CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-3325

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3326

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.

    Published: 23 Sept 2009
    6.8
    Medium

    CVE-2009-3330

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3332

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3334

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.

    Published: 23 Sept 2009
    9.3
    Critical

    CVE-2009-3329

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Winplot 1.25.0.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Plot2D (.wp2) file.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3319

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a sec list action, a different vector than CVE-2006-1018.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3323

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path parameter to (2) lib_users.php, (3) lib_stats.php, and (4) lib_slots.php in include/lib/.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3309

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3318

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3327

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3331

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submitted.php, and (4) autosubmitter/index.php.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3333

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3307

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3310

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action.

    Published: 23 Sept 2009
    4.3
    Medium

    CVE-2009-3311

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 23 Sept 2009
    6.8
    Medium

    CVE-2009-3312

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3316

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.

    Published: 23 Sept 2009
    4.3
    Medium

    CVE-2009-3320

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 23 Sept 2009
    4.3
    Medium

    CVE-2009-3328

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.

    Published: 23 Sept 2009
    7.5
    High

    CVE-2009-3287

    Last Modified: 23 Apr 2026

    lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.

    Published: 22 Sept 2009
    4.3
    Medium

    CVE-2009-3283

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to cookies.

    Published: 22 Sept 2009
    5
    Medium

    CVE-2009-3284

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 22 Sept 2009
    4.9
    Medium

    CVE-2009-3288

    Last Modified: 23 Apr 2026

    The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstrated by using xcdroast to duplicate a CD. NOTE: this is only exploitable by users who can open the cdrom device.

    Published: 22 Sept 2009
    5
    Medium

    CVE-2009-3294

    Last Modified: 23 Apr 2026

    The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows operating systems, allows context-dependent attackers to cause a denial of service (crash) via a crafted (1) "e" or (2) "er" string in the second argument (aka mode), possibly related to the _fdopen function in the Microsoft C runtime library. NOTE: this might not cross privilege boundaries except in rare cases in which the mode argument is accessible to an attacker outside of an application that uses the popen function.

    Published: 22 Sept 2009
    4.9
    Medium

    CVE-2009-2908

    Last Modified: 23 Apr 2026

    The d_delete function in fs/ecryptfs/inode.c in eCryptfs in the Linux kernel 2.6.31 allows local users to cause a denial of service (kernel OOPS) and possibly execute arbitrary code via unspecified vectors that cause a "negative dentry" and trigger a NULL pointer dereference, as demonstrated via a Mutt temporary directory in an eCryptfs mount.

    Published: 22 Sept 2009
    7.8
    High

    CVE-2009-2744

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."

    Published: 21 Sept 2009
    4.3
    Medium

    CVE-2009-3271

    Last Modified: 23 Apr 2026

    Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.

    Published: 21 Sept 2009
    5
    Medium

    CVE-2009-3277

    Last Modified: 23 Apr 2026

    DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of an [ (open bracket) followed by many commas, related to a certain regular expression, aka a "ReDoS" vulnerability.

    Published: 21 Sept 2009
    6.9
    Medium

    CVE-2009-2939

    Last Modified: 23 Apr 2026

    The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files.

    Published: 21 Sept 2009
    5.5
    Medium

    CVE-2009-3278

    Last Modified: 23 Apr 2026

    The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.

    Published: 21 Sept 2009
    5.9
    Medium

    CVE-2009-3200

    Last Modified: 23 Apr 2026

    The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK variable in flash memory, which allows local users to bypass the passphrase requirement and decrypt the hard drive by reading this variable, deobfuscating the key, and running a cryptsetup luksOpen command.

    Published: 21 Sept 2009
    4.9
    Medium

    CVE-2009-3279

    Last Modified: 23 Apr 2026

    The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using the AES-256 cipher in plain CBC mode, which allows local users to obtain sensitive information via a watermark attack.

    Published: 21 Sept 2009
    5
    Medium

    CVE-2009-3272

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences.

    Published: 21 Sept 2009
    9.3
    Critical

    CVE-2009-2140

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allow remote attackers to execute arbitrary code via a crafted EMF+ file, a similar issue to CVE-2008-2238.

    Published: 21 Sept 2009
    4.3
    Medium

    CVE-2009-2742

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.

    Published: 21 Sept 2009
    2.1
    Low

    CVE-2009-2743

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.

    Published: 21 Sept 2009
    7.5
    High

    CVE-2009-3273

    Last Modified: 23 Apr 2026

    iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate.

    Published: 21 Sept 2009
    5
    Medium

    CVE-2009-3275

    Last Modified: 23 Apr 2026

    Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many \ (backslash) characters followed by a " (double quote), related to a certain regular expression, aka a "ReDoS" vulnerability.

    Published: 21 Sept 2009
    5
    Medium

    CVE-2009-3276

    Last Modified: 23 Apr 2026

    Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.

    Published: 21 Sept 2009
    7.8
    High

    CVE-2009-3280

    Last Modified: 23 Apr 2026

    Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel before 2.6.31.1-rc1 allows remote attackers to cause a denial of service (soft lockup) via malformed packets.

    Published: 21 Sept 2009
    5
    Medium

    CVE-2008-7245

    Last Modified: 23 Apr 2026

    Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Published: 18 Sept 2009
    5
    Medium

    CVE-2008-7246

    Last Modified: 23 Apr 2026

    Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3263

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as XML "active content."

    Published: 18 Sept 2009
    5
    Medium

    CVE-2009-3267

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.

    Published: 18 Sept 2009
    5
    Medium

    CVE-2009-3268

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828.

    Published: 18 Sept 2009
    5
    Medium

    CVE-2009-3269

    Last Modified: 23 Apr 2026

    Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic submissions of a form containing a KEYGEN element, a related issue to CVE-2009-1828.

    Published: 18 Sept 2009
    5
    Medium

    CVE-2009-3270

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3265

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the vendor reportedly considers this behavior a "design feature," not a vulnerability.

    Published: 18 Sept 2009
    10
    Critical

    CVE-2009-2741

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and 6.2 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 18 Sept 2009