CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-3115

    Last Modified: 23 Apr 2026

    SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information.

    Published: 9 Sept 2009
    4.3
    Medium

    CVE-2009-3120

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 Sept 2009
    4.3
    Medium

    CVE-2009-3121

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Sept 2009
    6.4
    Medium

    CVE-2009-3122

    Last Modified: 23 Apr 2026

    The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecified vectors.

    Published: 9 Sept 2009
    7.5
    High

    CVE-2009-3116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2009-3124

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.

    Published: 9 Sept 2009
    7.5
    High

    CVE-2009-3117

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 9 Sept 2009
    7.5
    High

    CVE-2009-3118

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the comtext parameter, in conjunction with crafted comname and comtitle parameters, in a poll action to index.php, related to incorrect input sanitization in base/danneo.function.php.

    Published: 9 Sept 2009
    7.5
    High

    CVE-2009-3119

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2009-3123

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.

    Published: 9 Sept 2009
    6.8
    Medium

    CVE-2008-7192

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3112

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attackers to gain administrator privileges and access the shop backend via a crafted parameter.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2009-3113

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allows remote attackers to gain write access to product reviews via a crafted parameter.

    Published: 9 Sept 2009
    6.8
    Medium

    CVE-2008-7193

    Last Modified: 23 Apr 2026

    PHPKIT 1.6.4 PL1 includes the session ID in the URL, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks by reading the PHPKITSID parameter from the HTTP Referer and using it in a request to (1) modify the user profile via upload_files/include.php or (2) create a new administrator via upload_files/pk/include.php.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2008-7189

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Local Media Browser before 0.1 have unknown impact and attack vectors related to "Security holes."

    Published: 9 Sept 2009
    10
    Critical

    CVE-2008-7190

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adium before 1.2 has unknown impact and attack vectors related to javascript: URLs, possibly cross-site scripting (XSS).

    Published: 9 Sept 2009
    5
    Medium

    CVE-2008-7191

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Polipo before 1.0.4 allows remote attackers to cause a denial of service (crash) via a long request URL.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2009-2266

    Last Modified: 23 Apr 2026

    OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.

    Published: 9 Sept 2009
    7.5
    High

    CVE-2008-7188

    Last Modified: 23 Apr 2026

    ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2008-7186

    Last Modified: 23 Apr 2026

    Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2008-7187

    Last Modified: 23 Apr 2026

    Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.

    Published: 9 Sept 2009
    4.6
    Medium

    CVE-2009-3286

    Last Modified: 23 Apr 2026

    NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.

    Published: 9 Sept 2009
    4.4
    Medium

    CVE-2009-3274

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.

    Published: 9 Sept 2009
    6.8
    Medium

    CVE-2009-3231

    Last Modified: 23 Apr 2026

    The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

    Published: 9 Sept 2009
    6.5
    Medium

    CVE-2009-3230

    Last Modified: 23 Apr 2026

    The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.

    Published: 9 Sept 2009
    4
    Medium

    CVE-2009-3229

    Last Modified: 23 Apr 2026

    The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, and 8.2 before 8.2.14 allows remote authenticated users to cause a denial of service (backend shutdown) by "re-LOAD-ing" libraries from a certain plugins directory.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3073

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Sept 2009
    5
    Medium

    CVE-2009-3078

    Last Modified: 23 Apr 2026

    Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unicode characters with a tall line-height property.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3079

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors involving an object, the FeedWriter, and the BrowserFeedWriter.

    Published: 9 Sept 2009
    9.3
    Critical

    CVE-2009-3077

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability."

    Published: 9 Sept 2009
    9.3
    Critical

    CVE-2009-3076

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3074

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3075

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to use of mutable strings in the js_StringReplaceHelper function in js/src/jsstr.cpp, and unknown vectors.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3069

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3070

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3071

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 9 Sept 2009
    10
    Critical

    CVE-2009-3072

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.

    Published: 9 Sept 2009
    6.8
    Medium

    CVE-2008-7183

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in eva/index.php in EVA CMS 2.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the eva[caminho] parameter to index.php.

    Published: 8 Sept 2009
    4.3
    Medium

    CVE-2008-7184

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web script or HTML via a public comment.

    Published: 8 Sept 2009
    7.8
    High

    CVE-2009-0627

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco NX-OS before 4.0(1a)N2(1), when running on Nexus 5000 platforms, allows remote attackers to cause a denial of service (crash) via an unspecified "sequence of TCP packets" related to "TCP State manipulation," possibly related to separate attacks against CVE-2008-4609.

    Published: 8 Sept 2009
    4.8
    Medium

    CVE-2009-3107

    Last Modified: 23 Apr 2026

    Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening port for the DBManager service, which allows remote attackers to bypass authentication and modify tasks or the Altiris Database via a connection to this service.

    Published: 8 Sept 2009
    7.2
    High

    CVE-2009-3108

    Last Modified: 23 Apr 2026

    The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyone:Full Control), which allows local users to gain privileges by replacing the executable with a Trojan horse program.

    Published: 8 Sept 2009
    4.3
    Medium

    CVE-2008-7185

    Last Modified: 23 Apr 2026

    GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.

    Published: 8 Sept 2009
    9.3
    Critical

    CVE-2009-3109

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, when key-based authentication is being used between a deployment server and a client, allows remote attackers to bypass authentication and execute arbitrary commands as SYSTEM by spoofing the deployment server and sending "alternate commands" before the handshake is completed.

    Published: 8 Sept 2009
    9.3
    Critical

    CVE-2009-2139

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238.

    Published: 8 Sept 2009
    5.8
    Medium

    CVE-2009-3110

    Last Modified: 23 Apr 2026

    Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 allows remote attackers to read sensitive files and prevent client updates by connecting to the file transfer port before the expected client does.

    Published: 8 Sept 2009
    8.5
    High

    CVE-2009-2499

    Last Modified: 23 Apr 2026

    Microsoft Windows Media Format Runtime 9.0, 9.5, and 11; and Microsoft Media Foundation on Windows Vista Gold, SP1, and SP2 and Server 2008; allows remote attackers to execute arbitrary code via an MP3 file with crafted metadata that triggers memory corruption, aka "Windows Media Playback Memory Corruption Vulnerability."

    Published: 8 Sept 2009
    9.3
    Critical

    CVE-2009-2519

    Last Modified: 23 Apr 2026

    The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state" corruption, aka "DHTML Editing Component ActiveX Control Vulnerability."

    Published: 8 Sept 2009
    9.3
    Critical

    CVE-2009-1132

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Wireless LAN AutoConfig Service (aka Wlansvc) in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a malformed wireless frame, aka "Wireless Frame Parsing Remote Code Execution Vulnerability."

    Published: 8 Sept 2009
    9.3
    Critical

    CVE-2009-1920

    Last Modified: 23 Apr 2026

    The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted web site that triggers memory corruption, aka "JScript Remote Code Execution Vulnerability."

    Published: 8 Sept 2009