CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-4101

    Last Modified: 23 Apr 2026

    infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

    Published: 28 Nov 2009
    9.3
    Critical

    CVE-2009-4107

    Last Modified: 23 Apr 2026

    Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.

    Published: 28 Nov 2009
    4
    Medium

    CVE-2009-4108

    Last Modified: 23 Apr 2026

    XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of files or directories, then performing a LIST command.

    Published: 28 Nov 2009
    3.5
    Low

    CVE-2009-4105

    Last Modified: 23 Apr 2026

    TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command without sending file data in between these two commands.

    Published: 28 Nov 2009
    7.5
    High

    CVE-2009-4106

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitrary PHP code via the filename and text parameters.

    Published: 28 Nov 2009
    5
    Medium

    CVE-2009-4109

    Last Modified: 24 Apr 2026

    The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.

    Published: 28 Nov 2009
    4.3
    Medium

    CVE-2009-4110

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.

    Published: 28 Nov 2009
    9.3
    Critical

    CVE-2009-4102

    Last Modified: 23 Apr 2026

    Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

    Published: 28 Nov 2009
    7.5
    High

    CVE-2009-4096

    Last Modified: 23 Apr 2026

    RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc.

    Published: 28 Nov 2009
    9.3
    Critical

    CVE-2009-4097

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary code via a long URL in an M3U file. NOTE: some of these details are obtained from third party information.

    Published: 28 Nov 2009
    9.3
    Critical

    CVE-2009-4100

    Last Modified: 23 Apr 2026

    Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.

    Published: 28 Nov 2009
    7.5
    High

    CVE-2009-4082

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_path parameter.

    Published: 27 Nov 2009
    6.8
    Medium

    CVE-2009-4088

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrary files via directory traversal sequences in the css parameter to (1) getjs.php and (2) getcsslocal.php; and include and execute arbitrary local files via the (3) group parameter to upload.php.

    Published: 27 Nov 2009
    7.5
    High

    CVE-2009-4090

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ajax/addComment.php in telepark.wiki 2.4.23 and earlier script allows remote attackers to execute arbitrary code by uploading a file with a name containing a NULL byte.

    Published: 27 Nov 2009
    5
    Medium

    CVE-2009-4091

    Last Modified: 23 Apr 2026

    comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via the (1) edit or (2) del action.

    Published: 27 Nov 2009
    4.3
    Medium

    CVE-2009-4087

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in telepark.wiki 2.4.23 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 27 Nov 2009
    4.3
    Medium

    CVE-2009-4093

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cname (Name) or (2) email parameters.

    Published: 27 Nov 2009
    7.5
    High

    CVE-2009-4095

    Last Modified: 23 Apr 2026

    myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.

    Published: 27 Nov 2009
    7.5
    High

    CVE-2009-4094

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path parameter.

    Published: 27 Nov 2009
    4.3
    Medium

    CVE-2009-4083

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) submitnews.php, (2) usersettings.php; and (3) newpost.php, (4) banlist.php, (5) banner.php, (6) cpage.php, (7) download.php, (8) users_extended.php, (9) frontpage.php, (10) links.php, and (11) mailout.php in e107_admin/. NOTE: this may overlap CVE-2004-2040 and CVE-2006-4794, but there are insufficient details to be certain.

    Published: 27 Nov 2009
    7.5
    High

    CVE-2009-4084

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Nov 2009
    7.5
    High

    CVE-2009-4085

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[BASE] parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Nov 2009
    5
    Medium

    CVE-2009-4089

    Last Modified: 23 Apr 2026

    telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to ajax/deletePage.php or (2) delete arbitrary comments via a modified pageID parameter to ajax/deleteComment.php.

    Published: 27 Nov 2009
    6.8
    Medium

    CVE-2009-4092

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote attackers to hijack the authentication of administrators and users for requests that change passwords.

    Published: 27 Nov 2009
    5
    Medium

    CVE-2009-4086

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information.

    Published: 27 Nov 2009
    4.4
    Medium

    CVE-2009-4081

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in dstat before r3199 allows local users to gain privileges via a Trojan horse Python module in the current working directory, a different vulnerability than CVE-2009-3894.

    Published: 27 Nov 2009
    2.1
    Low

    CVE-2009-4080

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 and 10, and OpenSolaris before snv_78, allow local users to cause a denial of service (daemon crash) via vectors involving multiple serviceSearchDescriptor attributes and a call to the getldap_lookup function, and unspecified other vectors.

    Published: 27 Nov 2009
    4.3
    Medium

    CVE-2009-4214

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

    Published: 27 Nov 2009
    4.3
    Medium

    CVE-2009-4078

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Nov 2009
    6.8
    Medium

    CVE-2009-4079

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authentication of users for requests that delete a ticket via unspecified vectors.

    Published: 25 Nov 2009
    4.3
    Medium

    CVE-2009-4074

    Last Modified: 23 Apr 2026

    The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, related to the details of output encoding and improper modification of an HTML attribute, aka "XSS Filter Script Handling Vulnerability."

    Published: 25 Nov 2009
    5
    Medium

    CVE-2009-4075

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors that trigger a "dangling sshd authentication thread."

    Published: 25 Nov 2009
    9.3
    Critical

    CVE-2009-3033

    Last Modified: 23 Apr 2026

    Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.

    Published: 25 Nov 2009
    6.5
    Medium

    CVE-2009-4305

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

    Published: 25 Nov 2009
    7.5
    High

    CVE-2009-4304

    Last Modified: 23 Apr 2026

    Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.

    Published: 25 Nov 2009
    5
    Medium

    CVE-2009-4303

    Last Modified: 23 Apr 2026

    Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores (1) password hashes and (2) unspecified "secrets" in backup files, which might allow attackers to obtain sensitive information.

    Published: 25 Nov 2009
    5
    Medium

    CVE-2009-4302

    Last Modified: 23 Apr 2026

    login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing.

    Published: 25 Nov 2009
    6
    Medium

    CVE-2009-4301

    Last Modified: 23 Apr 2026

    mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.

    Published: 25 Nov 2009
    5
    Medium

    CVE-2009-4299

    Last Modified: 23 Apr 2026

    mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which allows attackers to read unauthorized Glossary entries via unknown vectors.

    Published: 25 Nov 2009
    6.8
    Medium

    CVE-2009-4297

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 25 Nov 2009
    9
    Critical

    CVE-2009-4112

    Last Modified: 23 Apr 2026

    Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain arbitrary commands.

    Published: 25 Nov 2009
    4.4
    Medium

    CVE-2009-3894

    Last Modified: 23 Apr 2026

    Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or (2) a certain subdirectory of the current working directory.

    Published: 25 Nov 2009
    5
    Medium

    CVE-2009-4298

    Last Modified: 23 Apr 2026

    The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.

    Published: 25 Nov 2009
    5
    Medium

    CVE-2009-4300

    Last Modified: 23 Apr 2026

    Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.

    Published: 25 Nov 2009
    9.3
    Critical

    CVE-2009-3576

    Last Modified: 23 Apr 2026

    Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.

    Published: 24 Nov 2009
    4.9
    Medium

    CVE-2009-3898

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4069

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Nov 2009
    5
    Medium

    CVE-2009-4073

    Last Modified: 23 Apr 2026

    The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and possibly a local username, by reading the dc:title element of a PDF document that was generated from a local web page.

    Published: 24 Nov 2009
    10
    Critical

    CVE-2009-4072

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-3303

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.

    Published: 24 Nov 2009