CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2009-2573

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php.

    Published: 22 Jul 2009
    7.5
    High

    CVE-2009-2567

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 22 Jul 2009
    9.3
    Critical

    CVE-2009-2570

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Symantec.FaxViewerControl.1 ActiveX control in WinFax\DCCFAXVW.DLL in Symantec WinFax Pro 10.03 allows remote attackers to execute arbitrary code via a long argument to the AppendFax method.

    Published: 22 Jul 2009
    9.3
    Critical

    CVE-2009-2568

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.

    Published: 22 Jul 2009
    4.3
    Medium

    CVE-2009-2405

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web script or HTML via the (1) monitorName, (2) objectName, (3) attribute, or (4) period parameter to createSnapshot.jsp, or the (5) monitorName, (6) objectName, (7) attribute, (8) threshold, (9) period, or (10) enabled parameter to createThresholdMonitor.jsp. NOTE: some of these details are obtained from third party information.

    Published: 22 Jul 2009
    10
    Critical

    CVE-2009-2466

    Last Modified: 25 Jun 2025

    The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2465

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.

    Published: 21 Jul 2009
    4.3
    Medium

    CVE-2009-2472

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2467

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2469

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2462

    Last Modified: 23 Apr 2026

    The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2463

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2464

    Last Modified: 23 Apr 2026

    The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.

    Published: 21 Jul 2009
    10
    Critical

    CVE-2009-2471

    Last Modified: 23 Apr 2026

    The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.

    Published: 21 Jul 2009
    9.3
    Critical

    CVE-2009-2566

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary code via a long string in a playlist (.m3u) file.

    Published: 21 Jul 2009
    4.3
    Medium

    CVE-2009-2565

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Perl CGI's By Mrs. Shiromuku shiromuku(fs6)DIARY 2.40 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Jul 2009
    7.2
    High

    CVE-2009-2564

    Last Modified: 23 Apr 2026

    NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM privileges by replacing getPlus_HelperSvc.exe with a Trojan horse program, as demonstrated by use of getPlus Download Manager within Adobe Reader. NOTE: within Adobe Reader, the scope of this issue is limited because the program is deleted and the associated service is not automatically launched after a successful installation and reboot.

    Published: 21 Jul 2009
    5
    Medium

    CVE-2009-2557

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the fichier parameter.

    Published: 21 Jul 2009
    7.5
    High

    CVE-2009-2558

    Last Modified: 23 Apr 2026

    system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct request.

    Published: 21 Jul 2009
    9.3
    Critical

    CVE-2009-2556

    Last Modified: 23 Apr 2026

    Google Chrome before 2.0.172.37 allows attackers to leverage renderer access to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger excessive memory allocation.

    Published: 21 Jul 2009
    9.3
    Critical

    CVE-2009-2555

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.

    Published: 21 Jul 2009
    5
    Medium

    CVE-2009-2470

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a long domain name in a reply.

    Published: 21 Jul 2009
    7.8
    High

    CVE-2009-1862

    Last Modified: 22 Apr 2026

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

    Published: 21 Jul 2009
    4.3
    Medium

    CVE-2009-2546

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Advanced Electron Forum (AEF) 1.x allows remote attackers to determine the existence of arbitrary files via the avatargalfile parameter when changing an avatar, which leaks the existence of the file in an error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Jul 2009
    10
    Critical

    CVE-2009-2548

    Last Modified: 23 Apr 2026

    Format string vulnerability in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the (1) nickname and (2) datafile fields in a join request, which is not properly handled when logging an error message.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2549

    Last Modified: 23 Apr 2026

    Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service via a join packet with a final field whose value is (1) 0, which triggers a server crash related to memory allocation, or (2) 1, which triggers CPU/memory consumption and a NULL pointer dereference.

    Published: 20 Jul 2009
    6.8
    Medium

    CVE-2009-2553

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the entry parameter.

    Published: 20 Jul 2009
    4.3
    Medium

    CVE-2009-2551

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject arbitrary web script or HTML via the id parameter in a detail action to (1) main.php and possibly (2) demo_page.php.

    Published: 20 Jul 2009
    9.3
    Critical

    CVE-2009-2550

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl playlist file.

    Published: 20 Jul 2009
    6.8
    Medium

    CVE-2009-2554

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the search method in jobline.class.php in Jobline (com_jobline) 1.1.2.2, 1.3.1, and possibly earlier versions, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the search parameter in a results action to index.php, which invokes the search method from the searchJobPostings function in jobline.php.

    Published: 20 Jul 2009
    6.8
    Medium

    CVE-2009-2545

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Advanced Electron Forum (AEF) 1.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the filename in an uploaded attachment. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2547

    Last Modified: 23 Apr 2026

    Integer underflow in Armed Assault (aka ArmA) 1.14 and earlier, and 1.16 beta, and Armed Assault II 1.02 and earlier allows remote attackers to cause a denial of service (crash) via a VoIP over Network (VON) packet to port 2305 with a negative packet_size value, which triggers a buffer over-read.

    Published: 20 Jul 2009
    6.8
    Medium

    CVE-2009-2552

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in comments.php in Super Simple Blog Script 2.5.4 allow remote attackers to overwrite, include, and execute arbitrary local files via the entry parameter.

    Published: 20 Jul 2009
    7.1
    High

    CVE-2009-2538

    Last Modified: 23 Apr 2026

    The Nokia N95 running Symbian OS 9.2, N82, and N810 Internet Tablet allow remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 20 Jul 2009
    4.3
    Medium

    CVE-2009-2540

    Last Modified: 23 Apr 2026

    Opera, possibly 9.64 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 20 Jul 2009
    4.3
    Medium

    CVE-2009-2542

    Last Modified: 23 Apr 2026

    Netscape 6 and 8 allows remote attackers to cause a denial of service (memory consumption) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 20 Jul 2009
    7.8
    High

    CVE-2009-2539

    Last Modified: 23 Apr 2026

    The Aigo P8860 allows remote attackers to cause a denial of service (memory consumption and browser hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 20 Jul 2009
    10
    Critical

    CVE-2009-2543

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allow remote attackers to bypass detection of malware via a modified (1) ZIP or (2) CAB archive, a related issue to CVE-2009-1240.

    Published: 20 Jul 2009
    4.3
    Medium

    CVE-2009-2536

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 20 Jul 2009
    7.5
    High

    CVE-2009-2541

    Last Modified: 23 Apr 2026

    The web browser on the Sony PLAYSTATION 3 (PS3) allows remote attackers to cause a denial of service (memory consumption and console hang) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

    Published: 20 Jul 2009
    6.8
    Medium

    CVE-2009-2544

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2533

    Last Modified: 23 Apr 2026

    rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2534

    Last Modified: 23 Apr 2026

    RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (daemon crash) via an RTSP SETUP request that (1) specifies the / URI or (2) lacks a / character in the URI.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2559

    Last Modified: 23 Apr 2026

    Buffer overflow in the IPMI dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an array index error. NOTE: some of these details are obtained from third party information.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2560

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Wireshark 1.2.0 allow remote attackers to cause a denial of service (application crash) via a file that records a malformed packet trace and is processed by the (1) Bluetooth L2CAP, (2) RADIUS, or (3) MIOP dissector. NOTE: it was later reported that the RADIUS issue also affects 0.10.13 through 1.0.9.

    Published: 20 Jul 2009
    7.1
    High

    CVE-2009-2563

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Infiniband dissector in Wireshark 1.0.6 through 1.2.0, when running on unspecified platforms, allows remote attackers to cause a denial of service (crash) via unknown vectors.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2562

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the AFS dissector in Wireshark 0.9.2 through 1.2.0 allows remote attackers to cause a denial of service (crash) via unknown vectors.

    Published: 20 Jul 2009
    5
    Medium

    CVE-2009-2561

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the sFlow dissector in Wireshark 1.2.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified vectors.

    Published: 20 Jul 2009
    6.9
    Medium

    CVE-2009-2348

    Last Modified: 23 Apr 2026

    Android 1.5 CRBxx allows local users to bypass the (1) Manifest.permission.CAMERA (aka android.permission.CAMERA) and (2) Manifest.permission.AUDIO_RECORD (aka android.permission.RECORD_AUDIO) configuration settings by installing and executing an application that does not make a permission request before using the camera or microphone.

    Published: 17 Jul 2009
    2.6
    Low

    CVE-2009-2492

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type before 4.261 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-2480.

    Published: 17 Jul 2009