Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.
['CVE-2006-4253']
['Debian GNU/Linux 12', 'thunderbird']
['CVE-2006-4253', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253']
{'cves': '["CVE-2006-4253"]', 'title': 'CVE-2006-4253 thunderbird', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "thunderbird"]', 'severity': None, 'references': '["CVE-2006-4253", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253"]', 'description': 'Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.', 'definition_id': 'oval:org.debian:def:183700420581963993296964300988610936628', 'package_criteria': [{'cve_id': 'CVE-2006-4253', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thunderbird', 'fixed_version': '1.5.0.7-1', 'affected_version_range': '< 1.5.0.7-1'}]}
a38c25104a4fc074196ad9e669813f7d695f289f389d990e8140239da12602f1
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:91064102204529443242478808786574481467
CVE-2009-3040 ocsinventory-server
Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.
['CVE-2009-3040']
['Debian GNU/Linux 12', 'ocsinventory-server']
['CVE-2009-3040', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3040']
{'cves': '["CVE-2009-3040"]', 'title': 'CVE-2009-3040 ocsinventory-server', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ocsinventory-server"]', 'severity': None, 'references': '["CVE-2009-3040", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3040"]', 'description': 'Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.', 'definition_id': 'oval:org.debian:def:91064102204529443242478808786574481467', 'package_criteria': [{'cve_id': 'CVE-2009-3040', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ocsinventory-server', 'fixed_version': '1.02.1-2', 'affected_version_range': '< 1.02.1-2'}]}
a3ce064100b95eccab93936dd7744c17c08cf5b091e2525cdfe5aa8a6167bdbe
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:202945604118434733963780146067626061122
CVE-2009-3042 ocsinventory-server
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.
['CVE-2009-3042']
['Debian GNU/Linux 12', 'ocsinventory-server']
['CVE-2009-3042', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3042']
{'cves': '["CVE-2009-3042"]', 'title': 'CVE-2009-3042 ocsinventory-server', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ocsinventory-server"]', 'severity': None, 'references': '["CVE-2009-3042", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3042"]', 'description': 'SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.', 'definition_id': 'oval:org.debian:def:202945604118434733963780146067626061122', 'package_criteria': [{'cve_id': 'CVE-2009-3042', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ocsinventory-server', 'fixed_version': '1.02.1-2', 'affected_version_range': '< 1.02.1-2'}]}
758ecc56f78f4b1827585582dd844390df4e295c7a9e889b22a113d05c94510b
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:165218588439385472658637393191257493039
CVE-2009-3050 htmldoc
Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.
['CVE-2009-3050']
['Debian GNU/Linux 12', 'htmldoc']
['CVE-2009-3050', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3050']
{'cves': '["CVE-2009-3050"]', 'title': 'CVE-2009-3050 htmldoc', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "htmldoc"]', 'severity': None, 'references': '["CVE-2009-3050", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3050"]', 'description': 'Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.', 'definition_id': 'oval:org.debian:def:165218588439385472658637393191257493039', 'package_criteria': [{'cve_id': 'CVE-2009-3050', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'htmldoc', 'fixed_version': '1.8.27-4.1', 'affected_version_range': '< 1.8.27-4.1'}]}
a0b13d505adbae6feae3bbb8031cae7808b3aebb9f09648c1f5f88225f86f6f0
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
wheezy
oval:org.debian:def:207871247964001913596224375064462787946
DSA-3409-1 putty
security update
['CVE-2015-5309']
['Debian GNU/Linux 7', 'putty']
['CVE-2015-5309', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5309']
{'cves': '["CVE-2015-5309"]', 'title': 'DSA-3409-1 putty', 'issued': None, 'release': 'wheezy', 'updated': None, 'affected': '["Debian GNU/Linux 7", "putty"]', 'severity': None, 'references': '["CVE-2015-5309", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5309"]', 'description': 'security update', 'definition_id': 'oval:org.debian:def:207871247964001913596224375064462787946', 'package_criteria': [{'cve_id': 'CVE-2015-5309', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'putty', 'fixed_version': '0.62-9+deb7u3', 'affected_version_range': '< 0.62-9+deb7u3'}]}
a25cc4ee5955858402f5d9aa78e8c9ec9b066b9c49ef64ba650027363556ec39
2026-05-30 01:54:19.138681+03:00
2026-06-29 20:17:43.385302+03:00
bookworm
oval:org.debian:def:285206647540308228391116875222403724034
CVE-2009-3083 pidgin
The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.
['CVE-2009-3083']
['Debian GNU/Linux 12', 'pidgin']
['CVE-2009-3083', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083']
{'cves': '["CVE-2009-3083"]', 'title': 'CVE-2009-3083 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-3083", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083"]', 'description': 'The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.', 'definition_id': 'oval:org.debian:def:285206647540308228391116875222403724034', 'package_criteria': [{'cve_id': 'CVE-2009-3083', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.6.2-1', 'affected_version_range': '< 2.6.2-1'}]}
6bfebd0f7f79fad2c319a100405575bc8cf9dbe42d2288c121ae5eff000668c9
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:101370027722286993380737289847070643415
CVE-2009-3086 rails
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
['CVE-2009-3086']
['Debian GNU/Linux 12', 'rails']
['CVE-2009-3086', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3086']
{'cves': '["CVE-2009-3086"]', 'title': 'CVE-2009-3086 rails', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "rails"]', 'severity': None, 'references': '["CVE-2009-3086", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3086"]', 'description': 'A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.', 'definition_id': 'oval:org.debian:def:101370027722286993380737289847070643415', 'package_criteria': [{'cve_id': 'CVE-2009-3086', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'rails', 'fixed_version': '2.2.3-1', 'affected_version_range': '< 2.2.3-1'}]}
005da560e80c4d12a910a743fc472c131259cbfb99f3634d92bd58e1cdd76693
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:150432487751440637607487750848230183835
CVE-2009-3095 apache2
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
['CVE-2009-3095']
['Debian GNU/Linux 12', 'apache2']
['CVE-2009-3095', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095']
{'cves': '["CVE-2009-3095"]', 'title': 'CVE-2009-3095 apache2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apache2"]', 'severity': None, 'references': '["CVE-2009-3095", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095"]', 'description': 'The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.', 'definition_id': 'oval:org.debian:def:150432487751440637607487750848230183835', 'package_criteria': [{'cve_id': 'CVE-2009-3095', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apache2', 'fixed_version': '2.2.13-2', 'affected_version_range': '< 2.2.13-2'}]}
285dc06d74e15e9cf77603d71ec4dedd6fac1801be80cb0ef727a0140c4286c4
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:337820251647819538673752925642307060309
CVE-2009-3111 freeradius
The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.
['CVE-2009-3111']
['Debian GNU/Linux 12', 'freeradius']
['CVE-2009-3111', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3111']
{'cves': '["CVE-2009-3111"]', 'title': 'CVE-2009-3111 freeradius', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "freeradius"]', 'severity': None, 'references': '["CVE-2009-3111", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3111"]', 'description': 'The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.', 'definition_id': 'oval:org.debian:def:337820251647819538673752925642307060309', 'package_criteria': [{'cve_id': 'CVE-2009-3111', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'freeradius', 'fixed_version': '2.0.0-1', 'affected_version_range': '< 2.0.0-1'}]}
7fa5a3399f3d6232358b15a040c7d6ef8181c8794513515fff9c7c64dbfc3d2a
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:77519067271661085615908637117142463896
CVE-2009-3233 changetrack
changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.
['CVE-2009-3233']
['Debian GNU/Linux 12', 'changetrack']
['CVE-2009-3233', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3233']
{'cves': '["CVE-2009-3233"]', 'title': 'CVE-2009-3233 changetrack', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "changetrack"]', 'severity': None, 'references': '["CVE-2009-3233", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3233"]', 'description': 'changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.', 'definition_id': 'oval:org.debian:def:77519067271661085615908637117142463896', 'package_criteria': [{'cve_id': 'CVE-2009-3233', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'changetrack', 'fixed_version': '4.5-2', 'affected_version_range': '< 4.5-2'}]}
8ad882939fa59add397819b19b6186509c90ea031d16829e5128360f00d809bc
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:96085401760679768789044073718547980880
CVE-2009-3235 dovecot
Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.
['CVE-2009-3235']
['Debian GNU/Linux 12', 'dovecot']
['CVE-2009-3235', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235']
{'cves': '["CVE-2009-3235"]', 'title': 'CVE-2009-3235 dovecot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dovecot"]', 'severity': None, 'references': '["CVE-2009-3235", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235"]', 'description': 'Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.', 'definition_id': 'oval:org.debian:def:96085401760679768789044073718547980880', 'package_criteria': [{'cve_id': 'CVE-2009-3235', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dovecot', 'fixed_version': '1:1.2.1-1', 'affected_version_range': '< 1:1.2.1-1'}]}
871f7ca4f6663725fc6d964297604d2ab6c16c545241f5bd8dbaa698bad9f234
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:9786195431872739144462304794814206940
CVE-2009-3241 wireshark
Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.
['CVE-2009-3241']
['Debian GNU/Linux 12', 'wireshark']
['CVE-2009-3241', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3241']
{'cves': '["CVE-2009-3241"]', 'title': 'CVE-2009-3241 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-3241", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3241"]', 'description': 'Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.', 'definition_id': 'oval:org.debian:def:9786195431872739144462304794814206940', 'package_criteria': [{'cve_id': 'CVE-2009-3241', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.2.2-1', 'affected_version_range': '< 1.2.2-1'}]}
912554dcdb5aed53159d2b40dfd5ae52573c9093b8193d389449f2a804da108a
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:57124108271738073518832475128381496461
CVE-2009-3287 thin
lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.
['CVE-2009-3287']
['Debian GNU/Linux 12', 'thin']
['CVE-2009-3287', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3287']
{'cves': '["CVE-2009-3287"]', 'title': 'CVE-2009-3287 thin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "thin"]', 'severity': None, 'references': '["CVE-2009-3287", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3287"]', 'description': 'lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.', 'definition_id': 'oval:org.debian:def:57124108271738073518832475128381496461', 'package_criteria': [{'cve_id': 'CVE-2009-3287', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thin', 'fixed_version': '1.2.4-1', 'affected_version_range': '< 1.2.4-1'}]}
44205339519020de69a3bc0085136df232ce149fc6a02f459d6fed0721bf1b5f
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:146249366598113472856943339170912844190
CVE-2009-3289 glib2.0
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.
['CVE-2009-3289']
['Debian GNU/Linux 12', 'glib2.0']
['CVE-2009-3289', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3289']
{'cves': '["CVE-2009-3289"]', 'title': 'CVE-2009-3289 glib2.0', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "glib2.0"]', 'severity': None, 'references': '["CVE-2009-3289", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3289"]', 'description': 'The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.', 'definition_id': 'oval:org.debian:def:146249366598113472856943339170912844190', 'package_criteria': [{'cve_id': 'CVE-2009-3289', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'glib2.0', 'fixed_version': '2.22.0-1', 'affected_version_range': '< 2.22.0-1'}]}
df8cb4d8163d73620e0887905850a0790df97184d0468a7dd0d52fd14006aa01
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00
bookworm
oval:org.debian:def:150387314635769531534728323264705197154
CVE-2009-3295 krb5
The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.
['CVE-2009-3295']
['Debian GNU/Linux 12', 'krb5']
['CVE-2009-3295', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3295']
{'cves': '["CVE-2009-3295"]', 'title': 'CVE-2009-3295 krb5', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "krb5"]', 'severity': None, 'references': '["CVE-2009-3295", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3295"]', 'description': 'The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.', 'definition_id': 'oval:org.debian:def:150387314635769531534728323264705197154', 'package_criteria': [{'cve_id': 'CVE-2009-3295', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'krb5', 'fixed_version': '1.7+dfsg-4', 'affected_version_range': '< 1.7+dfsg-4'}]}
e1b76aae8a6e880845dad27c2195c37a31e452857c87184a0aa953829066f1e8
2026-05-30 01:53:22.099498+03:00
2026-06-29 20:15:56.598384+03:00