CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2009-2717

    Last Modified: 23 Apr 2026

    The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet.

    Published: 10 Aug 2009
    6.8
    Medium

    CVE-2009-2718

    Last Modified: 23 Apr 2026

    The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended constraint on distance from the window border to the Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet.

    Published: 10 Aug 2009
    5
    Medium

    CVE-2009-2719

    Last Modified: 23 Apr 2026

    The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlp_file/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching Protocol (JNLP).

    Published: 10 Aug 2009
    5
    Medium

    CVE-2009-2720

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the javax.swing.plaf.synth.SynthContext.isSubregion method in the Swing implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException in the Jemmy library) via unknown vectors.

    Published: 10 Aug 2009
    10
    Critical

    CVE-2009-2721

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6406003.

    Published: 10 Aug 2009
    9.3
    Critical

    CVE-2009-2724

    Last Modified: 23 Apr 2026

    Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, related to a "3Y Race condition in reflection checks."

    Published: 10 Aug 2009
    10
    Critical

    CVE-2009-2722

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6429594. NOTE: this issue exists because of an incorrect fix for BugId 6406003.

    Published: 10 Aug 2009
    4.3
    Medium

    CVE-2008-6925

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Aug 2009
    4.3
    Medium

    CVE-2008-6927

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5) thispage, (6) thisapp, and (7) currentversion parameters in an Upgrade action.

    Published: 10 Aug 2009
    7.5
    High

    CVE-2009-2716

    Last Modified: 23 Apr 2026

    The plugin functionality in Sun Java SE 6 before Update 15 does not properly implement version selection, which allows context-dependent attackers to leverage vulnerabilities in "old zip and certificate handling" and have unspecified other impact via unknown vectors.

    Published: 10 Aug 2009
    10
    Critical

    CVE-2009-2723

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in deserialization in the Provider class in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, aka BugId 6444262.

    Published: 10 Aug 2009
    7.5
    High

    CVE-2008-6923

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter in a blogcategory action to index.php.

    Published: 10 Aug 2009
    10
    Critical

    CVE-2009-2415

    Last Modified: 23 Apr 2026

    Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.

    Published: 10 Aug 2009
    10
    Critical

    CVE-2009-2026

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in a token searching function in the dtscore library in Data Transport Services in CA Software Delivery r11.2 C1, C2, C3, and SP4; Unicenter Software Delivery 4.0 C3; CA Advantage Data Transport 3.0 C1; and CA IT Client Manager r12 allows remote attackers to execute arbitrary code via crafted data.

    Published: 10 Aug 2009
    9.3
    Critical

    CVE-2008-6922

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary code via a long argument to the (1) CreateUserPath, (2) Logout, (3) DeleteMailByUID, (4) MoveToInbox, (5) MoveToFolder, (6) DeleteMailEx, (7) GetMailDataEx, (8) SetReplySign, (9) SetForwardSign, and (10) SetReadSign methods, which are not properly handled by (a) the POP3 Class ActiveX control (CMailCom.POP3); or a long argument to the (11) AddAttach, (12) SetSubject, (13) SetBcc, (14) SetBody, (15) SetCc, (16) SetFrom, (17) SetTo, and (18) SetFromUID methods, which are not properly handled by the Class ActiveX control (CMailCOM.SMTP), as demonstrated via the indexOfMail parameter to mwmail.asp.

    Published: 10 Aug 2009
    7.5
    High

    CVE-2008-6921

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photoes/.

    Published: 10 Aug 2009
    6.8
    Medium

    CVE-2008-6918

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request to the file in galeria/.

    Published: 10 Aug 2009
    7.5
    High

    CVE-2008-6919

    Last Modified: 23 Apr 2026

    profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "fook!admin."

    Published: 10 Aug 2009
    7.5
    High

    CVE-2008-6920

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary code by uploading a file with an executable extension during a regnew action, then accessing it via a direct request to the file in photoes/.

    Published: 10 Aug 2009
    4.3
    Medium

    CVE-2009-3767

    Last Modified: 23 Apr 2026

    libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.

    Published: 10 Aug 2009
    6.8
    Medium

    CVE-2009-3766

    Last Modified: 23 Apr 2026

    mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 10 Aug 2009
    4.3
    Medium

    CVE-2009-2414

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework.

    Published: 10 Aug 2009
    6.5
    Medium

    CVE-2009-2416

    Last Modified: 23 Apr 2026

    Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.

    Published: 10 Aug 2009
    5
    Medium

    CVE-2009-2732

    Last Modified: 23 Apr 2026

    The checkHTTPpassword function in http.c in ntop 3.3.10 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an Authorization HTTP header that lacks a : (colon) character in the base64-decoded string.

    Published: 8 Aug 2009
    7.5
    High

    CVE-2008-6912

    Last Modified: 23 Apr 2026

    Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin/home.php.

    Published: 7 Aug 2009
    6.5
    Medium

    CVE-2008-6913

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile edit action, then accessing the file via a direct request to jobseekers/logos/.

    Published: 7 Aug 2009
    6.5
    Medium

    CVE-2008-6914

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/.

    Published: 7 Aug 2009
    4.3
    Medium

    CVE-2008-6915

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or HTML via the propid parameter.

    Published: 7 Aug 2009
    10
    Critical

    CVE-2008-6916

    Last Modified: 23 Apr 2026

    Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host header, possibly involving a trailing dot in the hostname.

    Published: 7 Aug 2009
    4.3
    Medium

    CVE-2009-2713

    Last Modified: 23 Apr 2026

    The CDCServlet component in Sun Java System Access Manager 7.0 2005Q4 and 7.1, when Cross Domain Single Sign On (CDSSO) is enabled, does not ensure that "policy advice" is presented to the correct client, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 7 Aug 2009
    4.9
    Medium

    CVE-2009-2711

    Last Modified: 23 Apr 2026

    XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than CVE-2009-1276.

    Published: 7 Aug 2009
    4.9
    Medium

    CVE-2009-2715

    Last Modified: 23 Apr 2026

    Sun VirtualBox 2.2 through 3.0.2 r49928 allows guest OS users to cause a denial of service (Linux host OS reboot) via a sysenter instruction.

    Published: 7 Aug 2009
    7.5
    High

    CVE-2008-6917

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQL commands via the username (user parameter).

    Published: 7 Aug 2009
    4.9
    Medium

    CVE-2009-2714

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun VirtualBox 3.0.0 and 3.0.2 allows guest OS users to cause a denial of service (host OS reboot) via unknown vectors.

    Published: 7 Aug 2009
    2.1
    Low

    CVE-2009-2712

    Last Modified: 23 Apr 2026

    Sun Java System Access Manager 6.3 2005Q1, 7.0 2005Q4, and 7.1; and OpenSSO Enterprise 8.0; when AMConfig.properties enables the debug flag, allows local users to discover cleartext passwords by reading debug files.

    Published: 7 Aug 2009
    6.8
    Medium

    CVE-2008-6911

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the loginUsername parameter to includes/logincheck.inc.php. NOTE: some of these details are obtained from third party information.

    Published: 6 Aug 2009
    6.5
    Medium

    CVE-2008-6909

    Last Modified: 23 Apr 2026

    Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact, probably related to man-in-the-middle attacks that modify critical data and allow remote attackers to impersonate other users and gain privileges.

    Published: 6 Aug 2009
    7.5
    High

    CVE-2008-6910

    Last Modified: 23 Apr 2026

    Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers to impersonate other users and gain privileges via a replay attack that sends the same request.

    Published: 6 Aug 2009
    6
    Medium

    CVE-2008-6905

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to hijack the authentication of administrators for requests that delete (1) categories or (2) groups; (3) ban users; or (4) delete users via the admin page.

    Published: 6 Aug 2009
    4.3
    Medium

    CVE-2008-6906

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BabbleBoard 1.1.6 allows remote attackers to inject arbitrary web script or HTML via the username.

    Published: 6 Aug 2009
    6.8
    Medium

    CVE-2008-6907

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, as accessible from a form generated by index.php.

    Published: 6 Aug 2009
    7.5
    High

    CVE-2008-6908

    Last Modified: 23 Apr 2026

    Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers to impersonate other users and gain privileges.

    Published: 6 Aug 2009
    6.8
    Medium

    CVE-2009-1728

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.

    Published: 6 Aug 2009
    7.5
    High

    CVE-2009-2192

    Last Modified: 23 Apr 2026

    MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue."

    Published: 6 Aug 2009
    10
    Critical

    CVE-2009-2193

    Last Modified: 23 Apr 2026

    Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet.

    Published: 6 Aug 2009
    4.9
    Medium

    CVE-2009-2194

    Last Modified: 23 Apr 2026

    Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which allows local users to cause a denial of service (system crash) by placing file descriptors in messages sent to a socket that has no receiver, related to a "synchronization issue."

    Published: 6 Aug 2009
    9.3
    Critical

    CVE-2009-2188

    Last Modified: 23 Apr 2026

    Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with crafted EXIF metadata.

    Published: 6 Aug 2009
    9.3
    Critical

    CVE-2009-1726

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile.

    Published: 6 Aug 2009
    6.8
    Medium

    CVE-2009-1727

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.

    Published: 6 Aug 2009
    7.8
    High

    CVE-2009-2190

    Last Modified: 23 Apr 2026

    launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connections to an inetd-based launchd service.

    Published: 6 Aug 2009