CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2009-3080

    Last Modified: 23 Apr 2026

    Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request.

    Published: 20 Nov 2009
    5
    Medium

    CVE-2009-3840

    Last Modified: 23 Apr 2026

    The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service (daemon crash) via an invalid Error Code field in a packet.

    Published: 19 Nov 2009
    5
    Medium

    CVE-2009-3977

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in a certain ActiveX control in ActiveDom.ocx in HP OpenView Network Node Manager (OV NNM) 7.53 might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via a long string argument to the (1) DisplayName, (2) AddGroup, (3) InstallComponent, or (4) Subscribe method. NOTE: this issue is not a vulnerability in many environments, because the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.

    Published: 19 Nov 2009
    7.5
    High

    CVE-2009-3974

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) search_term parameter to admin/applications/core/modules_public/search/search.php and (2) aid parameter to admin/applications/core/modules_public/global/lostpass.php. NOTE: on 20090818, the vendor patched 3.0.2 without changing the version number.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3972

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.

    Published: 18 Nov 2009
    9.3
    Critical

    CVE-2009-3969

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3968

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid parameter to itechd.php. NOTE: the sellers_othersitem.php, classifieds.php, and shop.php vectors are already covered by CVE-2008-3238.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3964

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.

    Published: 18 Nov 2009
    6.5
    Medium

    CVE-2009-3970

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3971

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3973

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.

    Published: 18 Nov 2009
    6.8
    Medium

    CVE-2009-3975

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.

    Published: 18 Nov 2009
    9.3
    Critical

    CVE-2009-3976

    Last Modified: 23 Apr 2026

    Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3967

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3966

    Last Modified: 23 Apr 2026

    Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3965

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter.

    Published: 18 Nov 2009
    4.3
    Medium

    CVE-2009-4363

    Last Modified: 23 Apr 2026

    Text_Filter/lib/Horde/Text/Filter/Xss.php in Horde Application Framework before 3.3.6, Horde Groupware before 1.2.5, and Horde Groupware Webmail Edition before 1.2.5 does not properly handle data: URIs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via data:text/html values for the HREF attribute of an A element in an HTML e-mail message. NOTE: the vendor states that the issue is caused by "an XSS vulnerability in Firefox browsers."

    Published: 18 Nov 2009
    5
    Medium

    CVE-2009-3386

    Last Modified: 23 Apr 2026

    Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) Depends On or (2) Blocks field of a related bug.

    Published: 18 Nov 2009
    7.5
    High

    CVE-2009-3963

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.

    Published: 17 Nov 2009
    7.8
    High

    CVE-2009-3962

    Last Modified: 23 Apr 2026

    The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program on TCP port 50001, a related issue to CVE-2006-4523.

    Published: 17 Nov 2009
    9
    Critical

    CVE-2009-3841

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 17 Nov 2009
    7.5
    High

    CVE-2009-3961

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote attackers to execute arbitrary SQL commands via the uid parameter, related to an "incorrect regexp." NOTE: some of these details are obtained from third party information.

    Published: 17 Nov 2009
    6
    Medium

    CVE-2009-3890

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.

    Published: 17 Nov 2009
    3.5
    Low

    CVE-2009-3891

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticated users to inject arbitrary web script or HTML via the s parameter (aka the selection variable).

    Published: 17 Nov 2009
    9.3
    Critical

    CVE-2009-3909

    Last Modified: 23 Apr 2026

    Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow.

    Published: 17 Nov 2009
    7.5
    High

    CVE-2009-3949

    Last Modified: 23 Apr 2026

    cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.

    Published: 16 Nov 2009
    4.3
    Medium

    CVE-2009-3950

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to newprofile.html; the (2) firstname, (3) lastname, and (4) company parameters to signup/signup.html; and the (5) firstname, (6) lastname, and (7) address[0].street1 parameters to contact.html.

    Published: 16 Nov 2009
    4.3
    Medium

    CVE-2009-3948

    Last Modified: 23 Apr 2026

    JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at the end of a .wav file.

    Published: 16 Nov 2009
    9.3
    Critical

    CVE-2009-3947

    Last Modified: 23 Apr 2026

    Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many space characters.

    Published: 16 Nov 2009
    5
    Medium

    CVE-2009-3946

    Last Modified: 23 Apr 2026

    Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's version number, via a direct request.

    Published: 16 Nov 2009
    5.5
    Medium

    CVE-2009-3945

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote authenticated users, with Author privileges, to replace the articles of an arbitrary user via unknown vectors.

    Published: 16 Nov 2009
    5
    Medium

    CVE-2009-3943

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.

    Published: 16 Nov 2009
    4.9
    Medium

    CVE-2009-3888

    Last Modified: 23 Apr 2026

    The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory.

    Published: 16 Nov 2009
    Unknown

    CVE-2008-4826

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-3853. Reason: This candidate is a duplicate of CVE-2009-3853. Notes: All CVE users should reference CVE-2009-3853 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Nov 2009
    6.8
    Medium

    CVE-2009-2746

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.39, 6.1 before 6.1.0.29, and 7.0 before 7.0.0.7 allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 16 Nov 2009
    2.1
    Low

    CVE-2009-3940

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and Sun VirtualBox before 3.0.10, allows guest OS users to cause a denial of service (memory consumption) on the guest OS via unknown vectors.

    Published: 16 Nov 2009
    5
    Medium

    CVE-2009-3944

    Last Modified: 23 Apr 2026

    Research In Motion (RIM) BlackBerry Browser on the BlackBerry 8800 allows remote attackers to cause a denial of service (application hang) via a JavaScript loop that configures the home page by using the setHomePage method and a DHTML behavior property.

    Published: 16 Nov 2009
    6.9
    Medium

    CVE-2009-3736

    Last Modified: 23 Apr 2026

    ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.

    Published: 16 Nov 2009
    4.3
    Medium

    CVE-2009-3892

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and other 3.4.6 through 3.8.4 versions allows remote attackers to inject arbitrary web script or HTML via certain Custom Fields.

    Published: 14 Nov 2009
    5.8
    Medium

    CVE-2009-3936

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Receiver for iPhone before 1.0.3, and ICA Java, Mac, UNIX, and Windows Clients for XenApp and XenDesktop allows remote attackers to impersonate the SSL/TLS server and bypass authentication via a crafted certificate, a different vulnerability than CVE-2009-3555.

    Published: 13 Nov 2009
    4.9
    Medium

    CVE-2009-3937

    Last Modified: 23 Apr 2026

    Memory leak in Solaris TCP sockets in Sun OpenSolaris snv_106 through snv_126 allows local users to cause a denial of service (kernel memory consumption) via unspecified vectors involving tcp_sendmsg processing "ancillary data."

    Published: 13 Nov 2009
    4
    Medium

    CVE-2009-2678

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Open System Services (OSS) Name Server on HP NonStop G06.27, G06.28, G06.29, G06.30, H06.06, H06.07, H06.08, and J06.03 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 13 Nov 2009
    4.3
    Medium

    CVE-2009-3565

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.

    Published: 13 Nov 2009
    4.3
    Medium

    CVE-2009-3566

    Last Modified: 23 Apr 2026

    McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.

    Published: 13 Nov 2009
    4.3
    Medium

    CVE-2009-2842

    Last Modified: 23 Apr 2026

    Apple Safari before 4.0.4 does not properly implement certain (1) Open Image and (2) Open Link menu options, which allows remote attackers to read local HTML files via a crafted web site.

    Published: 13 Nov 2009
    7.1
    High

    CVE-2009-3676

    Last Modified: 23 Apr 2026

    The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a) an incorrect length value in a NetBIOS header or (b) an additional length field at the end of this response packet, aka "SMB Client Incomplete Response Vulnerability."

    Published: 13 Nov 2009
    6.8
    Medium

    CVE-2007-5475

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Marvell wireless driver, as used in Linksys WAP4400N Wi-Fi access point with firmware 1.2.17 on the Marvell 88W8361P-BEM1 chipset, and other products, allow remote 802.11-authenticated users to cause a denial of service (wireless access point crash) and possibly execute arbitrary code via an association request with long (1) rates, (2) extended rates, and unspecified other information elements.

    Published: 12 Nov 2009
    5.5
    Medium

    CVE-2009-0052

    Last Modified: 23 Apr 2026

    The Atheros wireless driver, as used in Netgear WNDAP330 Wi-Fi access point with firmware 2.1.11 and other versions before 3.0.3 on the Atheros AR9160-BC1A chipset, and other products, allows remote authenticated users to cause a denial of service (device reboot or hang) and possibly execute arbitrary code via a truncated reserved management frame.

    Published: 12 Nov 2009
    7.5
    High

    CVE-2009-3548

    Last Modified: 23 Apr 2026

    The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

    Published: 12 Nov 2009
    4.3
    Medium

    CVE-2009-3934

    Last Modified: 23 Apr 2026

    The WebFrameLoaderClient::dispatchDidChangeLocationWithinPage function in src/webkit/glue/webframeloaderclient_impl.cc in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service via a page-local link, related to an "empty redirect chain," as demonstrated by a message in Yahoo! Mail.

    Published: 12 Nov 2009