CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-2444

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path_to_lang parameter to setup/index.php.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-2438

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the text parameter in a list action. NOTE: this might overlap CVE-2008-1399.

    Published: 13 Jul 2009
    7.5
    High

    CVE-2009-2436

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-2437

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action.

    Published: 13 Jul 2009
    7.5
    High

    CVE-2009-2439

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is not associated with alibaba.com or the Alibaba Group.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-2440

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-2441

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.

    Published: 13 Jul 2009
    5
    Medium

    CVE-2009-2443

    Last Modified: 23 Apr 2026

    Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Published: 13 Jul 2009
    9.3
    Critical

    CVE-2009-2347

    Last Modified: 23 Apr 2026

    Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-based buffer overflow in the (a) cvt_whole_image function in tiff2rgba and (b) tiffcvt function in rgb2ycbcr.

    Published: 13 Jul 2009
    4.3
    Medium

    CVE-2009-3010

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: in some product versions, the JavaScript executes outside of the context of the HTTP site.

    Published: 11 Jul 2009
    4.3
    Medium

    CVE-2009-2433

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.

    Published: 10 Jul 2009
    4.3
    Medium

    CVE-2009-2424

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

    Published: 10 Jul 2009
    7.5
    High

    CVE-2009-2427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands via the emp_id parameter.

    Published: 10 Jul 2009
    7.5
    High

    CVE-2009-2428

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php; and other unspecified vectors.

    Published: 10 Jul 2009
    4.6
    Medium

    CVE-2009-2429

    Last Modified: 23 Apr 2026

    SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jul 2009
    5
    Medium

    CVE-2009-2425

    Last Modified: 23 Apr 2026

    Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router descriptor.

    Published: 10 Jul 2009
    4.6
    Medium

    CVE-2009-2430

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Auditing is enabled, allows local users with an RBAC execution profile for auditconfig to gain privileges via unknown attack vectors.

    Published: 10 Jul 2009
    7.5
    High

    CVE-2009-2423

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.

    Published: 10 Jul 2009
    5
    Medium

    CVE-2009-2426

    Last Modified: 23 Apr 2026

    The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before 0.1.2.8-beta allows exit relays to have an unspecified impact by causing controllers to accept DNS responses that redirect to an internal IP address via unknown vectors. NOTE: some of these details are obtained from third party information.

    Published: 10 Jul 2009
    9.3
    Critical

    CVE-2009-2386

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.

    Published: 10 Jul 2009
    9.8
    Critical

    CVE-2009-2422

    Last Modified: 23 Apr 2026

    The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.

    Published: 10 Jul 2009
    2.1
    Low

    CVE-2009-2691

    Last Modified: 23 Apr 2026

    The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps and (2) smaps files under proc/ via vectors related to ELF loading, a setuid process, and a race condition.

    Published: 10 Jul 2009
    7.2
    High

    CVE-2009-0667

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in OCS Inventory allows local users to gain privileges via a Trojan horse Perl module in an arbitrary directory.

    Published: 9 Jul 2009
    9.3
    Critical

    CVE-2009-1725

    Last Modified: 23 Apr 2026

    WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms; KHTML in kdelibs in KDE; QtWebKit (aka Qt toolkit); and possibly other products do not properly handle numeric character references, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2390

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter to index.php.

    Published: 9 Jul 2009
    4.3
    Medium

    CVE-2009-2391

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2392

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Published: 9 Jul 2009
    6.5
    Medium

    CVE-2009-2393

    Last Modified: 23 Apr 2026

    admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2394

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

    Published: 9 Jul 2009
    5
    Medium

    CVE-2009-2398

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.

    Published: 9 Jul 2009
    6.8
    Medium

    CVE-2009-2399

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2400

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 9 Jul 2009
    4.3
    Medium

    CVE-2009-2401

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2402

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a thread action, a different vector than CVE-2008-0355.

    Published: 9 Jul 2009
    5
    Medium

    CVE-2009-2397

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.

    Published: 9 Jul 2009
    5
    Medium

    CVE-2009-2421

    Last Modified: 23 Apr 2026

    The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a "high-bit character" in a URL fragment for an unspecified protocol.

    Published: 9 Jul 2009
    4.9
    Medium

    CVE-2009-2387

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the proc filesystem in Sun OpenSolaris snv_49 through snv_109 allows local users to cause a denial of service (deadlock and panic) via unknown vectors, related to the ldt_rewrite_syscall function.

    Published: 9 Jul 2009
    6.8
    Medium

    CVE-2009-2388

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Jul 2009
    9.3
    Critical

    CVE-2009-2403

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.

    Published: 9 Jul 2009
    6.8
    Medium

    CVE-2009-2389

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2395

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.

    Published: 9 Jul 2009
    9.3
    Critical

    CVE-2009-2396

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

    Published: 9 Jul 2009
    4.3
    Medium

    CVE-2009-2419

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.

    Published: 9 Jul 2009
    5.8
    Medium

    CVE-2009-2420

    Last Modified: 23 Apr 2026

    Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitrary files or cause a denial of service (launch of multiple Windows Explorer instances) via vectors involving an unspecified HTML tag, possibly a related issue to CVE-2009-1703.

    Published: 9 Jul 2009
    8.5
    High

    CVE-2009-2446

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request. NOTE: some of these details are obtained from third party information.

    Published: 9 Jul 2009
    7.5
    High

    CVE-2009-2385

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 8 Jul 2009
    9.3
    Critical

    CVE-2009-2375

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_Name parameter in a .pdm file. NOTE: some of these details are obtained from third party information.

    Published: 8 Jul 2009
    4.3
    Medium

    CVE-2009-2373

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Jul 2009
    6.5
    Medium

    CVE-2009-2372

    Last Modified: 23 Apr 2026

    Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

    Published: 8 Jul 2009
    6.5
    Medium

    CVE-2009-2371

    Last Modified: 23 Apr 2026

    Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.

    Published: 8 Jul 2009