Zeros312
bookworm | oval:org.debian:def:17150963541325650009340851204767583853 | CVE-2008-3834 dbus | The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error. | ['CVE-2008-3834'] | ['Debian GNU/Linux 12', 'dbus'] | ['CVE-2008-3834', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834'] | {'cves': '["CVE-2008-3834"]', 'title': 'CVE-2008-3834 dbus', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dbus"]', 'severity': None, 'references': '["CVE-2008-3834", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834"]', 'description': 'The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.', 'definition_id': 'oval:org.debian:def:17150963541325650009340851204767583853', 'package_criteria': [{'cve_id': 'CVE-2008-3834', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dbus', 'fixed_version': '1.2.1-4', 'affected_version_range': '< 1.2.1-4'}]} | e624a6649886da1cd2b6f075c4e8676292b9712d980146141c906caddab92b1b | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:176701901440535772456826615525043252343 | CVE-2009-1721 openexr | The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer. | ['CVE-2009-1721'] | ['Debian GNU/Linux 12', 'openexr'] | ['CVE-2009-1721', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1721'] | {'cves': '["CVE-2009-1721"]', 'title': 'CVE-2009-1721 openexr', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "openexr"]', 'severity': None, 'references': '["CVE-2009-1721", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1721"]', 'description': 'The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.', 'definition_id': 'oval:org.debian:def:176701901440535772456826615525043252343', 'package_criteria': [{'cve_id': 'CVE-2009-1721', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openexr', 'fixed_version': '1.6.1-4.1', 'affected_version_range': '< 1.6.1-4.1'}]} | 079a5eef48c046e1162e359ccf653609be2360ed78f182859a3cefb3f77051f4 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:316741602078639721803970548724118741389 | CVE-2009-1722 openexr | Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors. | ['CVE-2009-1722'] | ['Debian GNU/Linux 12', 'openexr'] | ['CVE-2009-1722', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1722'] | {'cves': '["CVE-2009-1722"]', 'title': 'CVE-2009-1722 openexr', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "openexr"]', 'severity': None, 'references': '["CVE-2009-1722", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1722"]', 'description': 'Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.', 'definition_id': 'oval:org.debian:def:316741602078639721803970548724118741389', 'package_criteria': [{'cve_id': 'CVE-2009-1722', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openexr', 'fixed_version': '1.6.1-1', 'affected_version_range': '< 1.6.1-1'}]} | b5e41fc3c2fee4c4694ad98a8f01dab2e2f1059eb47b3d1b37dbe0b1c5871299 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:100315230763869213438215337750009774565 | CVE-2009-1757 transmission | Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | ['CVE-2009-1757'] | ['Debian GNU/Linux 12', 'transmission'] | ['CVE-2009-1757', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1757'] | {'cves': '["CVE-2009-1757"]', 'title': 'CVE-2009-1757 transmission', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "transmission"]', 'severity': None, 'references': '["CVE-2009-1757", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1757"]', 'description': 'Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.', 'definition_id': 'oval:org.debian:def:100315230763869213438215337750009774565', 'package_criteria': [{'cve_id': 'CVE-2009-1757', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'transmission', 'fixed_version': '1.61-1', 'affected_version_range': '< 1.61-1'}]} | 91cbbcc71649282f2c8aada6721eddfc5673a37aed776074ffc0290138064c11 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:110594252090381341836912233080357839237 | CVE-2009-1759 ctorrent | Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path. | ['CVE-2009-1759'] | ['Debian GNU/Linux 12', 'ctorrent'] | ['CVE-2009-1759', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1759'] | {'cves': '["CVE-2009-1759"]', 'title': 'CVE-2009-1759 ctorrent', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ctorrent"]', 'severity': None, 'references': '["CVE-2009-1759", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1759"]', 'description': 'Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.', 'definition_id': 'oval:org.debian:def:110594252090381341836912233080357839237', 'package_criteria': [{'cve_id': 'CVE-2009-1759', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ctorrent', 'fixed_version': '1.3.4-dnh3.2-1.1', 'affected_version_range': '< 1.3.4-dnh3.2-1.1'}]} | 62ad217dd0f766b3b93c4121b4edfaa2cf5c8b8b2b05bf8cdd18d41efe204d37 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:114313775752707857027208698847116106805 | CVE-2009-1760 libtorrent-rasterbar | Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file. | ['CVE-2009-1760'] | ['Debian GNU/Linux 12', 'libtorrent-rasterbar'] | ['CVE-2009-1760', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760'] | {'cves': '["CVE-2009-1760"]', 'title': 'CVE-2009-1760 libtorrent-rasterbar', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libtorrent-rasterbar"]', 'severity': None, 'references': '["CVE-2009-1760", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760"]', 'description': 'Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.', 'definition_id': 'oval:org.debian:def:114313775752707857027208698847116106805', 'package_criteria': [{'cve_id': 'CVE-2009-1760', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libtorrent-rasterbar', 'fixed_version': '0.14.4-1', 'affected_version_range': '< 0.14.4-1'}]} | 2f6c3c722b8c06af414c563ab871cf21ebd667cffd631f32afbb9751def9fbf1 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:226511505271699374456681548240454886850 | CVE-2009-1788 libsndfile | Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value. | ['CVE-2009-1788'] | ['Debian GNU/Linux 12', 'libsndfile'] | ['CVE-2009-1788', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788'] | {'cves': '["CVE-2009-1788"]', 'title': 'CVE-2009-1788 libsndfile', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libsndfile"]', 'severity': None, 'references': '["CVE-2009-1788", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1788"]', 'description': 'Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.', 'definition_id': 'oval:org.debian:def:226511505271699374456681548240454886850', 'package_criteria': [{'cve_id': 'CVE-2009-1788', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libsndfile', 'fixed_version': '1.0.20-1', 'affected_version_range': '< 1.0.20-1'}]} | 25f966cc730993601809b5b808464a69bce677821acbd268aeb0f2d4895d78c7 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:180797773148341744289330461767139605285 | CVE-2009-1789 eggdrop | mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807. | ['CVE-2009-1789'] | ['Debian GNU/Linux 12', 'eggdrop'] | ['CVE-2009-1789', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1789'] | {'cves': '["CVE-2009-1789"]', 'title': 'CVE-2009-1789 eggdrop', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "eggdrop"]', 'severity': None, 'references': '["CVE-2009-1789", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1789"]', 'description': 'mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.', 'definition_id': 'oval:org.debian:def:180797773148341744289330461767139605285', 'package_criteria': [{'cve_id': 'CVE-2009-1789', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'eggdrop', 'fixed_version': '1.6.19-1.2', 'affected_version_range': '< 1.6.19-1.2'}]} | 7224e66dcc0f0c8e3dd8209906711649fc470d99e3c31bbb78f5e728053cbff1 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:233582373034493297591578929406707608538 | CVE-2009-1829 wireshark | Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets. | ['CVE-2009-1829'] | ['Debian GNU/Linux 12', 'wireshark'] | ['CVE-2009-1829', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829'] | {'cves': '["CVE-2009-1829"]', 'title': 'CVE-2009-1829 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-1829", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829"]', 'description': 'Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.', 'definition_id': 'oval:org.debian:def:233582373034493297591578929406707608538', 'package_criteria': [{'cve_id': 'CVE-2009-1829', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.0.8-1', 'affected_version_range': '< 1.0.8-1'}]} | 56839ae57964cf229870fae0f93756d7880ccd240832c780b9e62012eaaca02d | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:226733781467473222940862071199261044135 | CVE-2009-1882 graphicsmagick | Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information. | ['CVE-2009-1882'] | ['Debian GNU/Linux 12', 'graphicsmagick'] | ['CVE-2009-1882', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882'] | {'cves': '["CVE-2009-1882"]', 'title': 'CVE-2009-1882 graphicsmagick', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "graphicsmagick"]', 'severity': None, 'references': '["CVE-2009-1882", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882"]', 'description': 'Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:226733781467473222940862071199261044135', 'package_criteria': [{'cve_id': 'CVE-2009-1882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'graphicsmagick', 'fixed_version': '1.3.5-5.1', 'affected_version_range': '< 1.3.5-5.1'}]} | 686ee4ce8da41b820ceb1b8629a08b77045dd86f37f16a5a37ebb217dc949a38 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:149927110986321008188992046286919145652 | CVE-2009-1882 imagemagick | Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information. | ['CVE-2009-1882'] | ['Debian GNU/Linux 12', 'imagemagick'] | ['CVE-2009-1882', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882'] | {'cves': '["CVE-2009-1882"]', 'title': 'CVE-2009-1882 imagemagick', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "imagemagick"]', 'severity': None, 'references': '["CVE-2009-1882", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1882"]', 'description': 'Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:149927110986321008188992046286919145652', 'package_criteria': [{'cve_id': 'CVE-2009-1882', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'imagemagick', 'fixed_version': '7:6.5.1.0-1.1', 'affected_version_range': '< 7:6.5.1.0-1.1'}]} | a7fc484ee621c0c3d18d97ead63306ad51e2d421b1a09fd05a730c8114d93328 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:336421291198663336624963504504667777509 | CVE-2009-1884 libcompress-raw-bzip2-perl | Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391. | ['CVE-2009-1884'] | ['Debian GNU/Linux 12', 'libcompress-raw-bzip2-perl'] | ['CVE-2009-1884', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1884'] | {'cves': '["CVE-2009-1884"]', 'title': 'CVE-2009-1884 libcompress-raw-bzip2-perl', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libcompress-raw-bzip2-perl"]', 'severity': None, 'references': '["CVE-2009-1884", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1884"]', 'description': 'Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.', 'definition_id': 'oval:org.debian:def:336421291198663336624963504504667777509', 'package_criteria': [{'cve_id': 'CVE-2009-1884', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcompress-raw-bzip2-perl', 'fixed_version': '2.018-1', 'affected_version_range': '< 2.018-1'}]} | b1f8c6689ba0acfd8d2e931a79f6eabad7f8a754ce612c1dc7f5721b5013f4d1 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:325796050154074568679461610359218879764 | CVE-2009-1885 xerces-c | Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework. | ['CVE-2009-1885'] | ['Debian GNU/Linux 12', 'xerces-c'] | ['CVE-2009-1885', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1885'] | {'cves': '["CVE-2009-1885"]', 'title': 'CVE-2009-1885 xerces-c', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "xerces-c"]', 'severity': None, 'references': '["CVE-2009-1885", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1885"]', 'description': 'Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.', 'definition_id': 'oval:org.debian:def:325796050154074568679461610359218879764', 'package_criteria': [{'cve_id': 'CVE-2009-1885', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xerces-c', 'fixed_version': '3.0.1-2', 'affected_version_range': '< 3.0.1-2'}]} | eea6b66c7cf410888aeaea9c6c65857e740e7653c82f54908fe8fdd8a01cef0b | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:217059961636896520459072842491256885194 | CVE-2009-1886 samba | Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename. | ['CVE-2009-1886'] | ['Debian GNU/Linux 12', 'samba'] | ['CVE-2009-1886', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886'] | {'cves': '["CVE-2009-1886"]', 'title': 'CVE-2009-1886 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-1886", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1886"]', 'description': 'Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.', 'definition_id': 'oval:org.debian:def:217059961636896520459072842491256885194', 'package_criteria': [{'cve_id': 'CVE-2009-1886', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.3.6-1', 'affected_version_range': '< 2:3.3.6-1'}]} | 055f5a824e844de871fb6c43bd40a10623e5ac50999e5cbbf37397ca63787019 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:181290405743222665189904300785379164258 | CVE-2009-1888 samba | The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory. | ['CVE-2009-1888'] | ['Debian GNU/Linux 12', 'samba'] | ['CVE-2009-1888', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888'] | {'cves': '["CVE-2009-1888"]', 'title': 'CVE-2009-1888 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-1888", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1888"]', 'description': 'The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, when dos filemode is enabled, allows remote attackers to modify access control lists for files via vectors related to read access to uninitialized memory.', 'definition_id': 'oval:org.debian:def:181290405743222665189904300785379164258', 'package_criteria': [{'cve_id': 'CVE-2009-1888', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.3.6-1', 'affected_version_range': '< 2:3.3.6-1'}]} | cb5cc12ca770b04cd4b4197e7680b018b0ec274394a9290ae2086b4997c9f880 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:268884902731360188882447881905316361473 | CVE-2009-1889 pidgin | The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory. | ['CVE-2009-1889'] | ['Debian GNU/Linux 12', 'pidgin'] | ['CVE-2009-1889', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889'] | {'cves': '["CVE-2009-1889"]', 'title': 'CVE-2009-1889 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-1889", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1889"]', 'description': 'The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS message type, which allows remote attackers to cause a denial of service (application crash) via a crafted ICQ web message that triggers allocation of a large amount of memory.', 'definition_id': 'oval:org.debian:def:268884902731360188882447881905316361473', 'package_criteria': [{'cve_id': 'CVE-2009-1889', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.5.8-1', 'affected_version_range': '< 2.5.8-1'}]} | 3b877bd49a268ddaeb0c52a9e7bd91d6b61936dbd601daae94087010adc18ac8 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:314085580784063994156934279618771546219 | CVE-2009-1890 apache2 | The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests. | ['CVE-2009-1890'] | ['Debian GNU/Linux 12', 'apache2'] | ['CVE-2009-1890', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890'] | {'cves': '["CVE-2009-1890"]', 'title': 'CVE-2009-1890 apache2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apache2"]', 'severity': None, 'references': '["CVE-2009-1890", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1890"]', 'description': 'The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.', 'definition_id': 'oval:org.debian:def:314085580784063994156934279618771546219', 'package_criteria': [{'cve_id': 'CVE-2009-1890', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apache2', 'fixed_version': '2.2.11-7', 'affected_version_range': '< 2.2.11-7'}]} | bee7a6fcdeb7fa4978a3414f2ef0ddca3834b8ab8b3e5d2bd844c152d02a21ec | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:26317716075797878364632916812815638529 | CVE-2009-1891 apache2 | The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption). | ['CVE-2009-1891'] | ['Debian GNU/Linux 12', 'apache2'] | ['CVE-2009-1891', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891'] | {'cves': '["CVE-2009-1891"]', 'title': 'CVE-2009-1891 apache2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apache2"]', 'severity': None, 'references': '["CVE-2009-1891", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891"]', 'description': 'The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).', 'definition_id': 'oval:org.debian:def:26317716075797878364632916812815638529', 'package_criteria': [{'cve_id': 'CVE-2009-1891', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apache2', 'fixed_version': '2.2.11-7', 'affected_version_range': '< 2.2.11-7'}]} | 47c8bdb0bd4f709a30d3b8c3feac47505782cafddfefa8e175e225e820f28cfb | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:75431260087458950854639605098454749350 | CVE-2009-1892 isc-dhcp | dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests. | ['CVE-2009-1892'] | ['Debian GNU/Linux 12', 'isc-dhcp'] | ['CVE-2009-1892', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1892'] | {'cves': '["CVE-2009-1892"]', 'title': 'CVE-2009-1892 isc-dhcp', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "isc-dhcp"]', 'severity': None, 'references': '["CVE-2009-1892", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1892"]', 'description': 'dhcpd in ISC DHCP 3.0.4 and 3.1.1, when the dhcp-client-identifier and hardware ethernet configuration settings are both used, allows remote attackers to cause a denial of service (daemon crash) via unspecified requests.', 'definition_id': 'oval:org.debian:def:75431260087458950854639605098454749350', 'package_criteria': [{'cve_id': 'CVE-2009-1892', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'isc-dhcp', 'fixed_version': '3.1.2p1-2', 'affected_version_range': '< 3.1.2p1-2'}]} | e76c0ba9a8c03e59638c4be8cecd21c4b34dff6d8c03530ea88435cbd14811fc | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:152563419271831605449815250667138881191 | CVE-2009-1956 apr-util | Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input. | ['CVE-2009-1956'] | ['Debian GNU/Linux 12', 'apr-util'] | ['CVE-2009-1956', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956'] | {'cves': '["CVE-2009-1956"]', 'title': 'CVE-2009-1956 apr-util', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apr-util"]', 'severity': None, 'references': '["CVE-2009-1956", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1956"]', 'description': 'Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.', 'definition_id': 'oval:org.debian:def:152563419271831605449815250667138881191', 'package_criteria': [{'cve_id': 'CVE-2009-1956', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apr-util', 'fixed_version': '1.3.7+dfsg-1', 'affected_version_range': '< 1.3.7+dfsg-1'}]} | 339283441a66a759797de2875c5606bc0c9052585ff7baad86e4d3746d9d05be | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:126232051260083801149194372368517090769 | CVE-2009-1957 strongswan | charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request. | ['CVE-2009-1957'] | ['Debian GNU/Linux 12', 'strongswan'] | ['CVE-2009-1957', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1957'] | {'cves': '["CVE-2009-1957"]', 'title': 'CVE-2009-1957 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-1957", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1957"]', 'description': 'charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.', 'definition_id': 'oval:org.debian:def:126232051260083801149194372368517090769', 'package_criteria': [{'cve_id': 'CVE-2009-1957', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.2.14-1.1', 'affected_version_range': '< 4.2.14-1.1'}]} | c24a266c5ad9b16eeebd1a5addf6cf9cc416452a173ab4600038fe2c4a1d21b8 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:327857179248031889548856667074163370091 | CVE-2009-1958 strongswan | charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector. | ['CVE-2009-1958'] | ['Debian GNU/Linux 12', 'strongswan'] | ['CVE-2009-1958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1958'] | {'cves': '["CVE-2009-1958"]', 'title': 'CVE-2009-1958 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-1958", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1958"]', 'description': 'charon/sa/tasks/child_create.c in the charon daemon in strongSWAN before 4.3.1 switches the NULL checks for TSi and TSr payloads, which allows remote attackers to cause a denial of service via an IKE_AUTH request without a (1) TSi or (2) TSr traffic selector.', 'definition_id': 'oval:org.debian:def:327857179248031889548856667074163370091', 'package_criteria': [{'cve_id': 'CVE-2009-1958', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.2.14-1.1', 'affected_version_range': '< 4.2.14-1.1'}]} | ba81c767f1a4624cf25092d97c675e43f038cd3484f03560689ebe8f49150a77 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:264821896760517898830389176499916489673 | CVE-2009-1959 irssi | Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow. | ['CVE-2009-1959'] | ['Debian GNU/Linux 12', 'irssi'] | ['CVE-2009-1959', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1959'] | {'cves': '["CVE-2009-1959"]', 'title': 'CVE-2009-1959 irssi', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "irssi"]', 'severity': None, 'references': '["CVE-2009-1959", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1959"]', 'description': 'Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.', 'definition_id': 'oval:org.debian:def:264821896760517898830389176499916489673', 'package_criteria': [{'cve_id': 'CVE-2009-1959', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'irssi', 'fixed_version': '0.8.13-2', 'affected_version_range': '< 0.8.13-2'}]} | 4d194dddca42d000acac9f15faddbfc3915899cf49fa82a1ce706deb69f3e0e6 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:205142739946424585275468486261834368829 | CVE-2009-1960 dokuwiki | inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs. | ['CVE-2009-1960'] | ['Debian GNU/Linux 12', 'dokuwiki'] | ['CVE-2009-1960', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1960'] | {'cves': '["CVE-2009-1960"]', 'title': 'CVE-2009-1960 dokuwiki', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dokuwiki"]', 'severity': None, 'references': '["CVE-2009-1960", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1960"]', 'description': 'inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.', 'definition_id': 'oval:org.debian:def:205142739946424585275468486261834368829', 'package_criteria': [{'cve_id': 'CVE-2009-1960', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dokuwiki', 'fixed_version': '0.0.20090214b-1', 'affected_version_range': '< 0.0.20090214b-1'}]} | 7addf3f13764250a5d1760ea6b10f680bb11bd43344c65242ba28a6918d2f988 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:238690468956056088465320423337515418289 | CVE-2009-1962 xfig | Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID. | ['CVE-2009-1962'] | ['Debian GNU/Linux 12', 'xfig'] | ['CVE-2009-1962', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1962'] | {'cves': '["CVE-2009-1962"]', 'title': 'CVE-2009-1962 xfig', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "xfig"]', 'severity': None, 'references': '["CVE-2009-1962", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1962"]', 'description': 'Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.', 'definition_id': 'oval:org.debian:def:238690468956056088465320423337515418289', 'package_criteria': [{'cve_id': 'CVE-2009-1962', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xfig', 'fixed_version': '1:3.2.5.a-1', 'affected_version_range': '< 1:3.2.5.a-1'}]} | 03c872c20e95f909aa88088330f4683b3c948071abd111c256a17d2d645535ff | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:171844929339957540114773860932096565428 | CVE-2009-2166 ocsinventory-server | Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter. | ['CVE-2009-2166'] | ['Debian GNU/Linux 12', 'ocsinventory-server'] | ['CVE-2009-2166', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2166'] | {'cves': '["CVE-2009-2166"]', 'title': 'CVE-2009-2166 ocsinventory-server', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ocsinventory-server"]', 'severity': None, 'references': '["CVE-2009-2166", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2166"]', 'description': 'Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter.', 'definition_id': 'oval:org.debian:def:171844929339957540114773860932096565428', 'package_criteria': [{'cve_id': 'CVE-2009-2166', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ocsinventory-server', 'fixed_version': '1.02.1-1', 'affected_version_range': '< 1.02.1-1'}]} | 76ac76742260d538e32dedbb220a035a3e17c159c3d3e6ab76fa646159db7045 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:264135998950516818315799196695300167303 | CVE-2009-2174 gupnp | GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message. | ['CVE-2009-2174'] | ['Debian GNU/Linux 12', 'gupnp'] | ['CVE-2009-2174', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2174'] | {'cves': '["CVE-2009-2174"]', 'title': 'CVE-2009-2174 gupnp', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "gupnp"]', 'severity': None, 'references': '["CVE-2009-2174", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2174"]', 'description': 'GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control message.', 'definition_id': 'oval:org.debian:def:264135998950516818315799196695300167303', 'package_criteria': [{'cve_id': 'CVE-2009-2174', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gupnp', 'fixed_version': '0.12.6-3.1', 'affected_version_range': '< 0.12.6-3.1'}]} | ed87c9bb0cec8969cd92e195467784f28258dd998d0968768525e7d2cf102dfb | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:16007930785623427920233057576304284254 | CVE-2009-2185 strongswan | The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string. | ['CVE-2009-2185'] | ['Debian GNU/Linux 12', 'strongswan'] | ['CVE-2009-2185', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185'] | {'cves': '["CVE-2009-2185"]', 'title': 'CVE-2009-2185 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-2185", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2185"]', 'description': 'The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.', 'definition_id': 'oval:org.debian:def:16007930785623427920233057576304284254', 'package_criteria': [{'cve_id': 'CVE-2009-2185', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.2.14-1.2', 'affected_version_range': '< 4.2.14-1.2'}]} | a2617204e80887c45a7d729bdb1f967a98e4ede5fcf92919049dd70087f614fc | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:71863795599795562682229526981736124233 | CVE-2009-2281 mapserver | Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840. | ['CVE-2009-2281'] | ['Debian GNU/Linux 12', 'mapserver'] | ['CVE-2009-2281', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2281'] | {'cves': '["CVE-2009-2281"]', 'title': 'CVE-2009-2281 mapserver', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "mapserver"]', 'severity': None, 'references': '["CVE-2009-2281", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2281"]', 'description': 'Multiple heap-based buffer underflows in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x through 4.10.4 and 5.x before 5.4.2 allow remote attackers to execute arbitrary code via (1) a crafted Content-Length HTTP header or (2) a large HTTP request, related to an integer overflow that triggers a heap-based buffer overflow. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-0840.', 'definition_id': 'oval:org.debian:def:71863795599795562682229526981736124233', 'package_criteria': [{'cve_id': 'CVE-2009-2281', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mapserver', 'fixed_version': '5.4.2-1', 'affected_version_range': '< 5.4.2-1'}]} | 9c13349ddb325054662eca23dbe20bd79ac82a4035c398c74dcdbb8aabccc713 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:239827302271764751369301443504619475531 | CVE-2009-2284 phpmyadmin | Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark. | ['CVE-2009-2284'] | ['Debian GNU/Linux 12', 'phpmyadmin'] | ['CVE-2009-2284', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2284'] | {'cves': '["CVE-2009-2284"]', 'title': 'CVE-2009-2284 phpmyadmin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "phpmyadmin"]', 'severity': None, 'references': '["CVE-2009-2284", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2284"]', 'description': 'Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.', 'definition_id': 'oval:org.debian:def:239827302271764751369301443504619475531', 'package_criteria': [{'cve_id': 'CVE-2009-2284', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'phpmyadmin', 'fixed_version': '4:3.2.0.1-1', 'affected_version_range': '< 4:3.2.0.1-1'}]} | bff9136d8f9998f9c2176f46b3fe88e3e25d5eaf5fefdbd4c28d8aed616fa37d | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:157893224846972689246283406945812282558 | CVE-2009-2286 libcompface | Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch. | ['CVE-2009-2286'] | ['Debian GNU/Linux 12', 'libcompface'] | ['CVE-2009-2286', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2286'] | {'cves': '["CVE-2009-2286"]', 'title': 'CVE-2009-2286 libcompface', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libcompface"]', 'severity': None, 'references': '["CVE-2009-2286", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2286"]', 'description': 'Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.', 'definition_id': 'oval:org.debian:def:157893224846972689246283406945812282558', 'package_criteria': [{'cve_id': 'CVE-2009-2286', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libcompface', 'fixed_version': '1:1.5.2-5', 'affected_version_range': '< 1:1.5.2-5'}]} | 7c2573a7cac30aab7417d134470d7e474d03caaf3aa526c5209ad4a296eb0bbf | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:98182656478239180621717792390402833422 | CVE-2009-2294 dillo | Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG image with crafted (1) width or (2) height values. | ['CVE-2009-2294'] | ['Debian GNU/Linux 12', 'dillo'] | ['CVE-2009-2294', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2294'] | {'cves': '["CVE-2009-2294"]', 'title': 'CVE-2009-2294 dillo', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dillo"]', 'severity': None, 'references': '["CVE-2009-2294", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2294"]', 'description': 'Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PNG image with crafted (1) width or (2) height values.', 'definition_id': 'oval:org.debian:def:98182656478239180621717792390402833422', 'package_criteria': [{'cve_id': 'CVE-2009-2294', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dillo', 'fixed_version': '3.0-1', 'affected_version_range': '< 3.0-1'}]} | e5684a21dbbe3cefac083ac4155a5f05b4401892ab0b335021b9a3a10929e920 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:187759103582602074914748461749779543898 | CVE-2009-2295 advi | Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function. | ['CVE-2009-2295'] | ['Debian GNU/Linux 12', 'advi'] | ['CVE-2009-2295', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2295'] | {'cves': '["CVE-2009-2295"]', 'title': 'CVE-2009-2295 advi', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "advi"]', 'severity': None, 'references': '["CVE-2009-2295", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2295"]', 'description': 'Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function.', 'definition_id': 'oval:org.debian:def:187759103582602074914748461749779543898', 'package_criteria': [{'cve_id': 'CVE-2009-2295', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'advi', 'fixed_version': '1.6.0-15', 'affected_version_range': '< 1.6.0-15'}]} | e45cc3c4bc999482781170a32961837588007cc51fc26176259355feca01d045 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:244677945050837520826360936587181700523 | CVE-2009-2335 wordpress | WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience." | ['CVE-2009-2335'] | ['Debian GNU/Linux 12', 'wordpress'] | ['CVE-2009-2335', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2335'] | {'cves': '["CVE-2009-2335"]', 'title': 'CVE-2009-2335 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2335", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2335"]', 'description': 'WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."', 'definition_id': 'oval:org.debian:def:244677945050837520826360936587181700523', 'package_criteria': [{'cve_id': 'CVE-2009-2335', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]} | e8ada103e870890542df0039177c87bfe9f73b336a9f07be8a3cf4c927d7ad98 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:104171003645694939709538853245143659988 | CVE-2009-2336 wordpress | The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience." | ['CVE-2009-2336'] | ['Debian GNU/Linux 12', 'wordpress'] | ['CVE-2009-2336', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2336'] | {'cves': '["CVE-2009-2336"]', 'title': 'CVE-2009-2336 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2336", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2336"]', 'description': 'The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."', 'definition_id': 'oval:org.debian:def:104171003645694939709538853245143659988', 'package_criteria': [{'cve_id': 'CVE-2009-2336', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]} | 0aa6fe6562febe046e93e22a6c45a366fc951f0182df557787c6cbffb554e121 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:140857754136168502997010906789876043069 | CVE-2009-2347 tiff | Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr. | ['CVE-2009-2347'] | ['Debian GNU/Linux 12', 'tiff'] | ['CVE-2009-2347', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347'] | {'cves': '["CVE-2009-2347"]', 'title': 'CVE-2009-2347 tiff', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "tiff"]', 'severity': None, 'references': '["CVE-2009-2347", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347"]', 'description': 'Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.', 'definition_id': 'oval:org.debian:def:140857754136168502997010906789876043069', 'package_criteria': [{'cve_id': 'CVE-2009-2347', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'tiff', 'fixed_version': '3.8.2-13', 'affected_version_range': '< 3.8.2-13'}]} | e3e9f47cc533e321904de173618d255e38e5d9e58d8700da913bb9ef5525b7c7 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:232952009893144092919424046548705335980 | CVE-2009-2404 nss | Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function. | ['CVE-2009-2404'] | ['Debian GNU/Linux 12', 'nss'] | ['CVE-2009-2404', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404'] | {'cves': '["CVE-2009-2404"]', 'title': 'CVE-2009-2404 nss', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "nss"]', 'severity': None, 'references': '["CVE-2009-2404", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404"]', 'description': "Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.", 'definition_id': 'oval:org.debian:def:232952009893144092919424046548705335980', 'package_criteria': [{'cve_id': 'CVE-2009-2404', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nss', 'fixed_version': '3.12.3-1', 'affected_version_range': '< 3.12.3-1'}]} | acf10848f9a18f5a6681c80f4d4d06422d7e72d3a782ec91fcf5e69bf73035e7 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:316168818269827681490263873092700999730 | CVE-2009-2409 nss | The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large. | ['CVE-2009-2409'] | ['Debian GNU/Linux 12', 'nss'] | ['CVE-2009-2409', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409'] | {'cves': '["CVE-2009-2409"]', 'title': 'CVE-2009-2409 nss', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "nss"]', 'severity': None, 'references': '["CVE-2009-2409", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409"]', 'description': 'The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.', 'definition_id': 'oval:org.debian:def:316168818269827681490263873092700999730', 'package_criteria': [{'cve_id': 'CVE-2009-2409', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nss', 'fixed_version': '3.12.3-1', 'affected_version_range': '< 3.12.3-1'}]} | 09968343c3730142eecee2a89683704f09ca8cdb7d25fff390630e87dab83bef | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:324209269217175619711341123243052652156 | CVE-2009-2409 openssl | The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large. | ['CVE-2009-2409'] | ['Debian GNU/Linux 12', 'openssl'] | ['CVE-2009-2409', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409'] | {'cves': '["CVE-2009-2409"]', 'title': 'CVE-2009-2409 openssl', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "openssl"]', 'severity': None, 'references': '["CVE-2009-2409", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409"]', 'description': 'The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.', 'definition_id': 'oval:org.debian:def:324209269217175619711341123243052652156', 'package_criteria': [{'cve_id': 'CVE-2009-2409', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'openssl', 'fixed_version': '0.9.8k-4', 'affected_version_range': '< 0.9.8k-4'}]} | 879d67e623463ad1bfc38b12e96051bf4744e84ebd6042d3ab97f94953892164 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:17939148550999958590457534619884751283 | CVE-2009-2411 subversion | Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412. | ['CVE-2009-2411'] | ['Debian GNU/Linux 12', 'subversion'] | ['CVE-2009-2411', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2411'] | {'cves': '["CVE-2009-2411"]', 'title': 'CVE-2009-2411 subversion', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "subversion"]', 'severity': None, 'references': '["CVE-2009-2411", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2411"]', 'description': 'Multiple integer overflows in the libsvn_delta library in Subversion before 1.5.7, and 1.6.x before 1.6.4, allow remote authenticated users and remote Subversion servers to execute arbitrary code via an svndiff stream with large windows that trigger a heap-based buffer overflow, a related issue to CVE-2009-2412.', 'definition_id': 'oval:org.debian:def:17939148550999958590457534619884751283', 'package_criteria': [{'cve_id': 'CVE-2009-2411', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'subversion', 'fixed_version': '1.6.4dfsg-1', 'affected_version_range': '< 1.6.4dfsg-1'}]} | 2c0cdf999dc2f57071063e2a1a2edd27cedb7ea105f55244f61797a63bd76fea | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:226064912423586615100545849297708038638 | CVE-2009-2412 apr-util | Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information. | ['CVE-2009-2412'] | ['Debian GNU/Linux 12', 'apr-util'] | ['CVE-2009-2412', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412'] | {'cves': '["CVE-2009-2412"]', 'title': 'CVE-2009-2412 apr-util', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apr-util"]', 'severity': None, 'references': '["CVE-2009-2412", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2412"]', 'description': 'Multiple integer overflows in the Apache Portable Runtime (APR) library and the Apache Portable Utility library (aka APR-util) 0.9.x and 1.3.x allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger crafted calls to the (1) allocator_alloc or (2) apr_palloc function in memory/unix/apr_pools.c in APR; or crafted calls to the (3) apr_rmm_malloc, (4) apr_rmm_calloc, or (5) apr_rmm_realloc function in misc/apr_rmm.c in APR-util; leading to buffer overflows. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:226064912423586615100545849297708038638', 'package_criteria': [{'cve_id': 'CVE-2009-2412', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apr-util', 'fixed_version': '1.3.9+dfsg-1', 'affected_version_range': '< 1.3.9+dfsg-1'}]} | 3d5889a68b67176f774ad9cf9114fa5ab77bf280d06439c14ff6ee338e21fc07 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:86020115285173983371273126013393182284 | CVE-2009-2414 libxml2 | Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework. | ['CVE-2009-2414'] | ['Debian GNU/Linux 12', 'libxml2'] | ['CVE-2009-2414', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2414'] | {'cves': '["CVE-2009-2414"]', 'title': 'CVE-2009-2414 libxml2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libxml2"]', 'severity': None, 'references': '["CVE-2009-2414", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2414"]', 'description': 'Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.', 'definition_id': 'oval:org.debian:def:86020115285173983371273126013393182284', 'package_criteria': [{'cve_id': 'CVE-2009-2414', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libxml2', 'fixed_version': '2.7.3.dfsg-2.1', 'affected_version_range': '< 2.7.3.dfsg-2.1'}]} | 7fb6f010f681444f6b5576009141d7b841a7b597dd44b41fb2396e55802d4960 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:231599164768019900502804537880944292693 | CVE-2009-2415 memcached | Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows. | ['CVE-2009-2415'] | ['Debian GNU/Linux 12', 'memcached'] | ['CVE-2009-2415', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2415'] | {'cves': '["CVE-2009-2415"]', 'title': 'CVE-2009-2415 memcached', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "memcached"]', 'severity': None, 'references': '["CVE-2009-2415", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2415"]', 'description': 'Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.', 'definition_id': 'oval:org.debian:def:231599164768019900502804537880944292693', 'package_criteria': [{'cve_id': 'CVE-2009-2415', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'memcached', 'fixed_version': '1.4.1-1', 'affected_version_range': '< 1.4.1-1'}]} | 4503903e479715dbaae3ffbbe49078790282462b8723b0eba88fd936bee1cfcb | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bullseye | oval:org.debian:def:231235182554739574276550960579961929159 | CVE-2022-4603 ppp | A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario. | ['CVE-2022-4603'] | ['Debian GNU/Linux 11', 'ppp'] | ['CVE-2022-4603', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4603'] | {'cves': '["CVE-2022-4603"]', 'title': 'CVE-2022-4603 ppp', 'issued': None, 'release': 'bullseye', 'updated': None, 'affected': '["Debian GNU/Linux 11", "ppp"]', 'severity': None, 'references': '["CVE-2022-4603", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4603"]', 'description': 'A vulnerability classified as problematic has been found in ppp. Affected is the function dumpppp of the file pppdump/pppdump.c of the component pppdump. The manipulation of the argument spkt.buf/rpkt.buf leads to improper validation of array index. The real existence of this vulnerability is still doubted at the moment. The name of the patch is a75fb7b198eed50d769c80c36629f38346882cbf. It is recommended to apply a patch to fix this issue. VDB-216198 is the identifier assigned to this vulnerability. NOTE: pppdump is not used in normal process of setting up a PPP connection, is not installed setuid-root, and is not invoked automatically in any scenario.', 'definition_id': 'oval:org.debian:def:231235182554739574276550960579961929159', 'package_criteria': [{'cve_id': 'CVE-2022-4603', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ppp', 'fixed_version': '0', 'affected_version_range': '< 0'}]} | 89f2461eb744266bd3dcfc8bbbc4056f2d8e43f50badb7a68853edcf5c4a09b8 | 2026-05-30 01:53:37.894761+03:00 | 2026-06-29 20:16:29.792504+03:00 | |||
bookworm | oval:org.debian:def:194089816891249449228379305158527923476 | CVE-2009-2417 curl | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | ['CVE-2009-2417'] | ['Debian GNU/Linux 12', 'curl'] | ['CVE-2009-2417', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417'] | {'cves': '["CVE-2009-2417"]', 'title': 'CVE-2009-2417 curl', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "curl"]', 'severity': None, 'references': '["CVE-2009-2417", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2417"]', 'description': "lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:194089816891249449228379305158527923476', 'package_criteria': [{'cve_id': 'CVE-2009-2417', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'curl', 'fixed_version': '7.19.5-1.1', 'affected_version_range': '< 7.19.5-1.1'}]} | 91217bc0db183a99da8e9e97dc46233f7f0b8538633ff41c0e8adadb036ee0df | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:185275371269894502660822889486400539218 | CVE-2009-2422 rails | The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password. | ['CVE-2009-2422'] | ['Debian GNU/Linux 12', 'rails'] | ['CVE-2009-2422', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2422'] | {'cves': '["CVE-2009-2422"]', 'title': 'CVE-2009-2422 rails', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "rails"]', 'severity': None, 'references': '["CVE-2009-2422", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2422"]', 'description': 'The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.', 'definition_id': 'oval:org.debian:def:185275371269894502660822889486400539218', 'package_criteria': [{'cve_id': 'CVE-2009-2422', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'rails', 'fixed_version': '2.3.5-1', 'affected_version_range': '< 2.3.5-1'}]} | 36e036606e61219533008c68aea072dcf6ff3e78eb6cec927dc944d958c9da34 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:59876714617119638918552221386266020438 | CVE-2009-2426 tor | The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via unknown vectors. NOTE: some of these details are obtained from third party information. | ['CVE-2009-2426'] | ['Debian GNU/Linux 12', 'tor'] | ['CVE-2009-2426', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2426'] | {'cves': '["CVE-2009-2426"]', 'title': 'CVE-2009-2426 tor', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "tor"]', 'severity': None, 'references': '["CVE-2009-2426", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2426"]', 'description': 'The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via unknown vectors. NOTE: some of these details are obtained from third party information.', 'definition_id': 'oval:org.debian:def:59876714617119638918552221386266020438', 'package_criteria': [{'cve_id': 'CVE-2009-2426', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'tor', 'fixed_version': '0.2.0.35-1', 'affected_version_range': '< 0.2.0.35-1'}]} | 74ea594e2ccab7a7dcf343e7b47dbbee3e8c1bb45161e466c8f07a5c75e5cda6 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:146769292755418433207331839713877881403 | CVE-2009-2459 mimetex | Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives. | ['CVE-2009-2459'] | ['Debian GNU/Linux 12', 'mimetex'] | ['CVE-2009-2459', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2459'] | {'cves': '["CVE-2009-2459"]', 'title': 'CVE-2009-2459 mimetex', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "mimetex"]', 'severity': None, 'references': '["CVE-2009-2459", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2459"]', 'description': 'Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \\environ, (2) \\input, and (3) \\counter TeX directives.', 'definition_id': 'oval:org.debian:def:146769292755418433207331839713877881403', 'package_criteria': [{'cve_id': 'CVE-2009-2459', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mimetex', 'fixed_version': '1.50-1.1', 'affected_version_range': '< 1.50-1.1'}]} | 985c27c1f6c9516bcdf3f039c20331c666e220127cb25da3d81590e1e2ebb62b | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:336524861926704887874345735549866745923 | CVE-2009-2461 mathtex | mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors. | ['CVE-2009-2461'] | ['Debian GNU/Linux 12', 'mathtex'] | ['CVE-2009-2461', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2461'] | {'cves': '["CVE-2009-2461"]', 'title': 'CVE-2009-2461 mathtex', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "mathtex"]', 'severity': None, 'references': '["CVE-2009-2461", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2461"]', 'description': 'mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vectors.', 'definition_id': 'oval:org.debian:def:336524861926704887874345735549866745923', 'package_criteria': [{'cve_id': 'CVE-2009-2461', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'mathtex', 'fixed_version': '1.03-1', 'affected_version_range': '< 1.03-1'}]} | 6304519fe1e0e55d8cc3773a88f87f81a1a7da7e9cfa44c6e4abc34eaf759e88 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:102011129042105680010244235469040221409 | CVE-2009-2474 litmus | neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | ['CVE-2009-2474'] | ['Debian GNU/Linux 12', 'litmus'] | ['CVE-2009-2474', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474'] | {'cves': '["CVE-2009-2474"]', 'title': 'CVE-2009-2474 litmus', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "litmus"]', 'severity': None, 'references': '["CVE-2009-2474", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474"]', 'description': "neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:102011129042105680010244235469040221409', 'package_criteria': [{'cve_id': 'CVE-2009-2474', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'litmus', 'fixed_version': '0.13-1', 'affected_version_range': '< 0.13-1'}]} | dadc7999858d3374cfe14af0f6e7a22ada2af88241256f206445bf9bcbc1c85c | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:225027218541019339831494099839634839422 | CVE-2009-2474 neon27 | neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | ['CVE-2009-2474'] | ['Debian GNU/Linux 12', 'neon27'] | ['CVE-2009-2474', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474'] | {'cves': '["CVE-2009-2474"]', 'title': 'CVE-2009-2474 neon27', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "neon27"]', 'severity': None, 'references': '["CVE-2009-2474", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2474"]', 'description': "neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:225027218541019339831494099839634839422', 'package_criteria': [{'cve_id': 'CVE-2009-2474', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'neon27', 'fixed_version': '0.28.6-1', 'affected_version_range': '< 0.28.6-1'}]} | 0ab0ca867c961e95c7e80474169f6e23a189e28673c445c9fdc4138c6541d40f | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:240704110048227942481293648559315319161 | CVE-2009-2562 wireshark | Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. | ['CVE-2009-2562'] | ['Debian GNU/Linux 12', 'wireshark'] | ['CVE-2009-2562', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562'] | {'cves': '["CVE-2009-2562"]', 'title': 'CVE-2009-2562 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-2562", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2562"]', 'description': 'Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.', 'definition_id': 'oval:org.debian:def:240704110048227942481293648559315319161', 'package_criteria': [{'cve_id': 'CVE-2009-2562', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.2.1-1', 'affected_version_range': '< 1.2.1-1'}]} | cc3dd97494d7cd794beae68cbfc3b38e64a3fe83e75b609b6161ce134b35c640 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:283220103337291650176916273827037548443 | CVE-2009-2563 wireshark | Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors. | ['CVE-2009-2563'] | ['Debian GNU/Linux 12', 'wireshark'] | ['CVE-2009-2563', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563'] | {'cves': '["CVE-2009-2563"]', 'title': 'CVE-2009-2563 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-2563", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2563"]', 'description': 'Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.', 'definition_id': 'oval:org.debian:def:283220103337291650176916273827037548443', 'package_criteria': [{'cve_id': 'CVE-2009-2563', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.2.1-1', 'affected_version_range': '< 1.2.1-1'}]} | 7223abc6c9f9e35d6e33dc6e0fc0eb80b45b9f5f33baa726fbf1a022f256e0e4 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:41328305736141197989028808185452163488 | CVE-2009-2624 gzip | The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression. | ['CVE-2009-2624'] | ['Debian GNU/Linux 12', 'gzip'] | ['CVE-2009-2624', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624'] | {'cves': '["CVE-2009-2624"]', 'title': 'CVE-2009-2624 gzip', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "gzip"]', 'severity': None, 'references': '["CVE-2009-2624", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2624"]', 'description': 'The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.', 'definition_id': 'oval:org.debian:def:41328305736141197989028808185452163488', 'package_criteria': [{'cve_id': 'CVE-2009-2624', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'gzip', 'fixed_version': '1.3.12-8', 'affected_version_range': '< 1.3.12-8'}]} | 34431a8709530524fe67459bcbab014ccbf54003cf993804d66c94c23993f1a3 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:304493765716272084089962096719797339379 | CVE-2009-2625 libxerces2-java | XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework. | ['CVE-2009-2625'] | ['Debian GNU/Linux 12', 'libxerces2-java'] | ['CVE-2009-2625', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625'] | {'cves': '["CVE-2009-2625"]', 'title': 'CVE-2009-2625 libxerces2-java', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libxerces2-java"]', 'severity': None, 'references': '["CVE-2009-2625", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625"]', 'description': 'XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.', 'definition_id': 'oval:org.debian:def:304493765716272084089962096719797339379', 'package_criteria': [{'cve_id': 'CVE-2009-2625', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libxerces2-java', 'fixed_version': '2.9.1-4.1', 'affected_version_range': '< 2.9.1-4.1'}]} | 9fb1501052d140c93c47ce4add3810b41e0170f94643e1bd849a5c6819dbd786 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:277102502336591933830975325946454144364 | CVE-2009-2629 nginx | Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests. | ['CVE-2009-2629'] | ['Debian GNU/Linux 12', 'nginx'] | ['CVE-2009-2629', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2629'] | {'cves': '["CVE-2009-2629"]', 'title': 'CVE-2009-2629 nginx', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "nginx"]', 'severity': None, 'references': '["CVE-2009-2629", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2629"]', 'description': 'Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.', 'definition_id': 'oval:org.debian:def:277102502336591933830975325946454144364', 'package_criteria': [{'cve_id': 'CVE-2009-2629', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'nginx', 'fixed_version': '0.7.61-3', 'affected_version_range': '< 0.7.61-3'}]} | 943b238116c68dee02d765738d051317b4272d6d423cdb217ac1c6246e899382 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:231157586657320490967033978313572536385 | CVE-2009-2632 dovecot | Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error. | ['CVE-2009-2632'] | ['Debian GNU/Linux 12', 'dovecot'] | ['CVE-2009-2632', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632'] | {'cves': '["CVE-2009-2632"]', 'title': 'CVE-2009-2632 dovecot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dovecot"]', 'severity': None, 'references': '["CVE-2009-2632", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632"]', 'description': 'Buffer overflow in the SIEVE script component (sieve/script.c), as used in cyrus-imapd in Cyrus IMAP Server 2.2.13 and 2.3.14, and Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, allows local users to execute arbitrary code and read or modify arbitrary messages via a crafted SIEVE script, related to the incorrect use of the sizeof operator for determining buffer length, combined with an integer signedness error.', 'definition_id': 'oval:org.debian:def:231157586657320490967033978313572536385', 'package_criteria': [{'cve_id': 'CVE-2009-2632', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dovecot', 'fixed_version': '1:1.2.1-1', 'affected_version_range': '< 1:1.2.1-1'}]} | 5b3ce2dbee362aebd981dac512ea1b270e2924e053a228ccb5ca2c5905b69868 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:216907791962626840608289799204968505530 | CVE-2009-2658 znc | Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request. | ['CVE-2009-2658'] | ['Debian GNU/Linux 12', 'znc'] | ['CVE-2009-2658', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2658'] | {'cves': '["CVE-2009-2658"]', 'title': 'CVE-2009-2658 znc', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "znc"]', 'severity': None, 'references': '["CVE-2009-2658", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2658"]', 'description': 'Directory traversal vulnerability in ZNC before 0.072 allows remote attackers to overwrite arbitrary files via a crafted DCC SEND request.', 'definition_id': 'oval:org.debian:def:216907791962626840608289799204968505530', 'package_criteria': [{'cve_id': 'CVE-2009-2658', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'znc', 'fixed_version': '0.074-1', 'affected_version_range': '< 0.074-1'}]} | 8d31afcac6c8908755380bb88e611418016a6a49c2643850cb0a8313cdbd2849 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:218786097106123476278237714855994691260 | CVE-2009-2659 python-django | The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL. | ['CVE-2009-2659'] | ['Debian GNU/Linux 12', 'python-django'] | ['CVE-2009-2659', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2659'] | {'cves': '["CVE-2009-2659"]', 'title': 'CVE-2009-2659 python-django', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "python-django"]', 'severity': None, 'references': '["CVE-2009-2659", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2659"]', 'description': 'The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL.', 'definition_id': 'oval:org.debian:def:218786097106123476278237714855994691260', 'package_criteria': [{'cve_id': 'CVE-2009-2659', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'python-django', 'fixed_version': '1.1-1', 'affected_version_range': '< 1.1-1'}]} | 06980ce84ee26056ec156a4279bb59c37f5f16a40bc08e3f892887a61096a5be | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:286718974016234650223056106963057880087 | CVE-2009-2660 advi | Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295. | ['CVE-2009-2660'] | ['Debian GNU/Linux 12', 'advi'] | ['CVE-2009-2660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660'] | {'cves': '["CVE-2009-2660"]', 'title': 'CVE-2009-2660 advi', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "advi"]', 'severity': None, 'references': '["CVE-2009-2660", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660"]', 'description': 'Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295.', 'definition_id': 'oval:org.debian:def:286718974016234650223056106963057880087', 'package_criteria': [{'cve_id': 'CVE-2009-2660', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'advi', 'fixed_version': '1.6.0-15', 'affected_version_range': '< 1.6.0-15'}]} | a00c1fc26ab0ccaba579173a1d98483b71498269f9fef4152e79ded41528c4a9 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:76624963214604227755632122478489228687 | CVE-2009-2660 camlimages | Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295. | ['CVE-2009-2660'] | ['Debian GNU/Linux 12', 'camlimages'] | ['CVE-2009-2660', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660'] | {'cves': '["CVE-2009-2660"]', 'title': 'CVE-2009-2660 camlimages', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "camlimages"]', 'severity': None, 'references': '["CVE-2009-2660", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2660"]', 'description': 'Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability than CVE-2009-2295.', 'definition_id': 'oval:org.debian:def:76624963214604227755632122478489228687', 'package_criteria': [{'cve_id': 'CVE-2009-2660', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'camlimages', 'fixed_version': '1:3.0.1-3', 'affected_version_range': '< 1:3.0.1-3'}]} | e894dc97698047d99608c4b4c8a6880f04af1f945db3c9766efc439b3ff9a093 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:126952981833205689869088225157955580367 | CVE-2009-2661 strongswan | The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185. | ['CVE-2009-2661'] | ['Debian GNU/Linux 12', 'strongswan'] | ['CVE-2009-2661', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2661'] | {'cves': '["CVE-2009-2661"]', 'title': 'CVE-2009-2661 strongswan', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "strongswan"]', 'severity': None, 'references': '["CVE-2009-2661", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2661"]', 'description': 'The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185.', 'definition_id': 'oval:org.debian:def:126952981833205689869088225157955580367', 'package_criteria': [{'cve_id': 'CVE-2009-2661', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'strongswan', 'fixed_version': '4.3.2-1.1', 'affected_version_range': '< 4.3.2-1.1'}]} | 054cbb45251ef7a7e2a176dadcf7dc1177fbb0aee9e1ee4f89cb40a81d09bef7 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:314577991129111053764120338789693133316 | CVE-2009-2663 libvorbis | libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file. | ['CVE-2009-2663'] | ['Debian GNU/Linux 12', 'libvorbis'] | ['CVE-2009-2663', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663'] | {'cves': '["CVE-2009-2663"]', 'title': 'CVE-2009-2663 libvorbis', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libvorbis"]', 'severity': None, 'references': '["CVE-2009-2663", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663"]', 'description': 'libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.', 'definition_id': 'oval:org.debian:def:314577991129111053764120338789693133316', 'package_criteria': [{'cve_id': 'CVE-2009-2663', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libvorbis', 'fixed_version': '1.2.0.dfsg-6', 'affected_version_range': '< 1.2.0.dfsg-6'}]} | 3e5816b2ffe0ef0dc09884007d5cc9d26dcff8c069e4ad068121138cc57062d4 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:290700755601125393283248055333125902215 | CVE-2009-2663 libvorbisidec | libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file. | ['CVE-2009-2663'] | ['Debian GNU/Linux 12', 'libvorbisidec'] | ['CVE-2009-2663', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663'] | {'cves': '["CVE-2009-2663"]', 'title': 'CVE-2009-2663 libvorbisidec', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "libvorbisidec"]', 'severity': None, 'references': '["CVE-2009-2663", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2663"]', 'description': 'libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.', 'definition_id': 'oval:org.debian:def:290700755601125393283248055333125902215', 'package_criteria': [{'cve_id': 'CVE-2009-2663', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'libvorbisidec', 'fixed_version': '1.0.2+svn16259-2', 'affected_version_range': '< 1.0.2+svn16259-2'}]} | ac411ee2bbb76e1cacd7d7141a56d661a1479cf426ae3555d75d3aa4b674a525 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:159079345828843489762978237414856274919 | CVE-2009-2666 fetchmail | socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408. | ['CVE-2009-2666'] | ['Debian GNU/Linux 12', 'fetchmail'] | ['CVE-2009-2666', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666'] | {'cves': '["CVE-2009-2666"]', 'title': 'CVE-2009-2666 fetchmail', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "fetchmail"]', 'severity': None, 'references': '["CVE-2009-2666", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2666"]', 'description': "socket.c in fetchmail before 6.3.11 does not properly handle a '\\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.", 'definition_id': 'oval:org.debian:def:159079345828843489762978237414856274919', 'package_criteria': [{'cve_id': 'CVE-2009-2666', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'fetchmail', 'fixed_version': '6.3.9~rc2-6', 'affected_version_range': '< 6.3.9~rc2-6'}]} | 1e6b110dba3edf17197bb51ddcdffe0c68b16d5ecd80c10ef25b857c6b5eea50 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:33617155369063178019811165922385047453 | CVE-2009-2694 pidgin | The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376. | ['CVE-2009-2694'] | ['Debian GNU/Linux 12', 'pidgin'] | ['CVE-2009-2694', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694'] | {'cves': '["CVE-2009-2694"]', 'title': 'CVE-2009-2694 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-2694", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694"]', 'description': 'The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.', 'definition_id': 'oval:org.debian:def:33617155369063178019811165922385047453', 'package_criteria': [{'cve_id': 'CVE-2009-2694', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.5.9-1', 'affected_version_range': '< 2.5.9-1'}]} | 797bf03900c47243b67697e27bf29afadc7add4e429bd5fbc9f35f039ff15039 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:4517515358224261332998392134916091154 | CVE-2009-2703 pidgin | libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string. | ['CVE-2009-2703'] | ['Debian GNU/Linux 12', 'pidgin'] | ['CVE-2009-2703', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703'] | {'cves': '["CVE-2009-2703"]', 'title': 'CVE-2009-2703 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-2703", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2703"]', 'description': 'libpurple/protocols/irc/msgs.c in the IRC protocol plugin in libpurple in Pidgin before 2.6.2 allows remote IRC servers to cause a denial of service (NULL pointer dereference and application crash) via a TOPIC message that lacks a topic string.', 'definition_id': 'oval:org.debian:def:4517515358224261332998392134916091154', 'package_criteria': [{'cve_id': 'CVE-2009-2703', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.6.2', 'affected_version_range': '< 2.6.2'}]} | f9e328638a1fae67d10d5e5ac4a651c354c2a1786f011376d506dcdd996c2a74 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:80778328249479244916138485035650801334 | CVE-2009-2851 wordpress | Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL. | ['CVE-2009-2851'] | ['Debian GNU/Linux 12', 'wordpress'] | ['CVE-2009-2851', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2851'] | {'cves': '["CVE-2009-2851"]', 'title': 'CVE-2009-2851 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2851", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2851"]', 'description': 'Cross-site scripting (XSS) vulnerability in the administrator interface in WordPress before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via a comment author URL.', 'definition_id': 'oval:org.debian:def:80778328249479244916138485035650801334', 'package_criteria': [{'cve_id': 'CVE-2009-2851', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]} | cd8f959be935faca36eea5cc3c7a4c48a7c6f9a4a8b2ae53b7d8a38fde00c800 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:72497765616078278346608473666821123983 | CVE-2009-2853 wordpress | Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/. | ['CVE-2009-2853'] | ['Debian GNU/Linux 12', 'wordpress'] | ['CVE-2009-2853', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2853'] | {'cves': '["CVE-2009-2853"]', 'title': 'CVE-2009-2853 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2853", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2853"]', 'description': 'Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.', 'definition_id': 'oval:org.debian:def:72497765616078278346608473666821123983', 'package_criteria': [{'cve_id': 'CVE-2009-2853', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]} | b442f72c858ea77d9134002af1a9a2ac8db0b8ec0da52fbd1749950792becd60 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:19940761191618801220961806669100976483 | CVE-2009-2854 wordpress | Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/. | ['CVE-2009-2854'] | ['Debian GNU/Linux 12', 'wordpress'] | ['CVE-2009-2854', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2854'] | {'cves': '["CVE-2009-2854"]', 'title': 'CVE-2009-2854 wordpress', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wordpress"]', 'severity': None, 'references': '["CVE-2009-2854", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2854"]', 'description': 'Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.', 'definition_id': 'oval:org.debian:def:19940761191618801220961806669100976483', 'package_criteria': [{'cve_id': 'CVE-2009-2854', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wordpress', 'fixed_version': '2.8.3-1', 'affected_version_range': '< 2.8.3-1'}]} | 7492567b63a9ba8a6bac0153154784fb30146478331724b02a52d91c84327996 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:188327652087283964038656090741838794100 | CVE-2009-2855 squid | The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function. | ['CVE-2009-2855'] | ['Debian GNU/Linux 12', 'squid'] | ['CVE-2009-2855', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2855'] | {'cves': '["CVE-2009-2855"]', 'title': 'CVE-2009-2855 squid', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "squid"]', 'severity': None, 'references': '["CVE-2009-2855", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2855"]', 'description': 'The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.', 'definition_id': 'oval:org.debian:def:188327652087283964038656090741838794100', 'package_criteria': [{'cve_id': 'CVE-2009-2855', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'squid', 'fixed_version': '2.7.STABLE7-1', 'affected_version_range': '< 2.7.STABLE7-1'}]} | b684bc9b2094111e207e34f23e4e1167c0fd999708d53499c59a87118f01ee71 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:243908649608121707952372316464563536635 | CVE-2009-2905 newt | Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box. | ['CVE-2009-2905'] | ['Debian GNU/Linux 12', 'newt'] | ['CVE-2009-2905', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905'] | {'cves': '["CVE-2009-2905"]', 'title': 'CVE-2009-2905 newt', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "newt"]', 'severity': None, 'references': '["CVE-2009-2905", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905"]', 'description': 'Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.', 'definition_id': 'oval:org.debian:def:243908649608121707952372316464563536635', 'package_criteria': [{'cve_id': 'CVE-2009-2905', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'newt', 'fixed_version': '0.52.10-4.1', 'affected_version_range': '< 0.52.10-4.1'}]} | 73ae2991f0a5173042a57e4eaf26be0a404646f80f03878792cc9c8f5e0bf337 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:104312876745457387559221790184179861226 | CVE-2009-2906 samba | smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet. | ['CVE-2009-2906'] | ['Debian GNU/Linux 12', 'samba'] | ['CVE-2009-2906', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906'] | {'cves': '["CVE-2009-2906"]', 'title': 'CVE-2009-2906 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-2906", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2906"]', 'description': 'smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.', 'definition_id': 'oval:org.debian:def:104312876745457387559221790184179861226', 'package_criteria': [{'cve_id': 'CVE-2009-2906', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.4.2-1', 'affected_version_range': '< 2:3.4.2-1'}]} | a03e37b2ce43e7c109c38db2d4807dd99eb498183d984a4203c7d4a3dcb15630 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:152285594152827863579352045013097430925 | CVE-2009-2911 systemtap | SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records. | ['CVE-2009-2911'] | ['Debian GNU/Linux 12', 'systemtap'] | ['CVE-2009-2911', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2911'] | {'cves': '["CVE-2009-2911"]', 'title': 'CVE-2009-2911 systemtap', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "systemtap"]', 'severity': None, 'references': '["CVE-2009-2911", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2911"]', 'description': 'SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local users to (1) cause a denial of service or gain privileges via a print operation with a large number of arguments that trigger a kernel stack overflow, (2) cause a denial of service via crafted DWARF expressions that trigger a kernel stack frame overflow, or (3) cause a denial of service (infinite loop) via vectors that trigger creation of large unwind tables, related to Common Information Entry (CIE) and Call Frame Instruction (CFI) records.', 'definition_id': 'oval:org.debian:def:152285594152827863579352045013097430925', 'package_criteria': [{'cve_id': 'CVE-2009-2911', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'systemtap', 'fixed_version': '1.0-2', 'affected_version_range': '< 1.0-2'}]} | b06c44b663c3ab9ec24288ae4e595e657ff31323e57917991618c042cb5f60b3 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:279821878024924764092435830953652341508 | CVE-2009-2936 varnish | The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless. | ['CVE-2009-2936'] | ['Debian GNU/Linux 12', 'varnish'] | ['CVE-2009-2936', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2936'] | {'cves': '["CVE-2009-2936"]', 'title': 'CVE-2009-2936 varnish', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "varnish"]', 'severity': None, 'references': '["CVE-2009-2936", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2936"]', 'description': 'The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim\'s location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.', 'definition_id': 'oval:org.debian:def:279821878024924764092435830953652341508', 'package_criteria': [{'cve_id': 'CVE-2009-2936', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'varnish', 'fixed_version': '2.1.0-2', 'affected_version_range': '< 2.1.0-2'}]} | 82ea2114b84ced0d318821b7590d1dda578c00c1d049e2373400080b78ea5d01 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:261788049974532640050045893387170507569 | CVE-2009-2939 postfix | The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files. | ['CVE-2009-2939'] | ['Debian GNU/Linux 12', 'postfix'] | ['CVE-2009-2939', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2939'] | {'cves': '["CVE-2009-2939"]', 'title': 'CVE-2009-2939 postfix', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "postfix"]', 'severity': None, 'references': '["CVE-2009-2939", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2939"]', 'description': 'The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.', 'definition_id': 'oval:org.debian:def:261788049974532640050045893387170507569', 'package_criteria': [{'cve_id': 'CVE-2009-2939', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'postfix', 'fixed_version': '2.6.5-3', 'affected_version_range': '< 2.6.5-3'}]} | ddc2da9a43f443c076ecb39e4345511e5c8c5d6d12b973a7ebda9b18b9d30f81 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:187138185985693500662038613448769494658 | CVE-2009-2944 ikiwiki | Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands. | ['CVE-2009-2944'] | ['Debian GNU/Linux 12', 'ikiwiki'] | ['CVE-2009-2944', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2944'] | {'cves': '["CVE-2009-2944"]', 'title': 'CVE-2009-2944 ikiwiki', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ikiwiki"]', 'severity': None, 'references': '["CVE-2009-2944", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2944"]', 'description': 'Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.', 'definition_id': 'oval:org.debian:def:187138185985693500662038613448769494658', 'package_criteria': [{'cve_id': 'CVE-2009-2944', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ikiwiki', 'fixed_version': '3.1415926', 'affected_version_range': '< 3.1415926'}]} | 8f631c4255e94252e2e358d2f71dd6ebb366e3785465af702d5cdb4a89d3f86f | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:13123199226128086658774104856942357902 | CVE-2009-2946 devscripts | Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages. | ['CVE-2009-2946'] | ['Debian GNU/Linux 12', 'devscripts'] | ['CVE-2009-2946', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2946'] | {'cves': '["CVE-2009-2946"]', 'title': 'CVE-2009-2946 devscripts', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "devscripts"]', 'severity': None, 'references': '["CVE-2009-2946", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2946"]', 'description': 'Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.', 'definition_id': 'oval:org.debian:def:13123199226128086658774104856942357902', 'package_criteria': [{'cve_id': 'CVE-2009-2946', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'devscripts', 'fixed_version': '2.10.54', 'affected_version_range': '< 2.10.54'}]} | 883e5dad6b689a452f66850b15c895cbd970ad3aca5703d08c71115f21888366 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:229408503795291312278205516393010876674 | CVE-2009-2947 xapian-omega | Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages. | ['CVE-2009-2947'] | ['Debian GNU/Linux 12', 'xapian-omega'] | ['CVE-2009-2947', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2947'] | {'cves': '["CVE-2009-2947"]', 'title': 'CVE-2009-2947 xapian-omega', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "xapian-omega"]', 'severity': None, 'references': '["CVE-2009-2947", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2947"]', 'description': 'Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.', 'definition_id': 'oval:org.debian:def:229408503795291312278205516393010876674', 'package_criteria': [{'cve_id': 'CVE-2009-2947', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'xapian-omega', 'fixed_version': '1.0.15-2', 'affected_version_range': '< 1.0.15-2'}]} | 2193a9c491d1baa63a613f15c688a0efcaa7cf531409ccdc929fba143fb120b3 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:157642303863690289932742794357916730179 | CVE-2009-2948 samba | mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option. | ['CVE-2009-2948'] | ['Debian GNU/Linux 12', 'samba'] | ['CVE-2009-2948', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948'] | {'cves': '["CVE-2009-2948"]', 'title': 'CVE-2009-2948 samba', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "samba"]', 'severity': None, 'references': '["CVE-2009-2948", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2948"]', 'description': 'mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.', 'definition_id': 'oval:org.debian:def:157642303863690289932742794357916730179', 'package_criteria': [{'cve_id': 'CVE-2009-2948', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'samba', 'fixed_version': '2:3.4.2-1', 'affected_version_range': '< 2:3.4.2-1'}]} | 6801b7f13658e04fec1de0c8e8e50bf7ba3e73ccefcfef4a8bec4928216b292e | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:246004658159848010907889957897248462659 | CVE-2009-2957 dnsmasq | Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request. | ['CVE-2009-2957'] | ['Debian GNU/Linux 12', 'dnsmasq'] | ['CVE-2009-2957', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957'] | {'cves': '["CVE-2009-2957"]', 'title': 'CVE-2009-2957 dnsmasq', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dnsmasq"]', 'severity': None, 'references': '["CVE-2009-2957", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2957"]', 'description': 'Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.', 'definition_id': 'oval:org.debian:def:246004658159848010907889957897248462659', 'package_criteria': [{'cve_id': 'CVE-2009-2957', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dnsmasq', 'fixed_version': '2.50-1', 'affected_version_range': '< 2.50-1'}]} | 8507969b2fef3b4041a83778e07e5e6c661da5043ae8c1b6f457691213d0350a | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:322154306840957602060035497182225960775 | CVE-2009-2958 dnsmasq | The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option. | ['CVE-2009-2958'] | ['Debian GNU/Linux 12', 'dnsmasq'] | ['CVE-2009-2958', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958'] | {'cves': '["CVE-2009-2958"]', 'title': 'CVE-2009-2958 dnsmasq', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dnsmasq"]', 'severity': None, 'references': '["CVE-2009-2958", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2958"]', 'description': 'The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.', 'definition_id': 'oval:org.debian:def:322154306840957602060035497182225960775', 'package_criteria': [{'cve_id': 'CVE-2009-2958', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dnsmasq', 'fixed_version': '2.50-1', 'affected_version_range': '< 2.50-1'}]} | 0ddad68288f93f4550e0dce0e5fc284fc83e5fd6a9f84a7f81e2610765340df9 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:90350963512456067148803715029076812480 | CVE-2009-2959 buildbot | Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | ['CVE-2009-2959'] | ['Debian GNU/Linux 12', 'buildbot'] | ['CVE-2009-2959', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2959'] | {'cves': '["CVE-2009-2959"]', 'title': 'CVE-2009-2959 buildbot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "buildbot"]', 'severity': None, 'references': '["CVE-2009-2959", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2959"]', 'description': 'Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.', 'definition_id': 'oval:org.debian:def:90350963512456067148803715029076812480', 'package_criteria': [{'cve_id': 'CVE-2009-2959', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'buildbot', 'fixed_version': '0.7.11p3-1', 'affected_version_range': '< 0.7.11p3-1'}]} | 18e051b1102a0ab39f05b07d538b7ae79f5f37f50d5618d6e58e884451879db1 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:151642752892950092571932649988614183750 | CVE-2009-2967 buildbot | Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959. | ['CVE-2009-2967'] | ['Debian GNU/Linux 12', 'buildbot'] | ['CVE-2009-2967', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2967'] | {'cves': '["CVE-2009-2967"]', 'title': 'CVE-2009-2967 buildbot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "buildbot"]', 'severity': None, 'references': '["CVE-2009-2967", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2967"]', 'description': 'Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959.', 'definition_id': 'oval:org.debian:def:151642752892950092571932649988614183750', 'package_criteria': [{'cve_id': 'CVE-2009-2967', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'buildbot', 'fixed_version': '0.7.11p3-1', 'affected_version_range': '< 0.7.11p3-1'}]} | e889b81cd1c5cfd00abec9ea305467a05294532e6dd08ccf07137695b84e18de | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:163860546688502455000666444520542426149 | CVE-2009-3026 pidgin | protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions. | ['CVE-2009-3026'] | ['Debian GNU/Linux 12', 'pidgin'] | ['CVE-2009-3026', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026'] | {'cves': '["CVE-2009-3026"]', 'title': 'CVE-2009-3026 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-3026", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3026"]', 'description': 'protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.', 'definition_id': 'oval:org.debian:def:163860546688502455000666444520542426149', 'package_criteria': [{'cve_id': 'CVE-2009-3026', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.6.1-1', 'affected_version_range': '< 2.6.1-1'}]} | a78c86be0fbca73bbc5186e5aec38d8ddd41ac41771ba7446c04a0f63f6ed408 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:183700420581963993296964300988610936628 | CVE-2006-4253 thunderbird | Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected. | ['CVE-2006-4253'] | ['Debian GNU/Linux 12', 'thunderbird'] | ['CVE-2006-4253', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253'] | {'cves': '["CVE-2006-4253"]', 'title': 'CVE-2006-4253 thunderbird', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "thunderbird"]', 'severity': None, 'references': '["CVE-2006-4253", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4253"]', 'description': 'Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.', 'definition_id': 'oval:org.debian:def:183700420581963993296964300988610936628', 'package_criteria': [{'cve_id': 'CVE-2006-4253', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thunderbird', 'fixed_version': '1.5.0.7-1', 'affected_version_range': '< 1.5.0.7-1'}]} | a38c25104a4fc074196ad9e669813f7d695f289f389d990e8140239da12602f1 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:91064102204529443242478808786574481467 | CVE-2009-3040 ocsinventory-server | Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php. | ['CVE-2009-3040'] | ['Debian GNU/Linux 12', 'ocsinventory-server'] | ['CVE-2009-3040', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3040'] | {'cves': '["CVE-2009-3040"]', 'title': 'CVE-2009-3040 ocsinventory-server', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ocsinventory-server"]', 'severity': None, 'references': '["CVE-2009-3040", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3040"]', 'description': 'Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.', 'definition_id': 'oval:org.debian:def:91064102204529443242478808786574481467', 'package_criteria': [{'cve_id': 'CVE-2009-3040', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ocsinventory-server', 'fixed_version': '1.02.1-2', 'affected_version_range': '< 1.02.1-2'}]} | a3ce064100b95eccab93936dd7744c17c08cf5b091e2525cdfe5aa8a6167bdbe | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:202945604118434733963780146067626061122 | CVE-2009-3042 ocsinventory-server | SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040. | ['CVE-2009-3042'] | ['Debian GNU/Linux 12', 'ocsinventory-server'] | ['CVE-2009-3042', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3042'] | {'cves': '["CVE-2009-3042"]', 'title': 'CVE-2009-3042 ocsinventory-server', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "ocsinventory-server"]', 'severity': None, 'references': '["CVE-2009-3042", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3042"]', 'description': 'SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.', 'definition_id': 'oval:org.debian:def:202945604118434733963780146067626061122', 'package_criteria': [{'cve_id': 'CVE-2009-3042', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'ocsinventory-server', 'fixed_version': '1.02.1-2', 'affected_version_range': '< 1.02.1-2'}]} | 758ecc56f78f4b1827585582dd844390df4e295c7a9e889b22a113d05c94510b | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:165218588439385472658637393191257493039 | CVE-2009-3050 htmldoc | Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries. | ['CVE-2009-3050'] | ['Debian GNU/Linux 12', 'htmldoc'] | ['CVE-2009-3050', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3050'] | {'cves': '["CVE-2009-3050"]', 'title': 'CVE-2009-3050 htmldoc', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "htmldoc"]', 'severity': None, 'references': '["CVE-2009-3050", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3050"]', 'description': 'Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.cxx and ps-pdf.cxx using an AFM font file with a long glyph name, but these vectors do not cross privilege boundaries.', 'definition_id': 'oval:org.debian:def:165218588439385472658637393191257493039', 'package_criteria': [{'cve_id': 'CVE-2009-3050', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'htmldoc', 'fixed_version': '1.8.27-4.1', 'affected_version_range': '< 1.8.27-4.1'}]} | a0b13d505adbae6feae3bbb8031cae7808b3aebb9f09648c1f5f88225f86f6f0 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
wheezy | oval:org.debian:def:207871247964001913596224375064462787946 | DSA-3409-1 putty | security update | ['CVE-2015-5309'] | ['Debian GNU/Linux 7', 'putty'] | ['CVE-2015-5309', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5309'] | {'cves': '["CVE-2015-5309"]', 'title': 'DSA-3409-1 putty', 'issued': None, 'release': 'wheezy', 'updated': None, 'affected': '["Debian GNU/Linux 7", "putty"]', 'severity': None, 'references': '["CVE-2015-5309", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5309"]', 'description': 'security update', 'definition_id': 'oval:org.debian:def:207871247964001913596224375064462787946', 'package_criteria': [{'cve_id': 'CVE-2015-5309', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'putty', 'fixed_version': '0.62-9+deb7u3', 'affected_version_range': '< 0.62-9+deb7u3'}]} | a25cc4ee5955858402f5d9aa78e8c9ec9b066b9c49ef64ba650027363556ec39 | 2026-05-30 01:54:19.138681+03:00 | 2026-06-29 20:17:43.385302+03:00 | |||
bookworm | oval:org.debian:def:285206647540308228391116875222403724034 | CVE-2009-3083 pidgin | The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client. | ['CVE-2009-3083'] | ['Debian GNU/Linux 12', 'pidgin'] | ['CVE-2009-3083', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083'] | {'cves': '["CVE-2009-3083"]', 'title': 'CVE-2009-3083 pidgin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "pidgin"]', 'severity': None, 'references': '["CVE-2009-3083", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3083"]', 'description': 'The msn_slp_sip_recv function in libpurple/protocols/msn/slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an SLP invite message that lacks certain required fields, as demonstrated by a malformed message from a KMess client.', 'definition_id': 'oval:org.debian:def:285206647540308228391116875222403724034', 'package_criteria': [{'cve_id': 'CVE-2009-3083', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'pidgin', 'fixed_version': '2.6.2-1', 'affected_version_range': '< 2.6.2-1'}]} | 6bfebd0f7f79fad2c319a100405575bc8cf9dbe42d2288c121ae5eff000668c9 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:101370027722286993380737289847070643415 | CVE-2009-3086 rails | A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts. | ['CVE-2009-3086'] | ['Debian GNU/Linux 12', 'rails'] | ['CVE-2009-3086', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3086'] | {'cves': '["CVE-2009-3086"]', 'title': 'CVE-2009-3086 rails', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "rails"]', 'severity': None, 'references': '["CVE-2009-3086", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3086"]', 'description': 'A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.', 'definition_id': 'oval:org.debian:def:101370027722286993380737289847070643415', 'package_criteria': [{'cve_id': 'CVE-2009-3086', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'rails', 'fixed_version': '2.2.3-1', 'affected_version_range': '< 2.2.3-1'}]} | 005da560e80c4d12a910a743fc472c131259cbfb99f3634d92bd58e1cdd76693 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:150432487751440637607487750848230183835 | CVE-2009-3095 apache2 | The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. | ['CVE-2009-3095'] | ['Debian GNU/Linux 12', 'apache2'] | ['CVE-2009-3095', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095'] | {'cves': '["CVE-2009-3095"]', 'title': 'CVE-2009-3095 apache2', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "apache2"]', 'severity': None, 'references': '["CVE-2009-3095", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095"]', 'description': 'The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.', 'definition_id': 'oval:org.debian:def:150432487751440637607487750848230183835', 'package_criteria': [{'cve_id': 'CVE-2009-3095', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'apache2', 'fixed_version': '2.2.13-2', 'affected_version_range': '< 2.2.13-2'}]} | 285dc06d74e15e9cf77603d71ec4dedd6fac1801be80cb0ef727a0140c4286c4 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:337820251647819538673752925642307060309 | CVE-2009-3111 freeradius | The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967. | ['CVE-2009-3111'] | ['Debian GNU/Linux 12', 'freeradius'] | ['CVE-2009-3111', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3111'] | {'cves': '["CVE-2009-3111"]', 'title': 'CVE-2009-3111 freeradius', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "freeradius"]', 'severity': None, 'references': '["CVE-2009-3111", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3111"]', 'description': 'The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.', 'definition_id': 'oval:org.debian:def:337820251647819538673752925642307060309', 'package_criteria': [{'cve_id': 'CVE-2009-3111', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'freeradius', 'fixed_version': '2.0.0-1', 'affected_version_range': '< 2.0.0-1'}]} | 7fa5a3399f3d6232358b15a040c7d6ef8181c8794513515fff9c7c64dbfc3d2a | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:77519067271661085615908637117142463896 | CVE-2009-3233 changetrack | changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack. | ['CVE-2009-3233'] | ['Debian GNU/Linux 12', 'changetrack'] | ['CVE-2009-3233', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3233'] | {'cves': '["CVE-2009-3233"]', 'title': 'CVE-2009-3233 changetrack', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "changetrack"]', 'severity': None, 'references': '["CVE-2009-3233", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3233"]', 'description': 'changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.', 'definition_id': 'oval:org.debian:def:77519067271661085615908637117142463896', 'package_criteria': [{'cve_id': 'CVE-2009-3233', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'changetrack', 'fixed_version': '4.5-2', 'affected_version_range': '< 4.5-2'}]} | 8ad882939fa59add397819b19b6186509c90ea031d16829e5128360f00d809bc | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:96085401760679768789044073718547980880 | CVE-2009-3235 dovecot | Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632. | ['CVE-2009-3235'] | ['Debian GNU/Linux 12', 'dovecot'] | ['CVE-2009-3235', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235'] | {'cves': '["CVE-2009-3235"]', 'title': 'CVE-2009-3235 dovecot', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "dovecot"]', 'severity': None, 'references': '["CVE-2009-3235", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3235"]', 'description': 'Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.', 'definition_id': 'oval:org.debian:def:96085401760679768789044073718547980880', 'package_criteria': [{'cve_id': 'CVE-2009-3235', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'dovecot', 'fixed_version': '1:1.2.1-1', 'affected_version_range': '< 1:1.2.1-1'}]} | 871f7ca4f6663725fc6d964297604d2ab6c16c545241f5bd8dbaa698bad9f234 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:9786195431872739144462304794814206940 | CVE-2009-3241 wireshark | Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets. | ['CVE-2009-3241'] | ['Debian GNU/Linux 12', 'wireshark'] | ['CVE-2009-3241', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3241'] | {'cves': '["CVE-2009-3241"]', 'title': 'CVE-2009-3241 wireshark', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "wireshark"]', 'severity': None, 'references': '["CVE-2009-3241", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3241"]', 'description': 'Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.', 'definition_id': 'oval:org.debian:def:9786195431872739144462304794814206940', 'package_criteria': [{'cve_id': 'CVE-2009-3241', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'wireshark', 'fixed_version': '1.2.2-1', 'affected_version_range': '< 1.2.2-1'}]} | 912554dcdb5aed53159d2b40dfd5ae52573c9093b8193d389449f2a804da108a | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:57124108271738073518832475128381496461 | CVE-2009-3287 thin | lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header. | ['CVE-2009-3287'] | ['Debian GNU/Linux 12', 'thin'] | ['CVE-2009-3287', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3287'] | {'cves': '["CVE-2009-3287"]', 'title': 'CVE-2009-3287 thin', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "thin"]', 'severity': None, 'references': '["CVE-2009-3287", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3287"]', 'description': 'lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.', 'definition_id': 'oval:org.debian:def:57124108271738073518832475128381496461', 'package_criteria': [{'cve_id': 'CVE-2009-3287', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'thin', 'fixed_version': '1.2.4-1', 'affected_version_range': '< 1.2.4-1'}]} | 44205339519020de69a3bc0085136df232ce149fc6a02f459d6fed0721bf1b5f | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:146249366598113472856943339170912844190 | CVE-2009-3289 glib2.0 | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory. | ['CVE-2009-3289'] | ['Debian GNU/Linux 12', 'glib2.0'] | ['CVE-2009-3289', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3289'] | {'cves': '["CVE-2009-3289"]', 'title': 'CVE-2009-3289 glib2.0', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "glib2.0"]', 'severity': None, 'references': '["CVE-2009-3289", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3289"]', 'description': 'The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.', 'definition_id': 'oval:org.debian:def:146249366598113472856943339170912844190', 'package_criteria': [{'cve_id': 'CVE-2009-3289', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'glib2.0', 'fixed_version': '2.22.0-1', 'affected_version_range': '< 2.22.0-1'}]} | df8cb4d8163d73620e0887905850a0790df97184d0468a7dd0d52fd14006aa01 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 | |||
bookworm | oval:org.debian:def:150387314635769531534728323264705197154 | CVE-2009-3295 krb5 | The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request. | ['CVE-2009-3295'] | ['Debian GNU/Linux 12', 'krb5'] | ['CVE-2009-3295', 'https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3295'] | {'cves': '["CVE-2009-3295"]', 'title': 'CVE-2009-3295 krb5', 'issued': None, 'release': 'bookworm', 'updated': None, 'affected': '["Debian GNU/Linux 12", "krb5"]', 'severity': None, 'references': '["CVE-2009-3295", "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3295"]', 'description': 'The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a ticket request.', 'definition_id': 'oval:org.debian:def:150387314635769531534728323264705197154', 'package_criteria': [{'cve_id': 'CVE-2009-3295', 'source': 'criterion_comment', 'status': 'fixed', 'package': 'krb5', 'fixed_version': '1.7+dfsg-4', 'affected_version_range': '< 1.7+dfsg-4'}]} | e1b76aae8a6e880845dad27c2195c37a31e452857c87184a0aa953829066f1e8 | 2026-05-30 01:53:22.099498+03:00 | 2026-06-29 20:15:56.598384+03:00 |