Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 9.3
CVE-2009-3131EPSS 25%
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…
Compatibility Pack Word Excel Powerpoint
Mitigation only
HIGH 9.3
CVE-2009-3132EPSS 26%
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…
Compatibility Pack Word Excel Powerpoint
Mitigation only
HIGH 9.3
CVE-2009-3133EPSS 25%
Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary…
Compatibility Pack Word Excel Powerpoint
Mitigation only
HIGH 9.3
CVE-2009-3134EPSS 26%
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel V…
Compatibility Pack Word Excel Powerpoint
Mitigation only
HIGH 9.3
CVE-2009-2514EPSS 47%
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of…
Windows 2000
Mitigation only
HIGH 9.3
CVE-2009-3127EPSS 25%
Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, and Office Excel Viewer 2003 SP3 …
Compatibility Pack Word Excel Powerpoint
Mitigation only
HIGH 9.3
CVE-2009-3128EPSS 25%
Microsoft Office Excel 2002 SP3 and 2003 SP3, and Office Excel Viewer 2003 SP3, does not properly parse the Excel file format, which allows remote at…
Compatibility Pack Word Excel Powerpoint
Mitigation only
HIGH 9.3
CVE-2009-3850EPSS 9%
Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoa…
Blender
No fix yet
HIGH 8.5
CVE-2009-3631
The Backend subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2, when the DAM extension or …
TYPO3
after 4.0.12
HIGH 7.5
CVE-2009-3817
PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers…
Com Booklibrary
No fix yet
HIGH 7.5
CVE-2009-3822
PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbi…
Com Ajaxchat
No fix yet
MEDIUM 6.5
CVE-2009-3814
Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" f…
Runcms
No fix yet
HIGH 7.5
CVE-2009-3760
Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote a…
Xencenterweb
No fix yet
HIGH 7.5
CVE-2009-3705EPSS 10%
PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbitrary PHP code via a URL in th…
Achievo
after 1.3.4
HIGH 9.3
CVE-2009-2497EPSS 23%
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle in…
Windows 2000
Mitigation only
HIGH 9.3
CVE-2009-2503EPSS 22%
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office Sys…
Windows 2003 Server
Mitigation only
HIGH 9.3
CVE-2009-2525EPSS 23%
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does …
Windows 2000
Mitigation only
HIGH 9.3
CVE-2009-2528EPSS 20%
GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows remote attackers to execute ar…
Windows 2003 Server
Mitigation only
HIGH 9.3
CVE-2009-0091EPSS 26%
Microsoft .NET Framework 2.0, 2.0 SP1, and 3.5 does not properly enforce a certain type-equality constraint in .NET verifiable code, which allows rem…
Windows 2000
Mitigation only
HIGH 9.3
CVE-2009-0555EPSS 27%
Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does …
Windows 2000
Patch available
MEDIUM 6.8
CVE-2009-3660
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attack…
Efront
after 3.5.4
HIGH 7.5
CVE-2009-3541
PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the Da…
Phpgenealogy
No fix yet
HIGH 9.3
CVE-2009-3518EPSS 5%
Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot an…
Installation Manager
after 1.3.2
HIGH 7.5
CVE-2009-3511
Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot …
Justvisual
No fix yet
HIGH 7.5
CVE-2009-3492
Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL…
Loggix Project
after 9.4.5
MEDIUM 6.0
CVE-2009-3478
Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension …
Fireftp
Patch available
MEDIUM 6.8
CVE-2009-3424
Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote attackers to execute arbitrary …
Maxcms
No fix yet
MEDIUM 6.8
CVE-2009-3426
PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code…
Maxcms
No fix yet
HIGH 7.5
CVE-2009-3362
PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP code via a URL in the id par…
Sznews
No fix yet
HIGH 7.5
CVE-2009-3365
PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 allows remote attackers to execu…
Aurora
No fix yet