CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2009-2597

    Last Modified: 23 Apr 2026

    The Sun Java System (SJS) Access Manager Policy Agent module 2.2 for SJS Web Proxy Server 4.0 allows remote attackers to cause a denial of service (daemon crash) via a GET request.

    Published: 27 Jul 2009
    7.5
    High

    CVE-2009-2603

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Escon SupportPortal Pro 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat and (2) tid parameters.

    Published: 27 Jul 2009
    7.5
    High

    CVE-2009-2604

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in adminlogin.asp in Zen Help Desk 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) userid (aka username) and (2) PassWord parameters to admin.asp.

    Published: 27 Jul 2009
    6.8
    Medium

    CVE-2009-2605

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.

    Published: 27 Jul 2009
    5
    Medium

    CVE-2009-2606

    Last Modified: 23 Apr 2026

    ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for NFL.mdb.

    Published: 27 Jul 2009
    5
    Medium

    CVE-2009-2602

    Last Modified: 23 Apr 2026

    R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for admin.mdb.

    Published: 27 Jul 2009
    7.1
    High

    CVE-2009-4308

    Last Modified: 23 Apr 2026

    The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference), and possibly have unspecified other impact, via a crafted read-only filesystem that lacks a journal.

    Published: 27 Jul 2009
    5
    Medium

    CVE-2009-2651

    Last Modified: 23 Apr 2026

    main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer.

    Published: 27 Jul 2009
    5
    Medium

    CVE-2009-2621

    Last Modified: 23 Apr 2026

    Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.

    Published: 27 Jul 2009
    5
    Medium

    CVE-2009-2622

    Last Modified: 23 Apr 2026

    Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.

    Published: 27 Jul 2009
    4.3
    Medium

    CVE-2011-1471

    Last Modified: 11 Apr 2025

    Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.

    Published: 27 Jul 2009
    4.3
    Medium

    CVE-2008-6876

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2008-6874

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQL commands via the iType parameter in (1) Auto1/type.asp or (2) auto2/type.asp.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2009-2590

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showcategory.php in Hutscripts PHP Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2009-2591

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MyAnnonces module for E-Xoopport 3.1 allows remote attackers to execute arbitrary SQL commands via the lid parameter in a viewannonces action to index.php.

    Published: 24 Jul 2009
    4.3
    Medium

    CVE-2009-2595

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in productSearch.html in Censura 2.0.4 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a ProductSearch action.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2008-6875

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2009-2585

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a member cookie in an account editprofile action, a different vector than CVE-2009-1731.

    Published: 24 Jul 2009
    4.3
    Medium

    CVE-2009-2586

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Published: 24 Jul 2009
    4.3
    Medium

    CVE-2009-2587

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search parameter to (3) index.php and (4) search.php, the (5) redirect parameter to login.php, and the (6) product parameter to productdetail.php.

    Published: 24 Jul 2009
    4.3
    Medium

    CVE-2009-2588

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Hotscripts Type PHP Clone Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.

    Published: 24 Jul 2009
    4.3
    Medium

    CVE-2009-2589

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Hutscripts PHP Website Script allow remote attackers to inject arbitrary web script or HTML via the msg parameter to (1) feedback.php, (2) index.php, and (3) lostpassword.php.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2009-2592

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in guestbook.php in PHPJunkYard GBook 1.6 allows remote attackers to execute arbitrary SQL commands via the mes_id parameter.

    Published: 24 Jul 2009
    7.5
    High

    CVE-2009-2593

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.

    Published: 24 Jul 2009
    4.3
    Medium

    CVE-2009-2594

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in censura.php in Censura 1.16.04 allows remote attackers to inject arbitrary web script or HTML via the itemid parameter in a details action.

    Published: 24 Jul 2009
    6.5
    Medium

    CVE-2009-5078

    Last Modified: 11 Apr 2025

    contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.

    Published: 24 Jul 2009
    3.3
    Low

    CVE-2009-5044

    Last Modified: 11 Apr 2025

    contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.

    Published: 24 Jul 2009
    5.8
    Medium

    CVE-2009-2654

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

    Published: 24 Jul 2009
    7.2
    High

    CVE-2009-2584

    Last Modified: 23 Apr 2026

    Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux kernel 2.6.30.2 and earlier on ia64 and x86 platforms might allow local users to overwrite arbitrary memory locations and gain privileges via a crafted count argument, which triggers a stack-based buffer overflow.

    Published: 23 Jul 2009
    6.8
    Medium

    CVE-2009-2583

    Last Modified: 23 Apr 2026

    Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack web sessions via unspecified vectors involving the (1) console and (2) self service interfaces.

    Published: 23 Jul 2009
    9.3
    Critical

    CVE-2009-2582

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2007-1891 and CVE-2007-1892.

    Published: 23 Jul 2009
    7.5
    High

    CVE-2008-6873

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the TabOpenQuickTab1 parameter to (1) popaccounts.aspx, (2) addressbook.aspx, and (3) emails.aspx.

    Published: 23 Jul 2009
    4.3
    Medium

    CVE-2008-6868

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default/login.php in EditeurScripts EsBaseAdmin 2.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the EsContacts 1.0 issue is covered in CVE-2008-2037.

    Published: 23 Jul 2009
    4.3
    Medium

    CVE-2009-2581

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 23 Jul 2009
    Unknown

    CVE-2009-2580

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1862. Reason: This candidate is a duplicate of CVE-2009-1862. Notes: All CVE users should reference CVE-2009-1862 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Jul 2009
    5
    Medium

    CVE-2008-6869

    Last Modified: 23 Apr 2026

    Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini.

    Published: 23 Jul 2009
    5
    Medium

    CVE-2008-6870

    Last Modified: 23 Apr 2026

    Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) config.asp and (2) users.asp.

    Published: 23 Jul 2009
    5
    Medium

    CVE-2008-6872

    Last Modified: 23 Apr 2026

    ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/aspthaiForum.mdb.

    Published: 23 Jul 2009
    5
    Medium

    CVE-2008-6871

    Last Modified: 23 Apr 2026

    Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitive information via a direct request.

    Published: 23 Jul 2009
    7.5
    High

    CVE-2009-4018

    Last Modified: 23 Apr 2026

    The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.

    Published: 23 Jul 2009
    7.5
    High

    CVE-2010-1632

    Last Modified: 11 Apr 2025

    Apache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, IBM Feature Pack for Web 2.0 1.0.1.0, Apache Synapse, Apache ODE, Apache Tuscany, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to the Synapse SimpleStockQuoteService.

    Published: 23 Jul 2009
    5
    Medium

    CVE-2009-2576

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479. NOTE: it was later reported that 7.0.6000.16473 and earlier are also affected.

    Published: 22 Jul 2009
    10
    Critical

    CVE-2009-2468

    Last Modified: 23 Apr 2026

    Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

    Published: 22 Jul 2009
    7.1
    High

    CVE-2009-2575

    Last Modified: 23 Apr 2026

    The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption and browser crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 22 Jul 2009
    5
    Medium

    CVE-2009-2577

    Last Modified: 23 Apr 2026

    Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption, and application hang) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.

    Published: 22 Jul 2009
    5
    Medium

    CVE-2009-2578

    Last Modified: 23 Apr 2026

    Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Unicode string argument to the write method, a related issue to CVE-2009-2479.

    Published: 22 Jul 2009
    6.5
    Medium

    CVE-2009-2574

    Last Modified: 23 Apr 2026

    index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.

    Published: 22 Jul 2009
    6.8
    Medium

    CVE-2009-2572

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Fivestar module 5.x-1.x before 5.x-1.14 and 6.x-1.x before 6.x-1.14, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users for requests that cast votes.

    Published: 22 Jul 2009
    4.3
    Medium

    CVE-2009-2571

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to inject arbitrary web script or HTML via (1) the URI, (2) the q parameter, (3) the nick parameter, or (4) the nick parameter in a bantest action.

    Published: 22 Jul 2009
    4.3
    Medium

    CVE-2009-2569

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Verlihub Control Panel (VHCP) 1.7e allow remote attackers to inject arbitrary web script or HTML via (1) the nick parameter in a login action to index.php or (2) the URI in a news request to index.html.

    Published: 22 Jul 2009