CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2009-2957

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, might allow remote attackers to execute arbitrary code via a long filename in a TFTP packet, as demonstrated by a read (aka RRQ) request.

    Published: 31 Aug 2009
    4.3
    Medium

    CVE-2009-2958

    Last Modified: 23 Apr 2026

    The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TFTP read (aka RRQ) request with a malformed blksize option.

    Published: 31 Aug 2009
    5.6
    Medium

    CVE-2010-0285

    Last Modified: 11 Apr 2025

    gnome-screensaver 2.14.3, 2.22.2, 2.27.x, 2.28.0, and 2.28.3, when the X configuration enables the extend screen option, allows physically proximate attackers to bypass screen locking, access an unattended workstation, and view half of the GNOME desktop by attaching an external monitor.

    Published: 31 Aug 2009
    7.8
    High

    CVE-2009-3620

    Last Modified: 23 Apr 2026

    The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.

    Published: 30 Aug 2009
    5
    Medium

    CVE-2009-2944

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.

    Published: 30 Aug 2009
    9.8
    Critical

    CVE-2008-7109

    Last Modified: 23 Apr 2026

    The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified program that does not prompt the user for a password.

    Published: 28 Aug 2009
    7.8
    High

    CVE-2008-7110

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to upload files to arbitrary locations via a .. (dot dot) in a request.

    Published: 28 Aug 2009
    9.3
    Critical

    CVE-2008-7111

    Last Modified: 23 Apr 2026

    The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it easier for remote attackers to execute arbitrary code or overwrite files by leveraging CVE-2008-7110 and CVE-2008-7109.

    Published: 28 Aug 2009
    5
    Medium

    CVE-2008-7112

    Last Modified: 23 Apr 2026

    The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to cause a denial of service (hang or crash) via invalid field length values in a malformed (1) document or (2) request.

    Published: 28 Aug 2009
    7.5
    High

    CVE-2008-7116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.

    Published: 28 Aug 2009
    5
    Medium

    CVE-2008-7118

    Last Modified: 23 Apr 2026

    WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.

    Published: 28 Aug 2009
    7.5
    High

    CVE-2008-7119

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Aug 2009
    10
    Critical

    CVE-2008-7115

    Last Modified: 23 Apr 2026

    The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/. NOTE: the setup_dns.exe vector is already covered by CVE-2008-1244.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2009-3004

    Last Modified: 23 Apr 2026

    Avant Browser 11.7 Builds 35 and 36 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2009-3006

    Last Modified: 23 Apr 2026

    Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2009-3008

    Last Modified: 23 Apr 2026

    K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.

    Published: 28 Aug 2009
    7.5
    High

    CVE-2008-7120

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter.

    Published: 28 Aug 2009
    6.4
    Medium

    CVE-2008-7113

    Last Modified: 23 Apr 2026

    The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 uses a small space of predictable user identification numbers for access control, which allows remote attackers to upload documents via a brute force attack.

    Published: 28 Aug 2009
    5
    Medium

    CVE-2008-7117

    Last Modified: 23 Apr 2026

    eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with the file parameter set to style.css. NOTE: this can probably be leveraged for cross-site scripting (XSS) attacks.

    Published: 28 Aug 2009
    7.1
    High

    CVE-2009-3000

    Last Modified: 23 Apr 2026

    The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handling."

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2009-3005

    Last Modified: 23 Apr 2026

    Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.

    Published: 28 Aug 2009
    7.2
    High

    CVE-2008-7107

    Last Modified: 23 Apr 2026

    easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL 0x222003 request to the \\.\easdrv device interface.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2008-7108

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Carmosa phpCart 3.4 through 4.6.4 allow remote attackers to inject arbitrary web script or HTML via the (1) quantity or (2) Add Engraving fields to the default URI; (3) Quantity field to phpcart.php; (4) Name, (5) Company, (6) Address, (7) City, and (8) Province/State fields in a checkout action to phpcart.php; and other unspecified vectors.

    Published: 28 Aug 2009
    6.8
    Medium

    CVE-2008-7114

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the name field.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2008-7121

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the search bar.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2009-3003

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page.

    Published: 28 Aug 2009
    7.8
    High

    CVE-2009-3289

    Last Modified: 23 Apr 2026

    The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.

    Published: 28 Aug 2009
    4.3
    Medium

    CVE-2009-2700

    Last Modified: 23 Apr 2026

    src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 28 Aug 2009
    9.3
    Critical

    CVE-2009-4247

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in protocol/rtsp/rtspclnt.cpp in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.x; RealPlayer SP 1.0.0 and 1.0.1; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, 11.0, and 11.0.1; Linux RealPlayer 10, 11.0.0, and 11.0.1; and Helix Player 10.x, 11.0.0, and 11.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an ASM RuleBook with a large number of rules, related to an "array overflow."

    Published: 28 Aug 2009
    5
    Medium

    CVE-2008-7106

    Last Modified: 23 Apr 2026

    The installation of Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2, when both anti-virus and anti-spam are supported, does not create or launch the associated scan engines when the system is under heavy load, which has unspecified impact, probably remote bypass of scanner protection or a denial of service (message loss or delay).

    Published: 27 Aug 2009
    5
    Medium

    CVE-2008-7105

    Last Modified: 23 Apr 2026

    Sophos PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (EdgeTransport.exe termination) via a TNEF-encoded message with a crafted rich text body that is not properly handled during conversion to plain text. NOTE: this might be related to CVE-2008-7104.

    Published: 27 Aug 2009
    7.5
    High

    CVE-2008-7097

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands via (1) the $id variable in admin/includes/dele_cpac.php, (2) $ord[order_id] variable in payments/payment_received.php, (3) $id variable in includes/functions.php, and (4) unspecified variables in modules/chat.php, as demonstrated via the (a) show parameter in an online action to index.php; (b) PATH_INTO to the room/ handler; (c) image and (d) id parameters in a vote action to index.php; (e) PATH_INFO to the blog/ handler; and (f) id parameter in a blog_edit action to index.php.

    Published: 27 Aug 2009
    6.9
    Medium

    CVE-2008-7096

    Last Modified: 23 Apr 2026

    Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.

    Published: 27 Aug 2009
    9.3
    Critical

    CVE-2008-7103

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of service (browser crash) or execute arbitrary code via a long Document.Location property value.

    Published: 27 Aug 2009
    5
    Medium

    CVE-2008-7104

    Last Modified: 23 Apr 2026

    Sophos PureMessage Scanner service (PMScanner.exe) in PureMessage for Microsoft Exchange 3.0 before 3.0.2 allows remote attackers to cause a denial of service (message queue delay and incomplete spam rule update) via a crafted (1) RTF or (2) PDF file.

    Published: 27 Aug 2009
    5
    Medium

    CVE-2008-7101

    Last Modified: 24 Apr 2026

    Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors.

    Published: 27 Aug 2009
    6.8
    Medium

    CVE-2008-7099

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arbitrary PHP code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Aug 2009
    6.5
    Medium

    CVE-2008-7100

    Last Modified: 24 Apr 2026

    Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity."

    Published: 27 Aug 2009
    7.5
    High

    CVE-2008-7102

    Last Modified: 24 Apr 2026

    DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.

    Published: 27 Aug 2009
    4.3
    Medium

    CVE-2008-7098

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary web script or HTML via the blog, possibly the (1) Title and (2) Text fields; (3) the gallery, possibly the Description field in Your Pictures; (4) the forum, possibly the Your Message field when posting a new thread; or (5) the vote parameter in a view action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Aug 2009
    7.5
    High

    CVE-2009-2978

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2008-7095

    Last Modified: 23 Apr 2026

    The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP community strings via SNMP-COMMUNITY-MIB::snmpCommunityName (1.3.6.1.6.3.18.1.1.1.2) or SNMP-VIEW-BASED-ACM-MIB::vacmGroupName (1.3.6.1.6.3.16.1.2.1.3) with knowledge of one community string, and (2) read SNMPv3 user names via SNMP-USER-BASED-SM-MIB or SNMP-VIEW-BASED-ACM-MIB.

    Published: 27 Aug 2009
    5
    Medium

    CVE-2009-2975

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2009-2972

    Last Modified: 23 Apr 2026

    in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors that trigger a "fork()/exec() bomb."

    Published: 27 Aug 2009
    3.3
    Low

    CVE-2009-2977

    Last Modified: 23 Apr 2026

    The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2009-2976

    Last Modified: 23 Apr 2026

    Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to discover Wireless LAN Controller MAC addresses and IP addresses, and AP configuration details, by sniffing the wireless network.

    Published: 27 Aug 2009
    5
    Medium

    CVE-2009-2974

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application hang) via vectors involving a chromehtml: URI value for the document.location property or (2) cause a denial of service (application hang and CPU consumption) via vectors involving a series of function calls that set a chromehtml: URI value for the document.location property.

    Published: 27 Aug 2009
    6.4
    Medium

    CVE-2009-2973

    Last Modified: 23 Apr 2026

    Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbitrary HTTPS servers via a crafted certificate, a related issue to CVE-2009-2409.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2009-2051

    Last Modified: 23 Apr 2026

    Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message that triggers an improper call to the sipSafeStrlen function, aka Bug IDs CSCsz40392 and CSCsz43987.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2009-2050

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.

    Published: 27 Aug 2009