CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2009-2056

    Last Modified: 23 Apr 2026

    Cisco IOS XR 3.8.1 and earlier allows remote authenticated users to cause a denial of service (process crash) via vectors involving a BGP UPDATE message with many AS numbers prepended to the AS path.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2008-7017

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in analyse.php in CAcert 20080921, and possibly other versions before 20080928, allows remote attackers to inject arbitrary web script or HTML via the CN (CommonName) field in the subject of an X.509 certificate.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2008-7018

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in NashTech Easy PHP Calendar 6.3.25 allows remote attackers to inject arbitrary web script or HTML via the Details field (descr parameter) in an Add New Event action in an unspecified request as generated by an add action in index.php.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2008-7019

    Last Modified: 23 Apr 2026

    Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.

    Published: 21 Aug 2009
    2.1
    Low

    CVE-2008-7020

    Last Modified: 23 Apr 2026

    McAfee SafeBoot Device Encryption 4 build 4750 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

    Published: 21 Aug 2009
    6
    Medium

    CVE-2008-7021

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as an image or logo, then accessing it via a direct request to the file in an unspecified directory.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2008-7027

    Last Modified: 23 Apr 2026

    Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.

    Published: 21 Aug 2009
    10
    Critical

    CVE-2008-7023

    Last Modified: 23 Apr 2026

    Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, which allows remote attackers to bypass authentication. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's security documentation.

    Published: 21 Aug 2009
    6.8
    Medium

    CVE-2008-7024

    Last Modified: 23 Apr 2026

    admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by setting the user cookie to "admin" and setting the name parameter to "users."

    Published: 21 Aug 2009
    7.5
    High

    CVE-2008-7028

    Last Modified: 23 Apr 2026

    RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.

    Published: 21 Aug 2009
    6.8
    Medium

    CVE-2008-7016

    Last Modified: 23 Apr 2026

    tnftpd before 20080929 splits large command strings into multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unknown vectors, probably involving a crafted ftp:// link to a tnftpd server.

    Published: 21 Aug 2009
    9.3
    Critical

    CVE-2008-7022

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.ChilkatMailMan2.1) allows remote attackers to execute arbitrary programs via the LoadXmlEmail method.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2008-7025

    Last Modified: 23 Apr 2026

    TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.

    Published: 21 Aug 2009
    6.8
    Medium

    CVE-2008-7026

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2009-2920

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Elvin 1.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) component and (2) priority parameters to buglist.php; and the (3) Username (4) E-mail, (5) Pass, and (6) Confirm pass fields to createaccount.php.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2009-2917

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2921

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).

    Published: 21 Aug 2009
    7.8
    High

    CVE-2009-2922

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in pixaria.image.php in Pixaria Gallery 2.0.0 through 2.3.5 allows remote attackers to read arbitrary files via a base64-encoded file parameter.

    Published: 21 Aug 2009
    5
    Medium

    CVE-2009-2923

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2924

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Videos Broadcast Yourself 2 allow remote attackers to execute arbitrary SQL commands via the (1) UploadID parameter to videoint.php, and possibly the (2) cat_id parameter to catvideo.php and (3) uid parameter to cviewchannels.php.

    Published: 21 Aug 2009
    7.8
    High

    CVE-2009-2925

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in DJcalendar.cgi in DJCalendar allows remote attackers to read arbitrary files via a .. (dot dot) in the TEMPLATE parameter.

    Published: 21 Aug 2009
    3.5
    Low

    CVE-2009-2919

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Boonex Orca 2.0 and 2.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the topic title field.

    Published: 21 Aug 2009
    2.1
    Low

    CVE-2009-2918

    Last Modified: 23 Apr 2026

    The tgbvpn.sys driver in TheGreenBow IPSec VPN Client 4.61.003 allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted request to the 0x80000034 IOCTL, probably involving an input or output buffer size of 0.

    Published: 21 Aug 2009
    9.3
    Critical

    CVE-2009-2916

    Last Modified: 23 Apr 2026

    Format string vulnerability in the CNS_AddTxt function in logs.dll in 2K Games Vietcong 2 1.10 and earlier might allow remote attackers to execute arbitrary code via format string specifiers in the nickname.

    Published: 21 Aug 2009
    7.5
    High

    CVE-2009-2915

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in 2fly_gift.php in 2FLY Gift Delivery System 6.0 allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a content action.

    Published: 21 Aug 2009
    5
    Medium

    CVE-2009-2953

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash property (aka location.hash), a related issue to CVE-2008-5715.

    Published: 21 Aug 2009
    4.3
    Medium

    CVE-2009-5017

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-1210.

    Published: 21 Aug 2009
    7.8
    High

    CVE-2009-0638

    Last Modified: 23 Apr 2026

    The Cisco Firewall Services Module (FWSM) 2.x, 3.1 before 3.1(16), 3.2 before 3.2(13), and 4.0 before 4.0(6) for Cisco Catalyst 6500 switches and Cisco 7600 routers allows remote attackers to cause a denial of service (traffic-handling outage) via a series of malformed ICMP messages.

    Published: 20 Aug 2009
    4.9
    Medium

    CVE-2009-2912

    Last Modified: 23 Apr 2026

    The (1) sendfile and (2) sendfilev functions in Sun Solaris 8 through 10, and OpenSolaris before snv_110, allow local users to cause a denial of service (panic) via vectors related to vnode function calls.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2914

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the name of an uploaded file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Aug 2009
    Unknown

    CVE-2009-2962

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2692. Reason: This candidate is a duplicate of CVE-2009-2692. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2009-2692 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2913

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in XZero Community Classifieds 4.97.8 allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2894

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to product_desc.php, and the cid parameter to (2) showcategory.php and (3) gallery.php.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2886

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2882

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PG MatchMaking allow remote attackers to inject arbitrary web script or HTML via the show parameter to (1) browse_ladies.php and (2) browse_men.php, the (3) gender parameter to search.php, and the (4) id parameter to services.php.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2893

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in XZero Community Classifieds 4.97.8 allow remote attackers to inject arbitrary web script or HTML via (1) the postevent parameter in a post action or (2) the _xzcal_y parameter.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2884

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to inject arbitrary web script or HTML via the rank parameter.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2881

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Basilic 1.5.13 allow remote attackers to execute arbitrary SQL commands via the idAuthor parameter to (1) index.php and possibly (2) allpubs.php in publications/.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2885

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bios.php in PHP Scripts Now World's Tallest Buildings allows remote attackers to execute arbitrary SQL commands via the rank parameter.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2887

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2888

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to execute arbitrary SQL commands via the n parameter.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2889

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHP Scripts Now Hangman allows remote attackers to inject arbitrary web script or HTML via the letters parameter.

    Published: 20 Aug 2009
    4.3
    Medium

    CVE-2009-2890

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arbitrary web script or HTML via the searchquery parameter.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2891

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list.php in PHP Scripts Now Riddles allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2892

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie.

    Published: 20 Aug 2009
    7.5
    High

    CVE-2009-2895

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 20 Aug 2009
    9.3
    Critical

    CVE-2009-2896

    Last Modified: 23 Apr 2026

    Buffer overflow in KMplayer 2.9.4.1433 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a subtitle (.srt) playlist file. NOTE: some of these details are obtained from third party information.

    Published: 20 Aug 2009
    6.8
    Medium

    CVE-2009-2883

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in SaphpLesson 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cp_username parameter, related to an error in the CleanVar function in includes/functions.php.

    Published: 20 Aug 2009
    5.9
    Medium

    CVE-2009-2055

    Last Modified: 22 Apr 2026

    Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE message with an invalid attribute, as demonstrated in the wild on 17 August 2009.

    Published: 19 Aug 2009
    5.5
    Medium

    CVE-2009-2857

    Last Modified: 23 Apr 2026

    The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the filesystem and virtual-memory implementations, which allows local users to cause a denial of service (deadlock and system halt) via vectors involving mmap and write operations on the same file.

    Published: 19 Aug 2009