CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-7230

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.

    Published: 14 Sept 2009
    10
    Critical

    CVE-2008-7232

    Last Modified: 23 Apr 2026

    Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted CONNECT TACACS command.

    Published: 14 Sept 2009
    10
    Critical

    CVE-2008-7228

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in White_Dune before 0.29beta851 have unspecified impact and attack vectors, a different vulnerability than CVE-2008-0101.

    Published: 14 Sept 2009
    4
    Medium

    CVE-2008-7237

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3 and 10.1.2.2 allows remote authenticated users to affect confidentiality via unknown vectors, aka AS06.

    Published: 14 Sept 2009
    5
    Medium

    CVE-2008-7239

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 allow remote attackers to affect confidentiality via unknown vectors related to the (1) Oracle Application Object Library (APP02) and (2) Oracle Applications Manager (APP04).

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2008-7236

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 and 10.1.3.1 allows remote attackers to affect integrity via unknown vectors, aka AS05.

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2008-7235

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Forms component in Oracle Application Server 10.1.2.2 and E-Business Suite 12.0.3 allows remote attackers to affect integrity via unknown vectors, aka AS04.

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2008-7223

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php, (4) include/left_menu.class.php, or (5) plugins/stats/stats_view.php.

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2008-7222

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2008-7221

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in RunCMS 1.6.1 allows remote attackers to hijack the authentication of administrators for requests that (1) add new administrators or (2) modify user profiles via a crafted request to system/admin.php.

    Published: 14 Sept 2009
    10
    Critical

    CVE-2008-7225

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Foxit Remote Access Server (aka WAC Server) 2.0 Build 3503 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long SSH packets, a different vulnerability than CVE-2008-0151.

    Published: 14 Sept 2009
    7.5
    High

    CVE-2008-7226

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter.

    Published: 14 Sept 2009
    5
    Medium

    CVE-2008-7227

    Last Modified: 23 Apr 2026

    PartialBufferOutputStream2 in GeoServer before 1.6.1 and 1.7.0-beta1 attempts to flush buffer contents even when it is handling an "in memory buffer," which prevents the reporting of a service exception, with unknown impact and attack vectors.

    Published: 14 Sept 2009
    3.5
    Low

    CVE-2008-7231

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Meridio Document and Records Management before 4.3 SR1 allows remote authenticated users to inject arbitrary web script or HTML via the Title field in a (1) document (subGeneralProps:dmpvDocTitle:PROP_W_title) or (2) container (subGeneralProps:dmpvContainerTitle:PROP_W_title).

    Published: 14 Sept 2009
    9.3
    Critical

    CVE-2008-7233

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the E-Business Application client, as used in Oracle Application Server 1.1.8.26 and E-Business Suite 11.5.10.2, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Oracle Jinitiator component, aka AS02.

    Published: 14 Sept 2009
    6.8
    Medium

    CVE-2008-7234

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle BPEL Worklist Application component in Oracle Application Server 10.1.2.2 and 10.1.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, aka AS03.

    Published: 14 Sept 2009
    6
    Medium

    CVE-2008-7238

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.3 allow (1) local users to affect confidentiality and integrity via unknown vectors related to the Mobile Application Server component (APP01); (2) remote attackers to affect confidentiality via unknown vectors related to the Oracle Applications Framework (APP03); remote authenticated users to affect confidentiality and integrity via unknown vectors related to the (3) CRM Technical Foundation (APP05) and (4) Oracle Application Object Library (APP06); and remote authenticated users to affect integrity and availability via unknown vectors related to (5) Oracle Applications Technology Stack (APP07).

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2009-3237

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; allow remote attackers to inject arbitrary web script or HTML via the (1) crafted number preferences that are not properly handled in the preference system (services/prefs.php), as demonstrated by the sidebar_width parameter; or (2) crafted unknown MIME "text parts" that are not properly handled in the MIME viewer library (config/mime_drivers.php).

    Published: 14 Sept 2009
    4.3
    Medium

    CVE-2009-3236

    Last Modified: 23 Apr 2026

    The form library in Horde Application Framework 3.2 before 3.2.5 and 3.3 before 3.3.5; Groupware 1.1 before 1.1.6 and 1.2 before 1.2.4; and Groupware Webmail Edition 1.1 before 1.1.6 and 1.2 before 1.2.4; reuses temporary filenames during the upload process which allows remote attackers, with privileges to write to the address book, to overwrite arbitrary files and execute PHP code via crafted Horde_Form_Type_image form field elements.

    Published: 14 Sept 2009
    7.5
    High

    CVE-2009-2629

    Last Modified: 23 Apr 2026

    Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.

    Published: 14 Sept 2009
    7.5
    High

    CVE-2009-3235

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Sieve plugin in Dovecot 1.0 before 1.0.4 and 1.1 before 1.1.7, as derived from Cyrus libsieve, allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted SIEVE script, as demonstrated by forwarding an e-mail message to a large number of recipients, a different vulnerability than CVE-2009-2632.

    Published: 14 Sept 2009
    10
    Critical

    CVE-2008-7219

    Last Modified: 23 Apr 2026

    Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 before 2.2-RC2; Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 does not validate ownership when performing share changes, which has unknown impact and attack vectors.

    Published: 13 Sept 2009
    4.6
    Medium

    CVE-2008-7217

    Last Modified: 23 Apr 2026

    Microsoft Office 2008 for Mac, when running on Macintosh systems that restrict Office access to administrators, does not enforce this restriction for user ID 502, which allows local users with that ID to bypass intended security policy and access Office programs, related to permissions and ownership for certain directories.

    Published: 13 Sept 2009
    10
    Critical

    CVE-2008-7218

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Horde API in Horde 3.1 before 3.1.6 and 3.2 before 3.2 before 3.2-RC2; Turba H3 2.1 before 2.1.6 and 2.2 before 2.2-RC2; Kronolith H3 2.1 before 2.1.7 and H3 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and 2.2 before 2.2-RC2; Horde Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.0.4 and 1.1 before 1.1-RC2 has unknown impact and attack vectors.

    Published: 13 Sept 2009
    10
    Critical

    CVE-2009-3177

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Kaspersky Online Scanner 7.0 has unknown impact and attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.8, (1) "Kaspersky Online Antivirus Scanner 7.0 exploit (Linux)" and (2) "Kaspersky Online Antivirus Scanner 7.0 exploit (Windows)." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 11 Sept 2009
    9.3
    Critical

    CVE-2009-3176

    Last Modified: 23 Apr 2026

    Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.1, "Novell iPrint Client 4.38 ActiveX exploit." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 11 Sept 2009
    10
    Critical

    CVE-2009-3169

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Hitachi JP1/File Transmission Server/FTP before 09-00 allow remote attackers to execute arbitrary code via unknown attack vectors.

    Published: 11 Sept 2009
    7.2
    High

    CVE-2009-3168

    Last Modified: 23 Apr 2026

    Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/user_add.php, which allows remote authenticated users to reset administrative passwords or add administrators via a direct request.

    Published: 11 Sept 2009
    6.8
    Medium

    CVE-2009-3182

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in user/File/.

    Published: 11 Sept 2009
    7.5
    High

    CVE-2009-3175

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php.

    Published: 11 Sept 2009
    9.3
    Critical

    CVE-2009-3170

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a (1) .pls or (2) .m3u playlist file.

    Published: 11 Sept 2009
    4.3
    Medium

    CVE-2009-3171

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user parameter to user.php or (2) lookup parameter to search.php.

    Published: 11 Sept 2009
    7.5
    High

    CVE-2009-3172

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi Groupmax Groupware Server 07-00 through 07-50-/A, Groupmax Server Set 03-00 through 06-52, Groupware Server Set 03-00 through 06-52, and Scheduler Server Set 03-00 through 06-52 has unknown impact and attack vectors related to invalid access rights.

    Published: 11 Sept 2009
    6.8
    Medium

    CVE-2009-3173

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/add_album.php in The Rat CMS Alpha 2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

    Published: 11 Sept 2009
    7.5
    High

    CVE-2009-3174

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fonctions_racine.php in OBOphiX 2.7.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin_lib parameter.

    Published: 11 Sept 2009
    7.8
    High

    CVE-2009-3178

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in mm.exe in Symantec Altiris Deployment Solution 6.9 allows remote attackers to cause a denial of service via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.18, "Symantec Altiris Deployment Solution 6.9 DoS." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 11 Sept 2009
    10
    Critical

    CVE-2009-3179

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Symantec Altiris Deployment Solution 6.9 might allow remote attackers to execute arbitrary code via unknown client-side attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 7.17, as identified by (1) "Symantec Altiris Deployment Solution 6.9 exploit, (2) "Symantec Altiris Deployment Solution 6.9 exploit (II)," and (3) "Symantec Altiris Deployment Solution 6.9 exploit (III)." NOTE: as of 20090909, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 11 Sept 2009
    7.5
    High

    CVE-2009-3180

    Last Modified: 23 Apr 2026

    Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php.

    Published: 11 Sept 2009
    5
    Medium

    CVE-2009-3181

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Anantasoft Gazelle CMS 1.0 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the customizetemplate parameter in a direct request to admin/settemplate.php.

    Published: 11 Sept 2009
    6.8
    Medium

    CVE-2009-2800

    Last Modified: 23 Apr 2026

    Buffer overflow in Alias Manager in Apple Mac OS X 10.4.11 and 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted alias file.

    Published: 11 Sept 2009
    4.3
    Medium

    CVE-2009-3167

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Anantasoft Gazelle CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Published: 11 Sept 2009
    5
    Medium

    CVE-2008-7203

    Last Modified: 23 Apr 2026

    Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.

    Published: 11 Sept 2009
    6.8
    Medium

    CVE-2008-7204

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in VirtueMart 1.0.13a and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 11 Sept 2009
    4.3
    Medium

    CVE-2008-7205

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the product view functionality in VirtueMart 1.0.13a and earlier allows remote attackers to read arbitrary files via vectors related to a template file.

    Published: 11 Sept 2009
    4.3
    Medium

    CVE-2008-7206

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Electronic Logbook (ELOG) before 2.7.2 has unknown impact and attack vectors when the "logbook contains HTML code," probably cross-site scripting (XSS).

    Published: 11 Sept 2009
    2.1
    Low

    CVE-2008-7207

    Last Modified: 23 Apr 2026

    RivetTracker before 1.0 stores passwords in cleartext in config.php, which allows local users to discover passwords by reading config.php.

    Published: 11 Sept 2009
    5
    Medium

    CVE-2008-7212

    Last Modified: 23 Apr 2026

    MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php, which reveals the installation path in an error message.

    Published: 11 Sept 2009
    4.3
    Medium

    CVE-2008-7213

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.

    Published: 11 Sept 2009
    6.8
    Medium

    CVE-2008-7214

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in administrator/index2.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add new administrator accounts via the save task in a com_users action, as demonstrated using a separate XSS vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php.

    Published: 11 Sept 2009
    4.3
    Medium

    CVE-2008-7216

    Last Modified: 23 Apr 2026

    Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip.

    Published: 11 Sept 2009