CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2009-2052

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "tracking of network connections," aka Bug IDs CSCsq22534 and CSCsw52371.

    Published: 27 Aug 2009
    10
    Critical

    CVE-2009-2935

    Last Modified: 23 Apr 2026

    Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2009-2053

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2) allows remote attackers to cause a denial of service (file-descriptor exhaustion and SCCP outage) via a flood of TCP packets, aka Bug ID CSCsx32236.

    Published: 27 Aug 2009
    7.8
    High

    CVE-2009-2054

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.

    Published: 27 Aug 2009
    7.3
    High

    CVE-2009-2861

    Last Modified: 23 Apr 2026

    The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does not properly implement access-point association, which allows remote attackers to spoof a controller and cause a denial of service (service outage) via crafted remote radio management (RRM) packets, aka "SkyJack" or Bug ID CSCtb56664.

    Published: 27 Aug 2009
    7.1
    High

    CVE-2009-3611

    Last Modified: 23 Apr 2026

    common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.

    Published: 27 Aug 2009
    4.3
    Medium

    CVE-2010-0656

    Last Modified: 11 Apr 2025

    WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a directory, which allows attackers to obtain sensitive information or possibly have unspecified other impact via a crafted local HTML document.

    Published: 27 Aug 2009
    5
    Medium

    CVE-2008-7094

    Last Modified: 23 Apr 2026

    Campaign/CampaignListener in the listener server in Unica Affinium Campaign 7.2.1.0.55 allows remote attackers to cause a denial of service (server crash) via a crafted length field that triggers (1) connection exhaustion or (2) memory allocation failure.

    Published: 26 Aug 2009
    5
    Medium

    CVE-2008-7084

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 26 Aug 2009
    6.5
    Medium

    CVE-2008-7088

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the file in a certain path. NOTE: this may be the same vulnerability as CVE-2008-0251, but this is not clear due to lack of details from the vendor.

    Published: 26 Aug 2009
    4.3
    Medium

    CVE-2008-7089

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Pligg 9.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action to user.php and other unspecified vectors.

    Published: 26 Aug 2009
    7.8
    High

    CVE-2008-7090

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existence of arbitrary files via a .. (dot dot) in the $tb_url variable in trackback.php, or (2) include arbitrary files via a .. (dot dot) in the template parameter to settemplate.php.

    Published: 26 Aug 2009
    4.3
    Medium

    CVE-2009-2967

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, different vulnerabilities than CVE-2009-2959.

    Published: 26 Aug 2009
    7.5
    High

    CVE-2008-7086

    Last Modified: 23 Apr 2026

    Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to admin.

    Published: 26 Aug 2009
    6.8
    Medium

    CVE-2008-7093

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to (1) create arbitrary directories or files via a .. (dot dot) in the folder name in the new folder functionality or (2) list arbitrary files via a crafted request to Campaign/CampaignListener.

    Published: 26 Aug 2009
    7.5
    High

    CVE-2008-7085

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the viewpage action to the default URI, probably index.php, or (2) divid parameter in the schedule action to index.php.

    Published: 26 Aug 2009
    7.5
    High

    CVE-2008-7087

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in search_wA.php in OpenPro 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the LIBPATH parameter.

    Published: 26 Aug 2009
    7.5
    High

    CVE-2008-7091

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to vote.php, which is not properly handled in libs/link.php; (2) id parameter to trackback.php; (3) an unspecified parameter to submit.php; (4) requestTitle variable in a query to story.php; (5) requestID and (6) requestTitle variables in recommend.php; (7) categoryID parameter to cloud.php; (8) title parameter to out.php; (9) username parameter to login.php; (10) id parameter to cvote.php; and (11) commentid parameter to edit.php.

    Published: 26 Aug 2009
    4.3
    Medium

    CVE-2008-7092

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Unica Affinium Campaign 7.2.1.0.55 allow remote attackers to inject arbitrary web script or HTML via a Javascript event in the (1) url, (2) PageName, and (3) title parameters in a CustomBookMarkLink action to Campaign/Campaign; (4) a Javascript event in the displayIcon parameter to Campaign/updateOfferTemplateSubmit.do (aka the templates web page); (5) crafted input to Campaign/CampaignListener (aka the listener server), which is not properly handled when displaying the status log; and (6) id parameter to Campaign/campaignDetails.do, (7) id parameter to Campaign/offerDetails.do, (8) function parameter to Campaign/Campaign, (9) sessionID parameter to Campaign/runAllFlowchart.do, (10) id parameter in an edit action to Campaign/updateOfferTemplatePage.do, (11) Frame parameter in a LoadFrame action to Campaign/Campaign, (12) affiniumUserName parameter to manager/jsp/test.jsp, (13) affiniumUserName parameter to Campaign/main.do, and possibly other vectors.

    Published: 26 Aug 2009
    4.3
    Medium

    CVE-2009-2966

    Last Modified: 23 Apr 2026

    avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.

    Published: 25 Aug 2009
    9.3
    Critical

    CVE-2009-2963

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the download and execution of arbitrary files via attack vectors related to a "malformed update url and a malformed update website."

    Published: 25 Aug 2009
    9.3
    Critical

    CVE-2009-2961

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in a .MP3 playlist file.

    Published: 25 Aug 2009
    4.3
    Medium

    CVE-2009-2965

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before SD 7.0.100, allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2009-2960

    Last Modified: 23 Apr 2026

    CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.

    Published: 25 Aug 2009
    4.3
    Medium

    CVE-2009-2959

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 through 0.7.11p1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7064

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as used in QSF Portal before 1.4.5, when running on Windows, allows remote attackers to include and execute arbitrary local files via a "\" (backslash) in the lang parameter to index.php, which bypasses a protection mechanism that only checks for "/" (forward slash), as demonstrated by uploading and including PHP code in an avatar file.

    Published: 25 Aug 2009
    7.8
    High

    CVE-2008-7065

    Last Modified: 23 Apr 2026

    Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and device reboot) via a crafted SIP packet to UDP port 5060.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7066

    Last Modified: 23 Apr 2026

    OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update parameter set to 1 and modified user and password parameters.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7067

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/plugins/Online_Users/main.php in PageTree CMS 0.0.2 BETA 0001 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[PT_Config][dir][data] parameter.

    Published: 25 Aug 2009
    5
    Medium

    CVE-2008-7063

    Last Modified: 23 Apr 2026

    Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for admin/o12faq.mdb.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7071

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL commands via the username parameter, related to login.php. NOTE: some of these details are obtained from third party information.

    Published: 25 Aug 2009
    4.3
    Medium

    CVE-2008-7072

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary web script or HTML via the start parameter.

    Published: 25 Aug 2009
    6.8
    Medium

    CVE-2008-7073

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/action/rss.php in RSS module 0.1 for Pie Web M{a,e}sher, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lib parameter.

    Published: 25 Aug 2009
    9.3
    Critical

    CVE-2008-7074

    Last Modified: 23 Apr 2026

    Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a server response, which is not properly handled "when displaying the signon message."

    Published: 25 Aug 2009
    6.5
    Medium

    CVE-2008-7076

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile photo, then accessing it via a direct request to the file in authorphoto/.

    Published: 25 Aug 2009
    5
    Medium

    CVE-2008-7080

    Last Modified: 23 Apr 2026

    Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

    Published: 25 Aug 2009
    10
    Critical

    CVE-2008-7081

    Last Modified: 23 Apr 2026

    userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges by setting the login parameter to admin. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7083

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Published: 25 Aug 2009
    9.3
    Critical

    CVE-2008-7079

    Last Modified: 23 Apr 2026

    Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a .M3U playlist file. NOTE: this issue might be related to CVE-2008-0619.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7069

    Last Modified: 23 Apr 2026

    All Club CMS (ACCMS) 0.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database configuration information, including credentials, via a direct request to accms.dat.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7077

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SailPlanner 0.3a allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Published: 25 Aug 2009
    6.8
    Medium

    CVE-2008-7062

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/.

    Published: 25 Aug 2009
    9.3
    Critical

    CVE-2008-7070

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI. NOTE: this might be due to an incomplete fix for CVE-2007-2951.

    Published: 25 Aug 2009
    7.5
    High

    CVE-2008-7075

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbitrary SQL commands via (1) the subcatid parameter to article.list.php; or the artid parameter to (2) article.print.php, (3) article.comments.php, (4) article.publisher.php, or (5) article.download.php; and (6) the PATH_INFO to article.download.php. NOTE: some of these details are obtained from third party information.

    Published: 25 Aug 2009
    9
    Critical

    CVE-2008-7078

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Rumpus before 6.0.1 allow remote attackers to (1) cause a denial of service (segmentation fault) via a long HTTP verb in the HTTP component; and allow remote authenticated users to execute arbitrary code via a long argument to the (2) MKD, (3) XMKD, (4) RMD, and other unspecified commands in the FTP component.

    Published: 25 Aug 2009
    6.8
    Medium

    CVE-2008-7082

    Last Modified: 23 Apr 2026

    MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header.

    Published: 25 Aug 2009
    7.2
    High

    CVE-2009-3525

    Last Modified: 23 Apr 2026

    The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.

    Published: 25 Aug 2009
    9.3
    Critical

    CVE-2008-7053

    Last Modified: 23 Apr 2026

    LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption.

    Published: 24 Aug 2009
    5
    Medium

    CVE-2008-7056

    Last Modified: 23 Apr 2026

    BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request.

    Published: 24 Aug 2009
    4.3
    Medium

    CVE-2008-7057

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbitrary HTML or web script via the type parameter.

    Published: 24 Aug 2009