CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-3203

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Sept 2009
    6.8
    Medium

    CVE-2009-3211

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the options[style_dir] parameter to the default URI.

    Published: 16 Sept 2009
    6.8
    Medium

    CVE-2009-3212

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3209

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 16 Sept 2009
    3.5
    Low

    CVE-2009-3206

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated users, with "administer imagecache" permissions, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3208

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to permalink.php and (2) year parameter to index.php.

    Published: 16 Sept 2009
    9.3
    Critical

    CVE-2009-3213

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in broid 1.0 Beta 3a allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .mp3 file.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3202

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Published: 16 Sept 2009
    3.5
    Low

    CVE-2009-3210

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.8 and 6.x before 6.x-1.8, a module for Drupal, allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Sept 2009
    9.3
    Critical

    CVE-2009-3214

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code via a crafted Slideshow project (.psh) file, related to the (1) cell[n].images[m].image and (2) cell[n].sound.file fields.

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3293

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3292

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."

    Published: 16 Sept 2009
    7.5
    High

    CVE-2009-3291

    Last Modified: 23 Apr 2026

    The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2013-4520

    Last Modified: 11 Apr 2025

    xslt.c in libxslt before 1.1.25 allows context-dependent attackers to cause a denial of service (crash) via a stylesheet that embeds a DTD, which causes a structure to be accessed as a different type. NOTE: this issue is due to an incomplete fix for CVE-2012-2825.

    Published: 16 Sept 2009
    6.2
    Medium

    CVE-2010-0746

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in DeviceKit-disks in DeviceKit, as used in Fedora 11 and 12 and possibly other operating systems, allows local users to gain privileges via .. (dot dot) sequences in the label for a pluggable storage device.

    Published: 16 Sept 2009
    4.3
    Medium

    CVE-2009-3201

    Last Modified: 23 Apr 2026

    Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007-4940.

    Published: 15 Sept 2009
    2.1
    Low

    CVE-2009-2201

    Last Modified: 23 Apr 2026

    The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in a URL within an error dialog, which allows physically proximate attackers to obtain credentials by reading this dialog.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3125

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3165

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-2945

    Last Modified: 23 Apr 2026

    weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 15 Sept 2009
    5
    Medium

    CVE-2009-3166

    Last Modified: 23 Apr 2026

    token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3195

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3194

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3193

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the DigiFolio (com_digifolio) component 1.52 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a project action to index.php.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3192

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in LinkorCMS 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the searchstr parameter in a search action; or the (2) nikname, (3) realname, (4) homepage, or (5) city parameter in a registration action.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3186

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web script or HTML via the (1) t parameter to forum.php, (2) profile_name parameter to profile.php, and (3) p parameter to view.php.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3187

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in gamelist.php in Stand Alone Arcade 1.1 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3196

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arbitrary web script or HTML via the key parameter.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3198

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 15 Sept 2009
    5
    Medium

    CVE-2009-3199

    Last Modified: 23 Apr 2026

    Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3197

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech PHP Calendars Script allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3191

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to inject arbitrary web script or HTML via the cat parameter to (1) rss.php and (2) opml.php.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3190

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.

    Published: 15 Sept 2009
    4.3
    Medium

    CVE-2009-3189

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3188

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in save.php in phpSANE 0.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the file_save parameter.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3185

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugin.php in the Crazy Star plugin 2.0 for Discuz! allows remote authenticated users to execute arbitrary SQL commands via the fmid parameter in a view action.

    Published: 15 Sept 2009
    7.5
    High

    CVE-2009-3184

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters.

    Published: 15 Sept 2009
    4.4
    Medium

    CVE-2009-1883

    Last Modified: 23 Apr 2026

    The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.

    Published: 15 Sept 2009
    7.8
    High

    CVE-2009-3623

    Last Modified: 23 Apr 2026

    The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cache even when a client specifies the AUTH_NULL authentication flavor, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via an NFSv4 mount request.

    Published: 15 Sept 2009
    7.2
    High

    CVE-2009-3183

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in w in Sun Solaris 8 through 10, and OpenSolaris before snv_124, allows local users to gain privileges via unspecified vectors.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2009-2805

    Last Modified: 23 Apr 2026

    Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JBIG2 stream in a PDF file, leading to a heap-based buffer overflow.

    Published: 14 Sept 2009
    7.2
    High

    CVE-2009-2807

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the USB backend in CUPS in Apple Mac OS X 10.5.8 allows local users to gain privileges via unspecified vectors.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2009-2811

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in Launch Services in Apple Mac OS X 10.5.8 allows user-assisted remote attackers to execute arbitrary code via a .fileloc file, which does not trigger a "potentially unsafe" warning message in the Quarantine feature.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2009-2812

    Last Modified: 23 Apr 2026

    Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2009-2814

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Wiki Server in Apple Mac OS X 10.5.8 allows remote attackers to inject arbitrary web script or HTML via a search request containing data that does not use UTF-8 encoding.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2009-2809

    Last Modified: 23 Apr 2026

    ImageIO in Apple Mac OS X 10.4.11 and 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PixarFilm encoded TIFF image, related to "multiple memory corruption issues."

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2009-2804

    Last Modified: 23 Apr 2026

    Integer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5.8, and Safari before 4.0.4 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ColorSync profile embedded in an image, leading to a heap-based buffer overflow.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2009-2803

    Last Modified: 23 Apr 2026

    CarbonCore in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a file with a crafted resource fork.

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2009-2947

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Xapian Omega before 1.0.16 allows remote attackers to inject arbitrary web script or HTML via unspecified CGI parameter values, which are sometimes included in exception messages.

    Published: 14 Sept 2009
    7.5
    High

    CVE-2008-7229

    Last Modified: 23 Apr 2026

    GreenSQL Firewall (greensql-fw) before 0.9.2 allows remote attackers to bypass SQL injection protection via a crafted string, possibly involving an encoded space character (%20).

    Published: 14 Sept 2009