CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-3264

    Last Modified: 23 Apr 2026

    The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user's visit to a different web server that hosts an SVG document.

    Published: 18 Sept 2009
    4.6
    Medium

    CVE-2009-2793

    Last Modified: 23 Apr 2026

    The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the iret instruction, which might allow local users to gain privileges via vectors related to a tempEIP pseudocode variable that is outside of the code-segment limits.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3266

    Last Modified: 23 Apr 2026

    Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to conduct cross-site scripting (XSS) attacks, and conduct cross-zone scripting attacks involving the Feed Subscription Page to read feeds or create feed subscriptions, via a crafted feed, related to the rendering of the application/rss+xml content type as "scripted content."

    Published: 18 Sept 2009
    7.5
    High

    CVE-2009-3261

    Last Modified: 23 Apr 2026

    update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.

    Published: 18 Sept 2009
    3.5
    Low

    CVE-2009-3262

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 allows remote authenticated users to inject arbitrary web script or HTML via the last name field in a profile.

    Published: 18 Sept 2009
    3.6
    Low

    CVE-2009-3257

    Last Modified: 23 Apr 2026

    vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.

    Published: 18 Sept 2009
    9
    Critical

    CVE-2009-3258

    Last Modified: 23 Apr 2026

    vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) views, and (5) tickets; insert (6) attachments, (7) reports, (8) filters, (9) views, and (10) tickets; and edit (11) reports, (12) filters, (13) views, and (14) tickets via unspecified vectors.

    Published: 18 Sept 2009
    7.5
    High

    CVE-2009-3259

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in RASH Quote Management System (RQMS) 1.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the search parameter in a search action, (2) the quote parameter in a quote addition, or (3) a User_Name cookie in unspecified administrative actions. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3260

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment.

    Published: 18 Sept 2009
    7.5
    High

    CVE-2009-3246

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. NOTE: some of these details are obtained from third party information.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3247

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php. NOTE: the query_string vector is already covered by CVE-2008-3101.3.

    Published: 18 Sept 2009
    6.8
    Medium

    CVE-2009-3248

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.

    Published: 18 Sept 2009
    4
    Medium

    CVE-2009-3251

    Last Modified: 23 Apr 2026

    include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access restrictions and read the (1) visibility, (2) location, and (3) recurrence fields of a calendar via a custom view.

    Published: 18 Sept 2009
    9.3
    Critical

    CVE-2009-3253

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.

    Published: 18 Sept 2009
    9.3
    Critical

    CVE-2009-3254

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.

    Published: 18 Sept 2009
    7.5
    High

    CVE-2009-3252

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3256

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the URI, as demonstrated by a SCRIPT element in an arbitrary parameter such as the asd parameter.

    Published: 18 Sept 2009
    7.5
    High

    CVE-2009-3249

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter to graph.php; or the (2) module or (3) file parameter to include/Ajax/CommonAjax.php, reachable through modules/Campaigns/CampaignsAjax.php, modules/SalesOrder/SalesOrderAjax.php, modules/System/SystemAjax.php, modules/Products/ProductsAjax.php, modules/uploads/uploadsAjax.php, modules/Dashboard/DashboardAjax.php, modules/Potentials/PotentialsAjax.php, modules/Notes/NotesAjax.php, modules/Faq/FaqAjax.php, modules/Quotes/QuotesAjax.php, modules/Utilities/UtilitiesAjax.php, modules/Calendar/ActivityAjax.php, modules/Calendar/CalendarAjax.php, modules/PurchaseOrder/PurchaseOrderAjax.php, modules/HelpDesk/HelpDeskAjax.php, modules/Invoice/InvoiceAjax.php, modules/Accounts/AccountsAjax.php, modules/Reports/ReportsAjax.php, modules/Contacts/ContactsAjax.php, and modules/Portal/PortalAjax.php; and allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the step parameter in an Import action to the (4) Accounts, (5) Contacts, (6) HelpDesk, (7) Leads, (8) Potentials, (9) Products, or (10) Vendors module, reachable through index.php and related to modules/Import/index.php and multiple Import.php files.

    Published: 18 Sept 2009
    9
    Critical

    CVE-2009-3250

    Last Modified: 23 Apr 2026

    The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.

    Published: 18 Sept 2009
    6.8
    Medium

    CVE-2009-3255

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.

    Published: 18 Sept 2009
    Unknown

    CVE-2009-3239

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2139, CVE-2009-2140. Reason: This candidate is a duplicate of CVE-2009-2139 and CVE-2009-2140. Notes: All CVE users should reference CVE-2009-2139 and CVE-2009-2140 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Sept 2009
    9.3
    Critical

    CVE-2009-3244

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-2937

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed.

    Published: 18 Sept 2009
    4.3
    Medium

    CVE-2009-3240

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Happy Linux XF-Section module 1.12a for XOOPS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2009
    5
    Medium

    CVE-2009-3243

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.

    Published: 18 Sept 2009
    3.3
    Low

    CVE-2009-4664

    Last Modified: 11 Apr 2025

    Firewall Builder 3.0.4, 3.0.5, and 3.0.6, when running on Linux, allows local users to gain privileges via a symlink attack on an unspecified temporary file that is created by the iptables script.

    Published: 18 Sept 2009
    4.9
    Medium

    CVE-2009-2707

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterprise (SLE) 10 SP2 on Itanium IA64 machines allows local users to cause a denial of service (system crash) via a 32-bit x86 application.

    Published: 18 Sept 2009
    7.5
    High

    CVE-2008-7240

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and execute arbitrary local files via the template parameter.

    Published: 17 Sept 2009
    6.8
    Medium

    CVE-2008-7241

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in PunBB before 1.2.17 allows remote attackers to hijack the authentication of unspecified users for requests related to a logout, probably a forced logout.

    Published: 17 Sept 2009
    4.3
    Medium

    CVE-2008-7242

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.

    Published: 17 Sept 2009
    6.8
    Medium

    CVE-2008-7243

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in page 34 in MODx CMS 0.9.6.1 and 0.9.6.1p1 allows remote attackers to hijack the authentication of other users for requests that modify passwords via manager/index.php. NOTE: due to the lack of details, it is not clear whether this is related to CVE-2008-5941.

    Published: 17 Sept 2009
    7.2
    High

    CVE-2009-3233

    Last Modified: 23 Apr 2026

    changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack.

    Published: 17 Sept 2009
    4.9
    Medium

    CVE-2009-3234

    Last Modified: 23 Apr 2026

    Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.

    Published: 17 Sept 2009
    9.3
    Critical

    CVE-2009-3232

    Last Modified: 23 Apr 2026

    pam-auth-update for PAM, as used in Ubuntu 8.10 and 9.4, and Debian GNU/Linux, does not properly handle an "empty selection" for system authentication modules in certain rare configurations, which causes any attempt to be successful and allows remote attackers to bypass authentication.

    Published: 17 Sept 2009
    7.5
    High

    CVE-2009-3215

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allows remote attackers to execute arbitrary SQL commands via the parent parameter.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3216

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in iWiccle 1.01, when magic_quotes_gpc is disabled, allow remote attackers to read arbitrary files via a .. (dot dot) in (1) the show parameter to the admin module, reachable through index.php; or (2) the module parameter to index.php.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3217

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the admin module in iWiccle 1.01 allows remote attackers to execute arbitrary SQL commands via the member_id parameter in an edit_user action to index.php.

    Published: 16 Sept 2009
    6.8
    Medium

    CVE-2009-3218

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 16 Sept 2009
    6.8
    Medium

    CVE-2009-3219

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3220

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cp_html2txt.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 16 Sept 2009
    9.3
    Critical

    CVE-2009-3221

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3226

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. NOTE: some of these details are obtained from third party information.

    Published: 16 Sept 2009
    6.5
    Medium

    CVE-2009-3223

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ppc-add-keywords.php in Inout Adserver allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Super Mod System, when using the 68 Classifieds 3.1 Core System, allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3222

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in FreeWebScriptz Honest Traffic (FWSHT) 1.x allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3225

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AlmondSoft Almond Classifieds Wap and Pro, and possibly Almond Affiliate Network Classifieds, allow remote attackers to inject arbitrary web script or HTML via (1) the page parameter in a browse action to index.php or (2) the addr parameter to gmap.php. NOTE: some of these details are obtained from third party information.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3227

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to inject arbitrary web script or HTML via the city parameter in a search action. NOTE: some of these details are obtained from third party information.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3204

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) demo.php and (2) forum.php, and the PATH_INFO to (3) include_forum.php.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3205

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_product action.

    Published: 16 Sept 2009
    6.8
    Medium

    CVE-2009-3207

    Last Modified: 23 Apr 2026

    The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote attackers to view arbitrary images via a request that specifies an image's filename.

    Published: 16 Sept 2009