CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-4221

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vector than CVE-2008-3767.

    Published: 7 Dec 2009
    7.2
    High

    CVE-2009-4215

    Last Modified: 23 Apr 2026

    Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs.

    Published: 7 Dec 2009
    6.8
    Medium

    CVE-2009-4224

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter to (1) _plugin/subscriber/inc/post.php and (2) as/lib/news_modify.php.

    Published: 7 Dec 2009
    7.5
    High

    CVE-2009-4220

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pcConfig[smartyPath] parameter.

    Published: 7 Dec 2009
    9.3
    Critical

    CVE-2009-4219

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote attackers to execute arbitrary code via a long URL property value. NOTE: some of these details are obtained from third party information.

    Published: 7 Dec 2009
    7.5
    High

    CVE-2009-4218

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attackers to execute arbitrary SQL commands via the (1) admin or (2) password field, a related issue to CVE-2007-6091. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Dec 2009
    7.5
    High

    CVE-2009-4217

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Dec 2009
    6.9
    Medium

    CVE-2009-4235

    Last Modified: 23 Apr 2026

    acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file or cause a denial of service by overwriting this file, a different vulnerability than CVE-2009-4033.

    Published: 7 Dec 2009
    6.9
    Medium

    CVE-2009-4033

    Last Modified: 23 Apr 2026

    A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file, cause a denial of service by overwriting this file, or gain privileges by executing this file.

    Published: 7 Dec 2009
    4.6
    Medium

    CVE-2010-0291

    Last Modified: 11 Apr 2025

    The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."

    Published: 7 Dec 2009
    5
    Medium

    CVE-2010-1311

    Last Modified: 11 Apr 2025

    The qtm_decompress function in libclamav/mspack.c in ClamAV before 0.96 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted CAB archive that uses the Quantum (aka .Q) compression format. NOTE: some of these details are obtained from third party information.

    Published: 7 Dec 2009
    10
    Critical

    CVE-2009-4124

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving (1) String#ljust, (2) String#center, or (3) String#rjust. NOTE: some of these details are obtained from third party information.

    Published: 7 Dec 2009
    4.4
    Medium

    CVE-2009-4135

    Last Modified: 23 Apr 2026

    The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.

    Published: 7 Dec 2009
    5.8
    Medium

    CVE-2009-4129

    Last Modified: 23 Apr 2026

    Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in between the document request and document load for a web page in a different domain.

    Published: 5 Dec 2009
    5.8
    Medium

    CVE-2009-4130

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.

    Published: 5 Dec 2009
    9.3
    Critical

    CVE-2009-4211

    Last Modified: 23 Apr 2026

    The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filenames equal to (1) java, (2) openssl, (3) php, (4) snort, (5) tshark, (6) vncserver, or (7) wireshark, which allows local users to gain privileges via a Trojan horse program.

    Published: 4 Dec 2009
    6.8
    Medium

    CVE-2009-4199

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) property_uid parameter in a viewproperty action to index.php and the (2) regID parameter in a showregion action to index.php.

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4206

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Dec 2009
    6.5
    Medium

    CVE-2009-4198

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.

    Published: 4 Dec 2009
    3.3
    Low

    CVE-2009-3304

    Last Modified: 23 Apr 2026

    GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.

    Published: 4 Dec 2009
    9.3
    Critical

    CVE-2009-4148

    Last Modified: 23 Apr 2026

    DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by code that loads the WScript.Shell ActiveX control, related to a "script injection vulnerability."

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4200

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_seminar action to index.php.

    Published: 4 Dec 2009
    9.3
    Critical

    CVE-2009-4201

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Mp3 Tag Assistant Professional 2.92 build 300 allow remote attackers to execute arbitrary code via an MP3 file with a long string in the (1) ID3v1, (2) ID3v2, or (3) APEv2 metadata field.

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4202

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the controller parameter to index.php.

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4203

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2) Client-IP HTTP header in a request to the default URI under admin/.

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4204

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Dec 2009
    7.5
    High

    CVE-2009-4208

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to index.php.

    Published: 4 Dec 2009
    4.3
    Medium

    CVE-2009-4209

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) file parameters in an editsite action, different vectors than CVE-2008-6127 and CVE-2009-1367.

    Published: 4 Dec 2009
    4.3
    Medium

    CVE-2009-4207

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a submission.

    Published: 4 Dec 2009
    9.3
    Critical

    CVE-2009-4195

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. NOTE: some of these details are obtained from third party information.

    Published: 4 Dec 2009
    6.8
    Medium

    CVE-2009-2631

    Last Modified: 23 Apr 2026

    Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL VPN; SafeNet SecureWire Access Gateway; Juniper Networks Secure Access; Nortel CallPilot; Citrix Access Gateway; and other products, when running in configurations that do not restrict access to the same domain as the VPN, retrieve the content of remote URLs from one domain and rewrite them so they originate from the VPN's domain, which violates the same origin policy and allows remote attackers to conduct cross-site scripting attacks, read cookies that originated from other domains, access the Web VPN session to gain access to internal resources, perform key logging, and conduct other attacks. NOTE: it could be argued that this is a fundamental design problem in any clientless VPN solution, as opposed to a commonly-introduced error that can be fixed in separate implementations. Therefore a single CVE has been assigned for all products that have this design

    Published: 4 Dec 2009
    4.3
    Medium

    CVE-2009-4196

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arbitrary web script or HTML via the (1) BackButton parameter to error_1; (2) wzConnFlag parameter to fresh_pppoe_1; (3) diag_pppindex_argen and (4) DiagStartFlag parameters to rpDiag_argen_1; (5) wzdmz_active and (6) wzdmzHostIP parameters to rpNATdmz_argen_1; (7) wzVIRTUALSVR_endPort, (8) wzVIRTUALSVR_endPortLocal, (9) wzVIRTUALSVR_IndexFlag, (10) wzVIRTUALSVR_localIP, (11) wzVIRTUALSVR_startPort, and (12) wzVIRTUALSVR_startPortLocal parameters to rpNATvirsvr_argen_1; (13) Connect_DialFlag, (14) Connect_DialHidden, and (15) Connect_Flag parameters to rpStatus_argen_1; (16) Telephone_select, and (17) wzFirstFlag parameters to rpwizard_1; and (18) wzConnectFlag parameter to rpwizPppoe_1.

    Published: 4 Dec 2009
    4.7
    Medium

    CVE-2009-4197

    Last Modified: 23 Apr 2026

    rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the autocomplete setting for the password parameter, which makes it easier for local users or physically proximate attackers to obtain the password from web browsers that support autocomplete.

    Published: 4 Dec 2009
    7.8
    High

    CVE-2009-4020

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.

    Published: 4 Dec 2009
    5.5
    Medium

    CVE-2012-0879

    Last Modified: 11 Apr 2025

    The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.

    Published: 4 Dec 2009
    8.1
    High

    CVE-2009-4194

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files via a .. (dot dot) in the DELE command. NOTE: some of these details are obtained from third party information.

    Published: 3 Dec 2009
    5
    Medium

    CVE-2009-4192

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Dec 2009
    9.3
    Critical

    CVE-2009-1566

    Last Modified: 23 Apr 2026

    Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimensions.

    Published: 3 Dec 2009
    10
    Critical

    CVE-2009-0895

    Last Modified: 23 Apr 2026

    Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.

    Published: 3 Dec 2009
    9.3
    Critical

    CVE-2009-1567

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value.

    Published: 3 Dec 2009
    10
    Critical

    CVE-2009-4189

    Last Modified: 23 Apr 2026

    HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3099 and CVE-2009-3843.

    Published: 3 Dec 2009
    7.8
    High

    CVE-2009-4190

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause a denial of service (panic) via unknown vectors, as demonstrated by the vd_solaris2 module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 3 Dec 2009
    7.2
    High

    CVE-2009-4191

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated by the vd_sol_local module in VulnDisco Pack Professional 8.12. NOTE: as of 20091203, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 3 Dec 2009
    9.3
    Critical

    CVE-2009-4186

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cascading Style Sheets (CSS) background property.

    Published: 3 Dec 2009
    4.3
    Medium

    CVE-2009-4187

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Dec 2009
    10
    Critical

    CVE-2009-4188

    Last Modified: 23 Apr 2026

    HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098.

    Published: 3 Dec 2009
    6.8
    Medium

    CVE-2009-4227

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the read_textobject function in read1_3.c in fig2dev in Transfig 3.2.5a and earlier, allows remote attackers to execute arbitrary code via a long string in a malformed .fig file that uses the 1.3 file format. NOTE: some of these details are obtained from third party information.

    Published: 3 Dec 2009
    4.3
    Medium

    CVE-2009-4228

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of service (application crash) via a long string in a malformed .fig file that uses the 1.3 file format, possibly related to the readfp_fig function in f_read.c.

    Published: 3 Dec 2009
    4.3
    Medium

    CVE-2009-4171

    Last Modified: 23 Apr 2026

    An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by calling the RegisterMe method with a long argument.

    Published: 2 Dec 2009