CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2009-3562

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.

    Published: 5 Oct 2009
    5
    Medium

    CVE-2009-3561

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.

    Published: 5 Oct 2009
    7.8
    High

    CVE-2009-2679

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.

    Published: 5 Oct 2009
    9.3
    Critical

    CVE-2009-3829

    Last Modified: 23 Apr 2026

    Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."

    Published: 5 Oct 2009
    7.5
    High

    CVE-2009-2699

    Last Modified: 23 Apr 2026

    The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs.

    Published: 5 Oct 2009
    7.2
    High

    CVE-2010-0297

    Last Modified: 11 Apr 2025

    Buffer overflow in the usb_host_handle_control function in the USB passthrough handling implementation in usb-linux.c in QEMU before 0.11.1 allows guest OS users to cause a denial of service (guest OS crash or hang) or possibly execute arbitrary code on the host OS via a crafted USB packet.

    Published: 4 Oct 2009
    7.2
    High

    CVE-2009-3638

    Last Modified: 23 Apr 2026

    Integer overflow in the kvm_dev_ioctl_get_supported_cpuid function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux kernel before 2.6.31.4 allows local users to have an unspecified impact via a KVM_GET_SUPPORTED_CPUID request to the kvm_arch_dev_ioctl function.

    Published: 4 Oct 2009
    6.8
    Medium

    CVE-2009-3529

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than CVE-2005-1074.

    Published: 2 Oct 2009
    4.3
    Medium

    CVE-2009-3530

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3531

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3532

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information.

    Published: 2 Oct 2009
    9.3
    Critical

    CVE-2009-3537

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in EpicDJSoftware EpicDJ 1.3.9.1 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3538

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Oct 2009
    4.3
    Medium

    CVE-2009-3539

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3541

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter.

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3543

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3533

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Oct 2009
    4.3
    Medium

    CVE-2009-3535

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the researcher also suggests an analogous PHP remote file inclusion vulnerability, but this may be incorrect.

    Published: 2 Oct 2009
    6.8
    Medium

    CVE-2009-3534

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Published: 2 Oct 2009
    4.3
    Medium

    CVE-2009-3540

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Oct 2009
    7.5
    High

    CVE-2009-3542

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 2 Oct 2009
    6.5
    Medium

    CVE-2009-3528

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.

    Published: 2 Oct 2009
    9.3
    Critical

    CVE-2009-3536

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.

    Published: 2 Oct 2009
    2.1
    Low

    CVE-2009-3554

    Last Modified: 23 Apr 2026

    Twiddle in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 writes the JMX password, and other command-line arguments, to the twiddle.log file, which allows local users to obtain sensitive information by reading this file.

    Published: 2 Oct 2009
    4.9
    Medium

    CVE-2009-2909

    Last Modified: 23 Apr 2026

    Integer signedness error in the ax25_setsockopt function in net/ax25/af_ax25.c in the ax25 subsystem in the Linux kernel before 2.6.31.2 allows local users to cause a denial of service (OOPS) via a crafted optlen value in an SO_BINDTODEVICE operation.

    Published: 2 Oct 2009
    3.5
    Low

    CVE-2009-3648

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated users, with 'administer content types' permissions, to inject arbitrary web script or HTML via unspecified vectors when displaying content type names.

    Published: 2 Oct 2009
    4.3
    Medium

    CVE-2009-3521

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Oct 2009
    7.2
    High

    CVE-2009-3522

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.

    Published: 1 Oct 2009
    6.9
    Medium

    CVE-2009-3523

    Last Modified: 23 Apr 2026

    aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

    Published: 1 Oct 2009
    7.2
    High

    CVE-2009-3524

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors.

    Published: 1 Oct 2009
    6.4
    Medium

    CVE-2009-0209

    Last Modified: 23 Apr 2026

    PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers to read or modify information in databases via unspecified vectors.

    Published: 1 Oct 2009
    7.2
    High

    CVE-2009-3516

    Last Modified: 23 Apr 2026

    gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.

    Published: 1 Oct 2009
    8.8
    High

    CVE-2009-3520

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.

    Published: 1 Oct 2009
    9.3
    Critical

    CVE-2009-3518

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.

    Published: 1 Oct 2009
    10
    Critical

    CVE-2009-3517

    Last Modified: 23 Apr 2026

    nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.

    Published: 1 Oct 2009
    4.9
    Medium

    CVE-2009-3519

    Last Modified: 23 Apr 2026

    Multiple memory leaks in the IP module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_109, allow local users to cause a denial of service (memory consumption) via vectors related to (1) M_DATA, (2) M_PROTO, (3) M_PCPROTO, and (4) M_SIG STREAMS messages.

    Published: 1 Oct 2009
    4.3
    Medium

    CVE-2009-3506

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.

    Published: 1 Oct 2009
    4.3
    Medium

    CVE-2009-3512

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.

    Published: 1 Oct 2009
    6.5
    Medium

    CVE-2009-3514

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.

    Published: 1 Oct 2009
    6.5
    Medium

    CVE-2009-3515

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter.

    Published: 1 Oct 2009
    7.5
    High

    CVE-2009-3507

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules.php in CMSphp 0.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod_file parameter.

    Published: 1 Oct 2009
    7.5
    High

    CVE-2009-3510

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.

    Published: 1 Oct 2009
    4.3
    Medium

    CVE-2009-3513

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php.

    Published: 1 Oct 2009
    4.3
    Medium

    CVE-2009-3509

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/admin_index.php in CJ Dynamic Poll PRO 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 1 Oct 2009
    6
    Medium

    CVE-2009-3508

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and the (2) url parameter to install/install.php; and allow remote authenticated administrators to read arbitrary files via a .. (dot dot) in the (3) _htmlfile parameter to admin.php.

    Published: 1 Oct 2009
    7.5
    High

    CVE-2009-3511

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php.

    Published: 1 Oct 2009
    2.1
    Low

    CVE-2009-5066

    Last Modified: 11 Apr 2025

    twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.

    Published: 1 Oct 2009
    1.9
    Low

    CVE-2009-2948

    Last Modified: 23 Apr 2026

    mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is installed suid root, does not properly enforce permissions, which allows local users to read part of the credentials file and obtain the password by specifying the path to the credentials file and using the --verbose or -v option.

    Published: 1 Oct 2009
    4
    Medium

    CVE-2009-2906

    Last Modified: 23 Apr 2026

    smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated users to cause a denial of service (infinite loop) via an unanticipated oplock break notification reply packet.

    Published: 1 Oct 2009
    2.1
    Low

    CVE-2009-2910

    Last Modified: 23 Apr 2026

    arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.

    Published: 1 Oct 2009