CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2009-0682

    Last Modified: 23 Apr 2026

    vetmonnt.sys in CA Internet Security Suite r3, vetmonnt.sys before 9.0.0.184 in Internet Security Suite r4, and vetmonnt.sys before 10.0.0.217 in Internet Security Suite r5 do not properly verify IOCTL calls, which allows local users to cause a denial of service (system crash) via a crafted call.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2009-2858

    Last Modified: 23 Apr 2026

    Memory leak in the Security component in IBM DB2 8.1 before FP18 on Unix platforms allows attackers to cause a denial of service (memory consumption) via unspecified vectors, related to private memory within the DB2 memory structure.

    Published: 19 Aug 2009
    4.6
    Medium

    CVE-2009-2859

    Last Modified: 23 Apr 2026

    IBM DB2 8.1 before FP18 allows attackers to obtain unspecified access via a das command.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2009-2860

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in db2jds in IBM DB2 8.1 before FP18 allows remote attackers to cause a denial of service (service crash) via "malicious packets."

    Published: 19 Aug 2009
    9.3
    Critical

    CVE-2009-2627

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the Acer LunchApp (aka AcerCtrls.APlunch) ActiveX control in acerctrl.ocx allows remote attackers to execute arbitrary commands via the Run method, a different vulnerability than CVE-2006-6121.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2009-2740

    Last Modified: 23 Apr 2026

    kmxIds.sys before 7.3.1.18 in CA Host-Based Intrusion Prevention System (HIPS) 8.1 allows remote attackers to cause a denial of service (system crash) via a malformed packet.

    Published: 19 Aug 2009
    10
    Critical

    CVE-2008-7004

    Last Modified: 23 Apr 2026

    Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.

    Published: 19 Aug 2009
    6.9
    Medium

    CVE-2008-7009

    Last Modified: 23 Apr 2026

    Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.

    Published: 19 Aug 2009
    10
    Critical

    CVE-2008-7010

    Last Modified: 23 Apr 2026

    Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a direct request to admin/register.php.

    Published: 19 Aug 2009
    7.8
    High

    CVE-2008-7012

    Last Modified: 23 Apr 2026

    courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2008-7013

    Last Modified: 23 Apr 2026

    NetService.dll in Baidu Hi IM allows remote servers to cause a denial of service (client crash) via a crafted login response that triggers a divide-by-zero error.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2008-7014

    Last Modified: 23 Apr 2026

    fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value.

    Published: 19 Aug 2009
    7.5
    High

    CVE-2008-7005

    Last Modified: 23 Apr 2026

    include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edit parameter. NOTE: this issue has been reported as an unrestricted file upload by some sources, but that is a potential consequence of code execution.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2008-7006

    Last Modified: 23 Apr 2026

    Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.

    Published: 19 Aug 2009
    7.5
    High

    CVE-2008-7007

    Last Modified: 23 Apr 2026

    Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting the (1) admin_name and (2) admin_pass cookie values to 1.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2008-7008

    Last Modified: 23 Apr 2026

    HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db.

    Published: 19 Aug 2009
    4
    Medium

    CVE-2008-7011

    Last Modified: 23 Apr 2026

    The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the Closing flag in UnChan.cpp is set.

    Published: 19 Aug 2009
    5
    Medium

    CVE-2008-7015

    Last Modified: 23 Apr 2026

    Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote attackers to cause a denial of service (server exit) via a packet with a large length value that triggers a memory allocation failure.

    Published: 19 Aug 2009
    4.3
    Medium

    CVE-2009-1874

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Management Console in Adobe JRun 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2009-1872

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.

    Published: 18 Aug 2009
    4
    Medium

    CVE-2009-1873

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2009-1877

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1875.

    Published: 18 Aug 2009
    5.8
    Medium

    CVE-2009-1878

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Adobe ColdFusion 8.0.1 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 18 Aug 2009
    5
    Medium

    CVE-2009-1876

    Last Modified: 23 Apr 2026

    Adobe ColdFusion 8.0.1 and earlier might allow attackers to obtain sensitive information via unspecified vectors, related to a "double-encoded null character vulnerability."

    Published: 18 Aug 2009
    3.5
    Low

    CVE-2009-2856

    Last Modified: 23 Apr 2026

    Sun Virtual Desktop Infrastructure (VDI) 3.0, when anonymous binding is enabled, does not properly handle a client's attempt to establish an authenticated and encrypted connection, which might allow remote attackers to read cleartext VDI configuration-data requests by sniffing LDAP sessions on the network.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2009-1875

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion 8.0.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1877.

    Published: 18 Aug 2009
    6.8
    Medium

    CVE-2009-2852

    Last Modified: 23 Apr 2026

    WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.

    Published: 18 Aug 2009
    10
    Critical

    CVE-2009-2853

    Last Modified: 23 Apr 2026

    Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7) edit-page-form.php, and (8) edit-tag-form.php in wp-admin/.

    Published: 18 Aug 2009
    9.3
    Critical

    CVE-2009-2850

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) LastRecord64, (4) CDFsel64, and other unspecified functions.

    Published: 18 Aug 2009
    6.4
    Medium

    CVE-2009-2854

    Last Modified: 23 Apr 2026

    Wordpress before 2.8.3 does not check capabilities for certain actions, which allows remote attackers to make unauthorized edits or additions via a direct request to (1) edit-comments.php, (2) edit-pages.php, (3) edit.php, (4) edit-category-form.php, (5) edit-link-category-form.php, (6) edit-tag-form.php, (7) export.php, (8) import.php, or (9) link-add.php in wp-admin/.

    Published: 18 Aug 2009
    7.8
    High

    CVE-2009-2846

    Last Modified: 23 Apr 2026

    The eisa_eeprom_read function in the parisc isa-eeprom component (drivers/parisc/eisa_eeprom.c) in the Linux kernel before 2.6.31-rc6 allows local users to access restricted memory via a negative ppos argument, which bypasses a check that assumes that ppos is positive and causes an out-of-bounds read in the readb function.

    Published: 18 Aug 2009
    7.8
    High

    CVE-2009-2844

    Last Modified: 23 Apr 2026

    cfg80211 in net/wireless/scan.c in the Linux kernel 2.6.30-rc1 and other versions before 2.6.31-rc6 allows remote attackers to cause a denial of service (crash) via a sequence of beacon frames in which one frame omits an SSID Information Element (IE) and the subsequent frame contains an SSID IE, which triggers a NULL pointer dereference in the cmp_ies function. NOTE: a potential weakness in the is_mesh function was also addressed, but the relevant condition did not exist in the code, so it is not a vulnerability.

    Published: 18 Aug 2009
    Unknown

    CVE-2009-2845

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2768. Reason: This candidate is a duplicate of CVE-2009-2768. Notes: All CVE users should reference CVE-2009-2768 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2008-6977

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inject arbitrary web script or HTML via the message parameter in a summary action.

    Published: 18 Aug 2009
    6.8
    Medium

    CVE-2008-6978

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in pics/, related to the uploadmedia action in album.asp.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2008-6979

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to inject arbitrary web script or HTML via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue might be resultant from a separate SQL injection vulnerability.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-6980

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in as_archives.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to execute arbitrary SQL commands via the results_per_page parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 18 Aug 2009
    5.8
    Medium

    CVE-2008-6984

    Last Modified: 23 Apr 2026

    Plesk 8.6.0, when short mail login names (SHORTNAMES) are enabled, allows remote attackers to bypass authentication and send spam e-mail via a message with (1) a base64-encoded username that begins with a valid shortname, or (2) a username that matches a valid password, as demonstrated using (a) SMTP and qmail, and (b) Courier IMAP and POP3.

    Published: 18 Aug 2009
    6.8
    Medium

    CVE-2008-6985

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in includes/classes/shopping_cart.php in Zen Cart 1.2.0 through 1.3.8a, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter when (1) adding or (2) updating the shopping cart.

    Published: 18 Aug 2009
    6.8
    Medium

    CVE-2008-6986

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the actionMultipleAddProduct function in includes/classes/shopping_cart.php in Zen Cart 1.3.0 through 1.3.8a, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the products_id array parameter in a multiple_products_add_product action, a different vulnerability than CVE-2008-6985.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-6987

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in eZoneScripts Dating Website script allows remote attackers to execute arbitrary code via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2008-6988

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) galleryid parameter to gallery.php, and the (2) size or (3) imageid parameters to show.php.

    Published: 18 Aug 2009
    10
    Critical

    CVE-2008-6993

    Last Modified: 23 Apr 2026

    Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Aug 2009
    5
    Medium

    CVE-2008-6996

    Last Modified: 23 Apr 2026

    Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for remote attackers or malware to cause a denial of service (disk consumption) or exploit other vulnerabilities via a URL that references an executable file, possibly related to the "ask where to save each file before downloading" setting.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2008-6997

    Last Modified: 23 Apr 2026

    Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-7000

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be related to CVE-2005-2255.1.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-7001

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the file manager in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-7003

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary SQL commands via the (1) user_id and (2) password parameter.

    Published: 18 Aug 2009
    5
    Medium

    CVE-2008-6981

    Last Modified: 23 Apr 2026

    index.php in phpAdultSite CMS, possibly 2.3.2, allows remote attackers to obtain the full installation path via an invalid results_per_page parameter, which leaks the path in an error message. NOTE: this issue might be resultant from a separate SQL injection vulnerability.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-6989

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 18 Aug 2009