CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6991

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL commands via the id_rub_page parameter.

    Published: 18 Aug 2009
    9.3
    Critical

    CVE-2008-6998

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.

    Published: 18 Aug 2009
    6.4
    Medium

    CVE-2008-6976

    Last Modified: 23 Apr 2026

    MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2008-6982

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web script or HTML via the currentpath parameter.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-6983

    Last Modified: 23 Apr 2026

    modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-6990

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2008-6992

    Last Modified: 23 Apr 2026

    GreenSQL Firewall (greensql-fw), possibly before 0.9.2 or 0.9.4, allows remote attackers to bypass the SQL injection protection mechanism via a WHERE clause containing an expression such as "x=y=z", which is successfully parsed by MySQL.

    Published: 18 Aug 2009
    9.3
    Critical

    CVE-2008-6994

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.149.27 allows user-assisted remote attackers to execute arbitrary code via a web page with a long TITLE element, which triggers the overflow when the user saves the page and a long filename is generated. NOTE: it might be possible to exploit this issue via an HTTP response that includes a long filename in a Content-Disposition header.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2008-6995

    Last Modified: 23 Apr 2026

    Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a denial of service (browser crash) via a URI with an invalid handler followed by a "%" (percent) character, which triggers a buffer over-read, as demonstrated using an "about:%" URI.

    Published: 18 Aug 2009
    5
    Medium

    CVE-2008-6999

    Last Modified: 23 Apr 2026

    phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Published: 18 Aug 2009
    8.5
    High

    CVE-2009-3369

    Last Modified: 23 Apr 2026

    CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore.

    Published: 18 Aug 2009
    5.8
    Medium

    CVE-2009-2474

    Last Modified: 23 Apr 2026

    neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2009-1884

    Last Modified: 23 Apr 2026

    Off-by-one error in the bzinflate function in Bzip2.xs in the Compress-Raw-Bzip2 module before 2.018 for Perl allows context-dependent attackers to cause a denial of service (application hang or crash) via a crafted bzip2 compressed stream that triggers a buffer overflow, a related issue to CVE-2009-1391.

    Published: 18 Aug 2009
    4.3
    Medium

    CVE-2009-2473

    Last Modified: 23 Apr 2026

    neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 18 Aug 2009
    10
    Critical

    CVE-2009-2694

    Last Modified: 23 Apr 2026

    The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim) before 2.5.9 and Adium 1.3.5 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) by sending multiple crafted SLP (aka MSNSLP) messages to trigger an overwrite of an arbitrary memory location. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1376.

    Published: 18 Aug 2009
    7.5
    High

    CVE-2009-2786

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in reputation.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the poster parameter.

    Published: 17 Aug 2009
    4.3
    Medium

    CVE-2009-2785

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter to buy.php and the id parameter to (2) contact.php and (3) tellafriend.php.

    Published: 17 Aug 2009
    4.3
    Medium

    CVE-2009-2780

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to category.php, view parameter to (2) login.php and (3) viewlisting.php, page parameter to (4) searchresults.php and (5) toplistings.php, and (6) member parameter to viewmember.php.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2792

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in plugings/pagecontent.php in Really Simple CMS (RSCMS) 0.3a allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PT parameter.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2782

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2790

    Last Modified: 6 Apr 2026

    SQL injection vulnerability in cat_products.php in SoftBiz Dating Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. NOTE: this might overlap CVE-2006-3271.4.

    Published: 17 Aug 2009
    4.3
    Medium

    CVE-2009-2783

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) op parameter to modules/pm/viewpmsg.php and (2) query string to modules/profile/user.php.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2788

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mobilelib GOLD 3 allow remote attackers to execute arbitrary SQL commands via the (1) adminName parameter to cp/auth.php, (2) cid parameter to artcat.php, and (3) catid parameter to show.php.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Permis (com_groups) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a list action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2791

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pda_projects.php in WebDynamite ProjectButler 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the offset parameter.

    Published: 17 Aug 2009
    6.8
    Medium

    CVE-2009-2787

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, and earlier for PunBB, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pun_user[language] parameter.

    Published: 17 Aug 2009
    9.3
    Critical

    CVE-2009-2784

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path parameter to index.php in (1) install/, (2) menus/left_rightslideopen/, (3) menus/side_pullout/, (4) menus/side_slideopen/, (5) menus/simple/, (6) menus/top_dropdown/, and (7) menus/topside/; the sitemap parameter to index.php in (8) menus/left_rightslideopen/, (9) menus/side_pullout/, (10) menus/side_slideopen/, (11) menus/top_dropdown/, and (12) menus/topside/; and the (13) relPath parameter to index/index.php. NOTE: PHP remote file inclusion vulnerabilities reportedly also exist for some of these vectors.

    Published: 17 Aug 2009
    6
    Medium

    CVE-2009-2781

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an addcomment action, a different vector than CVE-2006-1666.

    Published: 17 Aug 2009
    7.5
    High

    CVE-2009-2779

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via the id parameter in a productdetail action.

    Published: 17 Aug 2009
    4
    Medium

    CVE-2009-5006

    Last Modified: 11 Apr 2025

    The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash, and cluster outage) by attempting to modify the alternate of an exchange.

    Published: 16 Aug 2009
    4.3
    Medium

    CVE-2009-3007

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.

    Published: 15 Aug 2009
    7.5
    High

    CVE-2009-2773

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 14 Aug 2009
    7.5
    High

    CVE-2009-2775

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 14 Aug 2009
    7.5
    High

    CVE-2009-2776

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 14 Aug 2009
    7.5
    High

    CVE-2009-2777

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 14 Aug 2009
    4.3
    Medium

    CVE-2009-2778

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arbitrary web script or HTML via the key parameter. NOTE: some of these details are obtained from third party information.

    Published: 14 Aug 2009
    7.5
    High

    CVE-2009-2774

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 14 Aug 2009
    4.3
    Medium

    CVE-2009-2772

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.

    Published: 14 Aug 2009
    4.3
    Medium

    CVE-2009-2771

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to the default URI under search/.

    Published: 14 Aug 2009
    7.5
    High

    CVE-2009-2770

    Last Modified: 23 Apr 2026

    PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.

    Published: 14 Aug 2009
    6.8
    Medium

    CVE-2009-2769

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.

    Published: 14 Aug 2009
    7.8
    High

    CVE-2009-2768

    Last Modified: 23 Apr 2026

    The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by executing a shared flat binary, which triggers an access of an "uninitialized cred pointer."

    Published: 14 Aug 2009
    7.5
    High

    CVE-2009-2766

    Last Modified: 23 Apr 2026

    httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.

    Published: 14 Aug 2009
    6.8
    Medium

    CVE-2008-6975

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters. NOTE: This issue reportedly exists because of a "weak ... anti-CSRF fix" implemented in 24 sp2.

    Published: 14 Aug 2009
    8.3
    High

    CVE-2009-2765

    Last Modified: 23 Apr 2026

    httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.

    Published: 14 Aug 2009
    6.8
    Medium

    CVE-2009-2677

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 14 Aug 2009
    5
    Medium

    CVE-2009-2764

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.

    Published: 14 Aug 2009
    9.8
    Critical

    CVE-2009-1048

    Last Modified: 23 Apr 2026

    The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make arbitrary use of the phone, via a (1) http or (2) https request with 127.0.0.1 in the Host header.

    Published: 14 Aug 2009
    6.8
    Medium

    CVE-2008-6974

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters.

    Published: 14 Aug 2009
    3.3
    Low

    CVE-2009-5081

    Last Modified: 11 Apr 2025

    The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.

    Published: 14 Aug 2009