CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-3577

    Last Modified: 23 Apr 2026

    Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."

    Published: 24 Nov 2009
    9.3
    Critical

    CVE-2009-3578

    Last Modified: 23 Apr 2026

    Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbitrary code via a (1) .ma or (2) .mb file that uses the Maya Embedded Language (MEL) python command or unspecified other MEL commands, related to "Script Nodes."

    Published: 24 Nov 2009
    5
    Medium

    CVE-2009-3896

    Last Modified: 23 Apr 2026

    src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.14 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a long URI.

    Published: 24 Nov 2009
    7.5
    High

    CVE-2009-4070

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 24 Nov 2009
    5.8
    Medium

    CVE-2009-4071

    Last Modified: 23 Apr 2026

    Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a different web site, which allows remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 24 Nov 2009
    7.5
    High

    CVE-2009-4056

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the popup parameter.

    Published: 24 Nov 2009
    7.5
    High

    CVE-2009-4057

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action to index.php.

    Published: 24 Nov 2009
    7.5
    High

    CVE-2009-4058

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in allauctions.php in Telebid Auction Script allows remote attackers to execute arbitrary SQL commands via the aid parameter.

    Published: 24 Nov 2009
    6.8
    Medium

    CVE-2009-4059

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a thumbs action to index.php.

    Published: 24 Nov 2009
    7.5
    High

    CVE-2009-4060

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute arbitrary SQL commands via the productId parameter.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4064

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Gallery Assist module 6.x before 6.x-1.7 for Drupal allows remote attackers to inject arbitrary web script or HTML via node titles.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4065

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the settings page in the Strongarm module 6.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via the value field when viewing overridden variables.

    Published: 24 Nov 2009
    6.8
    Medium

    CVE-2009-4066

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 before 5.x-1.2 and 6 before 6.x-1.1 for Drupal allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) subscribing or (2) unsubscribing to mailing lists.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4061

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Agreement module 6.x before 6.x-1.2 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4062

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Printfriendly module 6.x before 6.x-1.6 for Drupal allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4063

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Subgroups for Organic Groups (OG) module 5.x before 5.x-4.0 and 5.x before 5.x-3.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified node titles.

    Published: 24 Nov 2009
    10
    Critical

    CVE-2009-3843

    Last Modified: 23 Apr 2026

    HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.

    Published: 24 Nov 2009
    7.8
    High

    CVE-2009-4031

    Last Modified: 23 Apr 2026

    The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before 2.6.32-rc8-next-20091125 tries to interpret instructions that contain too many bytes to be valid, which allows guest OS users to cause a denial of service (increased scheduling latency) on the host OS via unspecified manipulations related to SMP support.

    Published: 24 Nov 2009
    4.3
    Medium

    CVE-2009-4047

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to area.php; the (2) pagina, (3) sentido, (4) q_registros, and (5) orden parameters to area.php; (6) the q_registros parameter to solic_display.php; (7) the PATH_INFO to area_list.php; (8) the q_registros parameter to area_list.php; (9) the PATH_INFO to atributo.php; the (10) pagina, (11) q_registros, and (12) orden parameters to atributo_list.php; (13) an arbitrary parameter name beginning with "sentido" to atributo_list.php; and (14) the PATH_INFO to caso_insert.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Nov 2009
    4
    Medium

    CVE-2009-4048

    Last Modified: 23 Apr 2026

    Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage) via an APPE command to one socket in conjunction with a DELE command to a second socket.

    Published: 23 Nov 2009
    7.2
    High

    CVE-2009-4049

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted arguments to IOCTL 0x80002024.

    Published: 23 Nov 2009
    5
    Medium

    CVE-2009-4051

    Last Modified: 23 Apr 2026

    Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SITE INDEX commands.

    Published: 23 Nov 2009
    Unknown

    CVE-2009-4054

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-3672. Reason: This candidate is a duplicate of CVE-2009-3672. The duplicate was assigned by the CNA without proper coordination with MITRE. Notes: All CVE users should reference CVE-2009-3672 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Nov 2009
    5
    Medium

    CVE-2009-4050

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Nov 2009
    4.3
    Medium

    CVE-2009-4052

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.

    Published: 23 Nov 2009
    6.5
    Medium

    CVE-2009-4053

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Nov 2009
    7.1
    High

    CVE-2009-4307

    Last Modified: 23 Apr 2026

    The ext4_fill_flex_info function in fs/ext4/super.c in the Linux kernel before 2.6.32-git6 allows user-assisted remote attackers to cause a denial of service (divide-by-zero error and panic) via a malformed ext4 filesystem containing a super block with a large FLEX_BG group size (aka s_log_groups_per_flex value).

    Published: 23 Nov 2009
    2.6
    Low

    CVE-2009-4022

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.

    Published: 23 Nov 2009
    4.3
    Medium

    CVE-2010-2543

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in include/top_graph_header.php in Cacti before 0.8.7g allows remote attackers to inject arbitrary web script or HTML via the graph_start parameter to graph.php. NOTE: this vulnerability exists because of an incorrect fix for CVE-2009-4032.2.b.

    Published: 21 Nov 2009
    4.3
    Medium

    CVE-2009-4032

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.

    Published: 21 Nov 2009
    4.3
    Medium

    CVE-2009-4040

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.

    Published: 20 Nov 2009
    5
    Medium

    CVE-2009-4041

    Last Modified: 23 Apr 2026

    UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags.

    Published: 20 Nov 2009
    4.3
    Medium

    CVE-2009-4042

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 20 Nov 2009
    4.3
    Medium

    CVE-2009-4038

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) onok or (2) oncancel parameter to the logon program. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Nov 2009
    4.3
    Medium

    CVE-2009-4039

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Nov 2009
    7.5
    High

    CVE-2009-4044

    Last Modified: 23 Apr 2026

    The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API via unknown vectors.

    Published: 20 Nov 2009
    5
    Medium

    CVE-2005-4882

    Last Modified: 23 Apr 2026

    tftpd in Philippe Jounin Tftpd32 2.74 and earlier, as used in Wyse Simple Imager (WSI) and other products, allows remote attackers to cause a denial of service (daemon crash) via a long filename in a TFTP read (aka RRQ or get) request, a different vulnerability than CVE-2002-2226.

    Published: 20 Nov 2009
    4.3
    Medium

    CVE-2005-4883

    Last Modified: 23 Apr 2026

    Race condition in Philippe Jounin Tftpd32 before 2.80 allows remote attackers to cause a denial of service (daemon crash) via invalid "connect frames."

    Published: 20 Nov 2009
    4.3
    Medium

    CVE-2009-4043

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via a node title.

    Published: 20 Nov 2009
    7.5
    High

    CVE-2009-4037

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/db/users_db.inc, and various other .inc and .php files under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, and (7) purchasing/.

    Published: 20 Nov 2009
    7.5
    High

    CVE-2009-4045

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7) sales/view/, (8) taxes/, and (9) taxes/db/.

    Published: 20 Nov 2009
    7.5
    High

    CVE-2009-4046

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) bank_accounts.php, (2) currencies.php, (3) exchange_rates.php, (4) gl_account_types.php, and (5) gl_accounts.php in gl/manage/; and (6) audit_trail_db.inc, (7) comments_db.inc, (8) inventory_db.inc, (9) manufacturing_db.inc, and (10) references_db.inc in includes/db/.

    Published: 20 Nov 2009
    6.8
    Medium

    CVE-2009-3895

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif 0.6.18 allows remote attackers to cause a denial of service or possibly execute arbitrary code via an invalid EXIF image. NOTE: some of these details are obtained from third party information.

    Published: 20 Nov 2009
    10
    Critical

    CVE-2009-3842

    Last Modified: 23 Apr 2026

    Unspecified vulnerability on the HP Color LaserJet M3530 Multifunction Printer with firmware 05.058.4 and the Color LaserJet CP3525 Printer with firmware 53.021.2 allows remote attackers to obtain "access to data" or cause a denial of service via unknown vectors.

    Published: 20 Nov 2009
    10
    Critical

    CVE-2009-4006

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.

    Published: 20 Nov 2009
    7.8
    High

    CVE-2009-4004

    Last Modified: 23 Apr 2026

    Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc7 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via a KVM_X86_SETUP_MCE IOCTL request that specifies a large number of Machine Check Exception (MCE) banks.

    Published: 20 Nov 2009
    5.8
    Medium

    CVE-2009-4151

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages "HTTP access to the RT server," a related issue to CVE-2009-3585.

    Published: 20 Nov 2009
    5.8
    Medium

    CVE-2009-3585

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web sessions by setting the session identifier via a manipulation that leverages a second web server within the same domain.

    Published: 20 Nov 2009
    5.5
    Medium

    CVE-2009-3897

    Last Modified: 23 Apr 2026

    Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbitrary user accounts by replacing the auth socket, related to the parent directories of the base_dir directory, and possibly the base_dir directory itself.

    Published: 20 Nov 2009
    5
    Medium

    CVE-2009-4017

    Last Modified: 23 Apr 2026

    PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

    Published: 20 Nov 2009