CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-3830

    Last Modified: 23 Apr 2026

    The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.

    Published: 30 Oct 2009
    9.3
    Critical

    CVE-2009-3831

    Last Modified: 23 Apr 2026

    Opera before 10.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted domain name.

    Published: 30 Oct 2009
    5
    Medium

    CVE-2009-3828

    Last Modified: 23 Apr 2026

    The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.

    Published: 30 Oct 2009
    4.6
    Medium

    CVE-2010-0299

    Last Modified: 11 Apr 2025

    openSUSE 11.2 installs the devtmpfs root directory with insecure permissions (1777), which allows local users to gain privileges via unspecified vectors.

    Published: 30 Oct 2009
    10
    Critical

    CVE-2009-3371

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

    Published: 29 Oct 2009
    10
    Critical

    CVE-2009-3381

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 29 Oct 2009
    4.9
    Medium

    CVE-2009-3640

    Last Modified: 23 Apr 2026

    The update_cr8_intercept function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.32-rc1 does not properly handle the absence of an Advanced Programmable Interrupt Controller (APIC), which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via a call to the kvm_vcpu_ioctl function.

    Published: 29 Oct 2009
    10
    Critical

    CVE-2009-3383

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 29 Oct 2009
    9.3
    Critical

    CVE-2009-3378

    Last Modified: 23 Apr 2026

    The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.

    Published: 29 Oct 2009
    5
    Medium

    CVE-2009-3626

    Last Modified: 23 Apr 2026

    Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.

    Published: 29 Oct 2009
    4.3
    Medium

    CVE-2009-3978

    Last Modified: 23 Apr 2026

    The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.

    Published: 29 Oct 2009
    6.8
    Medium

    CVE-2009-4067

    Last Modified: 21 Nov 2024

    Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafted USB device, or take full control of the system.

    Published: 29 Oct 2009
    4.3
    Medium

    CVE-2009-3816

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Activities pages in the Mobile subsystem in IBM Lotus Connections 2.5.0.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2009
    7.5
    High

    CVE-2009-3820

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Flagbit Filebase (fb_filebase) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Oct 2009
    4.3
    Medium

    CVE-2009-3821

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Apache Solr Search (solr) extension 1.0.0 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2009
    4.3
    Medium

    CVE-2009-3823

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.

    Published: 28 Oct 2009
    7.5
    High

    CVE-2009-3824

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.

    Published: 28 Oct 2009
    7.5
    High

    CVE-2009-3825

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.

    Published: 28 Oct 2009
    10
    Critical

    CVE-2009-3818

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the session handling feature in freeCap CAPTCHA (sr_freecap) extension 1.2.0 and earlier for TYPO3 has unknown impact and attack vectors.

    Published: 28 Oct 2009
    7.5
    High

    CVE-2009-3822

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.

    Published: 28 Oct 2009
    7.5
    High

    CVE-2009-3817

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than CVE-2009-2637. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Oct 2009
    10
    Critical

    CVE-2009-3819

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Random Images (maag_randomimage) extension 1.6.4 and earlier for TYPO3 allows remote attackers to execute arbitrary shell commands via unspecified vectors.

    Published: 28 Oct 2009
    7.5
    High

    CVE-2009-3801

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Oct 2009
    4.3
    Medium

    CVE-2009-3805

    Last Modified: 23 Apr 2026

    gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certificate signature.

    Published: 27 Oct 2009
    7.5
    High

    CVE-2009-3806

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3807

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3808

    Last Modified: 23 Apr 2026

    MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3812

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.

    Published: 27 Oct 2009
    6.5
    Medium

    CVE-2009-3813

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via the (1) forum parameter to modules/forum/post.php and possibly (2) forum_id variable to modules/forum/class/class.permissions.php.

    Published: 27 Oct 2009
    6.5
    Medium

    CVE-2009-3814

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in RunCMS 2M1 allows remote authenticated administrators to execute arbitrary PHP code via the "Filter/Banning" feature, as demonstrated by modifying modules/system/cache/bademails.php using the "Prohibited: Emails" action, and other unspecified filters.

    Published: 27 Oct 2009
    5
    Medium

    CVE-2009-3815

    Last Modified: 23 Apr 2026

    RunCMS 2M1, when running with certain error_reporting levels, allows remote attackers to obtain sensitive information via (1) the op[] parameter to modules/contact/index.php or (2) uid[] parameter to userinfo.php, which leaks the installation path in an error message when these parameters are used in a call to the preg_match function.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3810

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.

    Published: 27 Oct 2009
    4.3
    Medium

    CVE-2009-3809

    Last Modified: 23 Apr 2026

    Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file.

    Published: 27 Oct 2009
    5
    Medium

    CVE-2009-3802

    Last Modified: 23 Apr 2026

    Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.

    Published: 27 Oct 2009
    4.3
    Medium

    CVE-2009-3803

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message body of a (21) forum, (22) guestbook, or (23) comment; (24) the content of an avatar file, which is not properly handled by Internet Explorer; and (25) the loginname parameter (aka username) in _admin/index.php.

    Published: 27 Oct 2009
    6.5
    Medium

    CVE-2009-3804

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3811

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information.

    Published: 27 Oct 2009
    10
    Critical

    CVE-2009-3373

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 27 Oct 2009
    10
    Critical

    CVE-2009-3379

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663.

    Published: 27 Oct 2009
    10
    Critical

    CVE-2009-3380

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3384

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a reply.

    Published: 27 Oct 2009
    6.8
    Medium

    CVE-2009-1563

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-0689. Reason: This candidate is a duplicate of CVE-2009-0689. Certain codebase relationships were not originally clear. Notes: All CVE users should reference CVE-2009-0689 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Oct 2009
    5
    Medium

    CVE-2010-1152

    Last Modified: 11 Apr 2025

    memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information.

    Published: 27 Oct 2009
    7.1
    High

    CVE-2009-3385

    Last Modified: 11 Apr 2025

    The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted remote attackers to obtain sensitive information via crafted content in an IFRAME element in an HTML e-mail message, as demonstrated by a Flash object that sends arbitrary local files during a reply or forward operation.

    Published: 27 Oct 2009
    4.3
    Medium

    CVE-2009-3375

    Last Modified: 23 Apr 2026

    content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3376

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

    Published: 27 Oct 2009
    10
    Critical

    CVE-2009-3382

    Last Modified: 23 Apr 2026

    layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 27 Oct 2009
    5
    Medium

    CVE-2009-3370

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.

    Published: 27 Oct 2009
    9.3
    Critical

    CVE-2009-3372

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

    Published: 27 Oct 2009
    7.5
    High

    CVE-2009-3374

    Last Modified: 23 Apr 2026

    The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

    Published: 27 Oct 2009