CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-4336

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Dec 2009
    9.3
    Critical

    CVE-2009-3980

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 17 Dec 2009
    4.3
    Medium

    CVE-2009-4343

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Training Company Database (trainincdb) extension 0.4.7 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Dec 2009
    6.8
    Medium

    CVE-2009-4349

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.

    Published: 17 Dec 2009
    9.3
    Critical

    CVE-2009-3982

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 17 Dec 2009
    7.5
    High

    CVE-2009-4337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2008-6691.

    Published: 17 Dec 2009
    7.5
    High

    CVE-2009-4338

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Flash SlideShow (slideshow) extension 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 17 Dec 2009
    7.5
    High

    CVE-2009-4339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Subscription (mf_subscription) extension 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 17 Dec 2009
    4.3
    Medium

    CVE-2009-4340

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the No indexed Search (no_indexed_search) extension 0.2.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Dec 2009
    7.5
    High

    CVE-2009-4341

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the No indexed Search (no_indexed_search) extension 0.2.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 17 Dec 2009
    7.5
    High

    CVE-2009-4342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Job Exchange (jobexchange) extension 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 17 Dec 2009
    4.3
    Medium

    CVE-2009-4346

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Frontend news submitter with RTE (fe_rtenews) extension 1.4.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Dec 2009
    4.3
    Medium

    CVE-2009-4347

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in daloradius-users/login.php in daloRADIUS 0.9-8 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Published: 17 Dec 2009
    4.3
    Medium

    CVE-2009-4348

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to inject arbitrary web script or HTML via the topic parameter in a topic action, a different vector than CVE-2006-2146.

    Published: 17 Dec 2009
    4.3
    Medium

    CVE-2009-4377

    Last Modified: 23 Apr 2026

    The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service (crash) via a crafted packet that triggers a NULL pointer dereference, as demonstrated by fuzz-2009-12-07-11141.pcap.

    Published: 17 Dec 2009
    4.7
    Medium

    CVE-2009-4895

    Last Modified: 11 Apr 2025

    Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via unknown vectors, related to the put_tty_queue and __f_setown functions. NOTE: the vulnerability was addressed in a different way in 2.6.32.9.

    Published: 17 Dec 2009
    10
    Critical

    CVE-2009-4335

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."

    Published: 16 Dec 2009
    4.6
    Medium

    CVE-2009-4334

    Last Modified: 23 Apr 2026

    The Self Tuning Memory Manager (STMM) component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 uses 0666 permissions for the STMM log file, which allows local users to cause a denial of service or have unspecified other impact by writing to this file.

    Published: 16 Dec 2009
    4
    Medium

    CVE-2009-4328

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DRDA Services component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (server trap) by calling a SQL stored procedure in unknown circumstances.

    Published: 16 Dec 2009
    6.4
    Medium

    CVE-2009-4325

    Last Modified: 23 Apr 2026

    The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers."

    Published: 16 Dec 2009
    4.3
    Medium

    CVE-2009-3731

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebWorks Help 2.0 through 5.0 in VMware vCenter 4.0 before Update 1 Build 208156; VMware Server 2.0.2; VMware ESX 4.0; VMware Lab Manager 2.x; VMware vCenter Lab Manager 3.x and 4.x before 4.0.1; VMware Stage Manager 1.x before 4.0.1; WebWorks Publisher 6.x through 8.x; WebWorks Publisher 2003; and WebWorks ePublisher 9.0.x through 9.3, 2008.1 through 2008.4, and 2009.x before 2009.3 allow remote attackers to inject arbitrary web script or HTML via (1) wwhelp_entry.html, reachable through index.html and wwhsec.htm, (2) wwhelp/wwhimpl/api.htm, (3) wwhelp/wwhimpl/common/html/frameset.htm, (4) wwhelp/wwhimpl/common/scripts/switch.js, or (5) the window.opener component in wwhelp/wwhimpl/common/html/bookmark.htm, related to (a) unspecified parameters and (b) messages used in topic links for the bookmarking functionality.

    Published: 16 Dec 2009
    5
    Medium

    CVE-2009-4327

    Last Modified: 23 Apr 2026

    The Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1 does not properly validate the size of a memory pool during a creation attempt, which allows attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 16 Dec 2009
    4
    Medium

    CVE-2009-4329

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Engine Utilities component in IBM DB2 9.5 before FP5 allows remote authenticated users to cause a denial of service (segmentation fault) by modifying the db2ra data stream sent in a request from the Load Utility.

    Published: 16 Dec 2009
    7.2
    High

    CVE-2009-4331

    Last Modified: 23 Apr 2026

    The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and authorization settings, which has unknown impact and local attack vectors.

    Published: 16 Dec 2009
    5
    Medium

    CVE-2009-4332

    Last Modified: 23 Apr 2026

    db2pd in the Problem Determination component in IBM DB2 9.1 before FP7 and 9.5 before FP5 allows attackers to cause a denial of service (NULL pointer dereference and application termination) via unspecified vectors.

    Published: 16 Dec 2009
    7.5
    High

    CVE-2009-4333

    Last Modified: 23 Apr 2026

    The Relational Data Services component in IBM DB2 9.5 before FP5 allows attackers to obtain the password argument from the SET ENCRYPTION PASSWORD statement via vectors involving the GET SNAPSHOT FOR DYNAMIC SQL command.

    Published: 16 Dec 2009
    7.2
    High

    CVE-2009-4330

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in db2licm in the Engine Utilities component in IBM DB2 9.5 before FP5 has unknown impact and local attack vectors.

    Published: 16 Dec 2009
    4.3
    Medium

    CVE-2009-4326

    Last Modified: 23 Apr 2026

    The RAND scalar function in the Common Code Infrastructure component in IBM DB2 9.5 before FP5 and 9.7 before FP1, when the Database Partitioning Feature (DPF) is used, produces "repeating" return values, which might allow attackers to defeat protection mechanisms based on randomization by predicting a value.

    Published: 16 Dec 2009
    9.3
    Critical

    CVE-2009-4035

    Last Modified: 23 Apr 2026

    The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to execute arbitrary code via a PDF file with a crafted Type 1 font that can produce a negative value, leading to a signed-to-unsigned integer conversion error and a buffer overflow.

    Published: 16 Dec 2009
    4.3
    Medium

    CVE-2009-3701

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) phpshell.php, (2) cmdshell.php, or (3) sqlshell.php in admin/, related to the PHP_SELF variable.

    Published: 16 Dec 2009
    7.2
    High

    CVE-2009-4141

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include enabling O_ASYNC (aka FASYNC or FIOASYNC) on a locked file, and then closing this file.

    Published: 16 Dec 2009
    10
    Critical

    CVE-2009-4143

    Last Modified: 23 Apr 2026

    PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.

    Published: 16 Dec 2009
    9.3
    Critical

    CVE-2009-3388

    Last Modified: 23 Apr 2026

    liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."

    Published: 15 Dec 2009
    6.8
    Medium

    CVE-2009-3983

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.

    Published: 15 Dec 2009
    6.8
    Medium

    CVE-2009-3985

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the associated blank document, a related issue to CVE-2009-2654.

    Published: 15 Dec 2009
    Unknown

    CVE-2010-0061

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 15 Dec 2009
    7.6
    High

    CVE-2009-3986

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window.opener property.

    Published: 15 Dec 2009
    7.8
    High

    CVE-2009-3987

    Last Modified: 23 Apr 2026

    The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote attackers to obtain potentially sensitive information about installed software by making multiple calls that specify the ProgID values of different COM objects.

    Published: 15 Dec 2009
    9.3
    Critical

    CVE-2009-3389

    Last Modified: 23 Apr 2026

    Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a video with large dimensions.

    Published: 15 Dec 2009
    9.3
    Critical

    CVE-2009-3979

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 15 Dec 2009
    9.3
    Critical

    CVE-2009-3981

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 15 Dec 2009
    6.8
    Medium

    CVE-2009-3984

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with a No Content (aka 204) status code and an empty body.

    Published: 15 Dec 2009
    7.5
    High

    CVE-2009-4323

    Last Modified: 23 Apr 2026

    The installation for Zen Cart stores sensitive information and insecure programs under the (1) docs, (2) extras, and (3) zc_install folders, and (4) install.txt, which allows remote attackers to obtain sensitive information, delete the database, and conduct other attacks via a direct request, different vulnerabilities than CVE-2009-4321 and CVE-2009-4322.

    Published: 14 Dec 2009
    5
    Medium

    CVE-2009-4321

    Last Modified: 23 Apr 2026

    extras/curltest.php in Zen Cart 1.3.8 and 1.3.8a, and possibly other versions, allows remote attackers to read arbitrary files via a file:// URI. NOTE: some of these details are obtained from third party information.

    Published: 14 Dec 2009
    5
    Medium

    CVE-2009-4322

    Last Modified: 23 Apr 2026

    extras/ipn_test_return.php in Zen Cart allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Published: 14 Dec 2009
    4.3
    Medium

    CVE-2009-4320

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in searchform.php in The Next Generation of Genealogy Sitebuilding (TNG) 7.1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 14 Dec 2009
    6.8
    Medium

    CVE-2009-4315

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or modify arbitrary files via a .. (dot dot) in the nugget parameter and a modified pagevalue parameter, as demonstrated by creating and accessing a .php file to execute arbitrary PHP code.

    Published: 14 Dec 2009
    6.8
    Medium

    CVE-2009-4319

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in js/bbcodepress/bbcode-form.php in eoCMS 0.9.03 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BBCODE_path parameter.

    Published: 14 Dec 2009
    4.3
    Medium

    CVE-2009-4318

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.

    Published: 14 Dec 2009
    4.3
    Medium

    CVE-2009-4317

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in ScriptsEz Ez Cart allows remote attackers to inject arbitrary web script or HTML via the sid parameter in a showcat action.

    Published: 14 Dec 2009