CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2008-7215

    Last Modified: 23 Apr 2026

    The Image Manager in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to rename arbitrary files and cause a denial of service via modified file[NewFile][name], file[NewFile][tmp_name], and file[NewFile][size] parameters in a FileUpload command, which are used to modify equivalent variables in $_FILES that are accessed when the is_uploaded_file check fails.

    Published: 11 Sept 2009
    6.8
    Medium

    CVE-2008-7208

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php.

    Published: 11 Sept 2009
    7.5
    High

    CVE-2008-7209

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as image/gif, then accessing it via a direct request to the file in an unspecified directory.

    Published: 11 Sept 2009
    7.5
    High

    CVE-2008-7210

    Last Modified: 23 Apr 2026

    directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being unset. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in AJChat.

    Published: 11 Sept 2009
    6.9
    Medium

    CVE-2008-7211

    Last Modified: 23 Apr 2026

    CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which allows local users to gain SYSTEM privileges via a crafted IRP request that dereferences a NULL FsContext pointer.

    Published: 11 Sept 2009
    7.2
    High

    CVE-2009-4997

    Last Modified: 11 Apr 2025

    gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or hibernate button is pressed, which might make it easier for physically proximate attackers to access an unattended laptop via a resume action, a related issue to CVE-2010-2532. NOTE: this issue exists because of a regression that followed a gnome-power-manager fix a few years earlier.

    Published: 11 Sept 2009
    7.1
    High

    CVE-2009-2903

    Last Modified: 23 Apr 2026

    Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.

    Published: 11 Sept 2009
    7.1
    High

    CVE-2009-3164

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IPv6 networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_122, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames. NOTE: this issue exists because of an incomplete fix for CVE-2009-2136.

    Published: 10 Sept 2009
    9.3
    Critical

    CVE-2009-2202

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted H.264 movie file.

    Published: 10 Sept 2009
    9.3
    Critical

    CVE-2009-2203

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG-4 video file.

    Published: 10 Sept 2009
    4.6
    Medium

    CVE-2009-2794

    Last Modified: 23 Apr 2026

    The Exchange Support component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, does not properly implement the "Maximum inactivity time lock" functionality, which allows local users to bypass intended Microsoft Exchange restrictions by choosing a large Require Passcode time value.

    Published: 10 Sept 2009
    7.2
    High

    CVE-2009-2795

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Recovery Mode component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allows local users to bypass the passcode requirement and access arbitrary data via vectors related to "command parsing."

    Published: 10 Sept 2009
    2.1
    Low

    CVE-2009-2796

    Last Modified: 23 Apr 2026

    The UIKit component in Apple iPhone OS 3.0, and iPhone OS 3.0.1 for iPod touch, allows physically proximate attackers to discover a password by watching a user undo deletions of characters in the password.

    Published: 10 Sept 2009
    9.3
    Critical

    CVE-2009-2799

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted H.264 movie file.

    Published: 10 Sept 2009
    6.8
    Medium

    CVE-2009-2206

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the AudioCodecs library in the CoreAudio component in Apple iPhone OS before 3.1, and iPhone OS before 3.1.1 for iPod touch, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted (1) AAC or (2) MP3 file, as demonstrated by a ringtone with malformed entries in the sample size table.

    Published: 10 Sept 2009
    2.1
    Low

    CVE-2009-2207

    Last Modified: 23 Apr 2026

    The MobileMail component in Apple iPhone OS 3.0 and 3.0.1, and iPhone OS 3.0 for iPod touch, lists deleted e-mail messages in Spotlight search results, which might allow local users to obtain sensitive information by reading these messages.

    Published: 10 Sept 2009
    9.3
    Critical

    CVE-2009-2798

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file.

    Published: 10 Sept 2009
    7.8
    High

    CVE-2009-2815

    Last Modified: 23 Apr 2026

    The Telephony component in Apple iPhone OS before 3.1 does not properly handle SMS arrival notifications, which allows remote attackers to cause a denial of service (NULL pointer dereference and service interruption) via a crafted SMS message.

    Published: 10 Sept 2009
    7.5
    High

    CVE-2009-3150

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.

    Published: 10 Sept 2009
    5
    Medium

    CVE-2009-3151

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3155

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in gmap.php in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the addr parameter.

    Published: 10 Sept 2009
    3.5
    Low

    CVE-2009-3157

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Calendar module 6.x before 6.x-2.2 for Drupal allows remote authenticated users, with "create new content types" privileges, to inject arbitrary web script or HTML via the title of a content type.

    Published: 10 Sept 2009
    7.5
    High

    CVE-2009-3158

    Last Modified: 23 Apr 2026

    admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via unknown vectors. NOTE: some of these details are obtained from third party information.

    Published: 10 Sept 2009
    7.8
    High

    CVE-2009-3161

    Last Modified: 23 Apr 2026

    The server in IBM WebSphere MQ 7.0.0.1, 7.0.0.2, and 7.0.1.0 allows attackers to cause a denial of service (trap) or possibly have unspecified other impact via malformed data.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3146

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search_advance.php in ArticleFriend Script allows remote attackers to inject arbitrary web script or HTML via the SearchWd parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3152

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in becommunity/community/index.php in NTSOFT BBS E-Market Professional allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) bt_code, and (3) b_no parameters in a board view action.

    Published: 10 Sept 2009
    7.8
    High

    CVE-2009-3159

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the rriDecompress function in IBM WebSphere MQ 7.0.0.0, 7.0.0.1, and 7.0.0.2 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3147

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbitrary web script or HTML via the date parameter.

    Published: 10 Sept 2009
    7.5
    High

    CVE-2009-3148

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to assignments.php.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3149

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3153

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in x10 MP3 Search engine 1.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) pic_id parameter to includes/video_ad.php, (2) category parameter to linkvideos_listing.php, id parameter to (3) templates/header1.php and (4) mp3/lyrics.php, key parameter to (5) video_listing.php and (6) adult/video_listing.php, and name parameter to (7) mp3/embed.php and (8) mp3/info.php.

    Published: 10 Sept 2009
    7.5
    High

    CVE-2009-3154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 7.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action to index.php, a different vector than CVE-2009-2567.

    Published: 10 Sept 2009
    2.1
    Low

    CVE-2009-3156

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Date Tools sub-module in the Date module 6.x before 6.x-2.3 for Drupal allows remote authenticated users, with "use date tools" or "administer content types" privileges, to inject arbitrary web script or HTML via a "Content type label" field.

    Published: 10 Sept 2009
    8.8
    High

    CVE-2009-3160

    Last Modified: 23 Apr 2026

    IBM WebSphere MQ 6.x through 6.0.2.7, 7.0.0.0, 7.0.0.1, 7.0.0.2, and 7.0.1.0, when read ahead or asynchronous message consumption is enabled, allows attackers to have an unspecified impact via unknown vectors, related to a "memory overwrite" issue.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2009-3162

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Multi Website 1.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action to the default URI.

    Published: 10 Sept 2009
    9.3
    Critical

    CVE-2007-6730

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web management interface in the ZyXEL P-330W router allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote router management via goform/formRmtMgt or (2) modify the administrator password via goform/formPasswordSetup.

    Published: 10 Sept 2009
    5
    Medium

    CVE-2008-7195

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Fujitsu Interstage HTTP Server, as used in Interstage Application Server Enterprise Edition 7.0.1 for Solaris, allows attackers to cause a denial of service via unknown vectors related to SSL.

    Published: 10 Sept 2009
    10
    Critical

    CVE-2008-7196

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in metashell before 0.03 has unknown impact and attack vectors related to a "PATH execution security flaw," possibly an untrusted search path vulnerability.

    Published: 10 Sept 2009
    10
    Critical

    CVE-2008-7197

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in G15Daemon before 1.9.4 have unknown impact and attack vectors.

    Published: 10 Sept 2009
    10
    Critical

    CVE-2008-7198

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in phpns before 2.1.1beta1 have unknown impact and attack vectors.

    Published: 10 Sept 2009
    5
    Medium

    CVE-2008-7199

    Last Modified: 23 Apr 2026

    Phoenix Contact FL IL 24 BK-PAC allows remote attackers to cause a denial of service (hang) via (1) unspecified manipulations as demonstrated by a Nessus scan or (2) malformed input to TCP port 502.

    Published: 10 Sept 2009
    10
    Critical

    CVE-2008-7200

    Last Modified: 23 Apr 2026

    Double free vulnerability in Deliantra server engine before 2.4 has unknown impact and attack vectors.

    Published: 10 Sept 2009
    5
    Medium

    CVE-2008-7194

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Fujitsu Interstage HTTP Server, as used in Interstage Application Server 5.0, 7.0, 7.0.1, and 8.0.0 for Windows, allows attackers to cause a denial of service via a crafted request.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2008-7202

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in OpenWebMail before 2.53 (Stable) allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 10 Sept 2009
    4.3
    Medium

    CVE-2007-6729

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web management interface in the ZyXEL P-330W router allows remote attackers to inject arbitrary web script or HTML via the pingstr parameter and other unspecified vectors.

    Published: 10 Sept 2009
    7.8
    High

    CVE-2008-7201

    Last Modified: 23 Apr 2026

    Lantronix MSS485-T allows remote attackers to cause a denial of service (unstable performance and service loss) via certain vulnerability scans, as demonstrated using (1) Nessus and (2) nmap.

    Published: 10 Sept 2009
    7.1
    High

    CVE-2009-3722

    Last Modified: 23 Apr 2026

    The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege Level (CPL) before accessing a debug register, which allows guest OS users to cause a denial of service (trap) on the host OS via a crafted application.

    Published: 10 Sept 2009
    6
    Medium

    CVE-2009-2813

    Last Modified: 23 Apr 2026

    Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.

    Published: 10 Sept 2009
    6.8
    Medium

    CVE-2009-2205

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Published: 9 Sept 2009
    7.5
    High

    CVE-2009-3114

    Last Modified: 23 Apr 2026

    The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.

    Published: 9 Sept 2009