CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-3449

    Last Modified: 23 Apr 2026

    MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file.

    Published: 29 Sept 2009
    4.3
    Medium

    CVE-2009-3450

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow remote attackers to inject arbitrary web script or HTML via parameters with names beginning with __ (underscore underscore) sequences, which are incompatible with an XSS protection mechanism provided by Microsoft ASP.NET.

    Published: 29 Sept 2009
    5
    Medium

    CVE-2009-3451

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 29 Sept 2009
    5
    Medium

    CVE-2009-3452

    Last Modified: 23 Apr 2026

    WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.

    Published: 29 Sept 2009
    7.5
    High

    CVE-2009-3434

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Tupinambis (com_tupinambis) component 1.0 for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the proyecto parameter in a verproyecto action to index.php.

    Published: 28 Sept 2009
    4.3
    Medium

    CVE-2009-3435

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a variable name.

    Published: 28 Sept 2009
    7.5
    High

    CVE-2009-3436

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.

    Published: 28 Sept 2009
    4.3
    Medium

    CVE-2009-3437

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the live preview feature in the Markdown Preview module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via "Markdown input."

    Published: 28 Sept 2009
    5
    Medium

    CVE-2009-3442

    Last Modified: 23 Apr 2026

    The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 28 Sept 2009
    7.5
    High

    CVE-2009-3443

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Fastball (com_fastball) component 1.1.0 through 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the league parameter to index.php.

    Published: 28 Sept 2009
    4.3
    Medium

    CVE-2009-3444

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in email.php in e107 0.7.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header in a news.1 (aka news to email) action.

    Published: 28 Sept 2009
    7.5
    High

    CVE-2009-3438

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomlaFacebook (com_facebook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a student action to index.php.

    Published: 28 Sept 2009
    6.5
    Medium

    CVE-2009-3439

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Open Source Security Information Management (OSSIM) before 2.1.2 allow remote authenticated users to execute arbitrary SQL commands via the id_document parameter to (1) repository_document.php, (2) repository_links.php, and (3) repository_editdocument.php in repository/; the (4) group parameter to policy/getpolicy.php; the name parameter to (5) host/newhostgroupform.php and (6) net/modifynetform.php; and unspecified other vectors related to the policy menu.

    Published: 28 Sept 2009
    4.3
    Medium

    CVE-2009-3440

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the option parameter to the default URI (aka the main menu).

    Published: 28 Sept 2009
    5
    Medium

    CVE-2009-3441

    Last Modified: 23 Apr 2026

    Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure information, via a direct request to (1) graphs/alarms_events.php or (2) host/draw_tree.php.

    Published: 28 Sept 2009
    5
    Medium

    CVE-2009-3445

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command.

    Published: 28 Sept 2009
    7.5
    High

    CVE-2009-3446

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MyRemote Video Gallery (com_mytube) component 1.0 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a videos action to index.php.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2866

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2 through 12.4 allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet, aka Bug ID CSCsz38104.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2867

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4T, 12.4XZ, and 12.4YA, when Zone-Based Policy Firewall SIP Inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted SIP transit packet, aka Bug ID CSCsr18691.

    Published: 28 Sept 2009
    7.1
    High

    CVE-2009-2863

    Last Modified: 23 Apr 2026

    Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypass the consent web page, via a crafted request, aka Bug ID CSCsy15227.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2871

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when SSLVPN sessions, SSH sessions, or IKE encrypted nonces are enabled, allows remote attackers to cause a denial of service (device reload) via a crafted encrypted packet, aka Bug ID CSCsq24002.

    Published: 28 Sept 2009
    7.1
    High

    CVE-2009-2873

    Last Modified: 23 Apr 2026

    Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via malformed packets, aka Bug ID CSCsx70889.

    Published: 28 Sept 2009
    7.2
    High

    CVE-2009-3433

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in clsetup in the configuration utility in Sun Solaris Cluster 3.2 allows local users to gain privileges via unknown vectors.

    Published: 28 Sept 2009
    7.6
    High

    CVE-2009-2865

    Last Modified: 23 Apr 2026

    Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.

    Published: 28 Sept 2009
    6.8
    Medium

    CVE-2009-2872

    Last Modified: 23 Apr 2026

    Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2868

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.

    Published: 28 Sept 2009
    4.3
    Medium

    CVE-2009-2862

    Last Modified: 23 Apr 2026

    The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47076, CSCsv48603, CSCsy54122, and CSCsu50252.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2864

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2869

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2XNA, 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to cause a denial of service (device reload) via a crafted NTPv4 packet, aka Bug IDs CSCsu24505 and CSCsv75948.

    Published: 28 Sept 2009
    7.8
    High

    CVE-2009-2870

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when the Cisco Unified Border Element feature is enabled, allows remote attackers to cause a denial of service (device reload) via crafted SIP messages, aka Bug ID CSCsx25880.

    Published: 28 Sept 2009
    1.9
    Low

    CVE-2009-3432

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in xscreensaver in Sun Solaris 10, and OpenSolaris before snv_112, when Xorg or Xnewt is used and RandR is enabled, allows physically proximate attackers to read a locked screen via unknown vectors related to XRandR resize events.

    Published: 28 Sept 2009
    7.1
    High

    CVE-2009-3939

    Last Modified: 23 Apr 2026

    The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file.

    Published: 28 Sept 2009
    6.6
    Medium

    CVE-2009-3889

    Last Modified: 23 Apr 2026

    The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file.

    Published: 28 Sept 2009
    3.3
    Low

    CVE-2009-4193

    Last Modified: 23 Apr 2026

    Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.

    Published: 27 Sept 2009
    4.3
    Medium

    CVE-2009-5067

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot dot) in the "include file" SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices.

    Published: 27 Sept 2009
    6.8
    Medium

    CVE-2009-5016

    Last Modified: 11 Apr 2025

    Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string that uses overlong UTF-8 encoding, a different vulnerability than CVE-2010-3870.

    Published: 27 Sept 2009
    6.8
    Medium

    CVE-2010-3870

    Last Modified: 11 Apr 2025

    The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass cross-site scripting (XSS) and SQL injection protection mechanisms via a crafted string.

    Published: 27 Sept 2009
    5
    Medium

    CVE-2009-3431

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and earlier 8.x versions; and possibly 7.1.4 and earlier 7.x versions allows remote attackers to cause a denial of service (application crash) via a PDF file with a large number of [ (open square bracket) characters in the argument to the alert method. NOTE: some of these details are obtained from third party information.

    Published: 25 Sept 2009
    6.5
    Medium

    CVE-2009-3418

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL commands via the m parameter to manager/index.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit_link action to manager/tools.php. NOTE: some of these details are obtained from third party information.

    Published: 25 Sept 2009
    7.5
    High

    CVE-2009-3419

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbitrary SQL commands via the historymonth parameter.

    Published: 25 Sept 2009
    6.8
    Medium

    CVE-2009-3422

    Last Modified: 23 Apr 2026

    login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Published: 25 Sept 2009
    6.8
    Medium

    CVE-2009-3426

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers to execute arbitrary PHP code via a URL in the fm_includes_special parameter.

    Published: 25 Sept 2009
    4.3
    Medium

    CVE-2009-3427

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote attackers to inject arbitrary web script or HTML via the subject field in a ticket.

    Published: 25 Sept 2009
    9.3
    Critical

    CVE-2009-3428

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file.

    Published: 25 Sept 2009
    9.3
    Critical

    CVE-2009-3429

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code via a long string in a .pls playlist file.

    Published: 25 Sept 2009
    6.8
    Medium

    CVE-2009-3423

    Last Modified: 23 Apr 2026

    login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Published: 25 Sept 2009
    7.5
    High

    CVE-2009-3430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Allomani Mobile 2.5 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Published: 25 Sept 2009
    7.5
    High

    CVE-2009-3417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action to index.php, a different vector than CVE-2008-2627.

    Published: 25 Sept 2009
    4.3
    Medium

    CVE-2009-3420

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote attackers to inject arbitrary web script or HTML via the (1) begin parameter and the (2) PATH_INFO.

    Published: 25 Sept 2009
    9.8
    Critical

    CVE-2009-3421

    Last Modified: 23 Apr 2026

    login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by setting the login_ok parameter to 1.

    Published: 25 Sept 2009