CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-2298

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in rping in HP OpenView Network Node Manager (OV NNM) 7.53 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a CGI request to webappmon.exe. NOTE: this may overlap CVE-2009-1420.

    Published: 2 Jul 2009
    5
    Medium

    CVE-2009-2299

    Last Modified: 23 Apr 2026

    The Artofdefence Hyperguard Web Application Firewall (WAF) module before 2.5.5-11635, 3.0 before 3.0.3-11636, and 3.1 before 3.1.1-11637, a module for the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via an HTTP request with a large Content-Length value but no POST data.

    Published: 2 Jul 2009
    10
    Critical

    CVE-2009-2300

    Last Modified: 23 Apr 2026

    The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width and height parameters for an image, which allows remote attackers to execute arbitrary commands or cause a denial of service (resource consumption) via a crafted request.

    Published: 2 Jul 2009
    7.8
    High

    CVE-2009-2305

    Last Modified: 23 Apr 2026

    The ARD-9808 DVR card security camera allows remote attackers to cause a denial of service via a long URI composed of //.\ (slash slash dot backslash) sequences.

    Published: 2 Jul 2009
    5.5
    Medium

    CVE-2009-1388

    Last Modified: 23 Apr 2026

    The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution of the do_coredump function, which allows local users to cause a denial of service (deadlock) via vectors involving the ptrace system call and a coredumping thread.

    Published: 2 Jul 2009
    7.1
    High

    CVE-2009-1890

    Last Modified: 23 Apr 2026

    The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.

    Published: 2 Jul 2009
    6.8
    Medium

    CVE-2009-2353

    Last Modified: 23 Apr 2026

    encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a location under the web root via the -o option, and then making a direct request to this file, related to upload of image files.

    Published: 2 Jul 2009
    6.8
    Medium

    CVE-2009-2369

    Last Modified: 23 Apr 2026

    Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted JPEG file, which triggers a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Jul 2009
    6.8
    Medium

    CVE-2008-6840

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) CONFIG[pear_dir] parameter to (a) Mail/RFC822.php, (b) Net/Socket.php, (c) XML/Parser.php, (d) XML/Tree.php, (e) Mail/mimeDecode.php, (f) Console/Getopt.php, (g) System.php, (h) Log.php, and (i) File.php in includes/pear/; the CONFIG[pear_dir] parameter to (j) includes/prepend.php, and (k) includes/cachedConfig.php; and the (2) CONFIG[includes] parameter to (l) prepend.php and (m) email.list.search.php in includes/. NOTE: the CONFIG[pear_dir] parameter to includes/mailaccess/pop3.php is already covered by CVE-2006-2666.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2008-6841

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_dbquery) component 1.4.1.1 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to classes/DBQ/admin/common.class.php.

    Published: 1 Jul 2009
    2.6
    Low

    CVE-2009-2268

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager 6 2005Q1, 7 2005Q4, and 7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Jul 2009
    10
    Critical

    CVE-2009-2271

    Last Modified: 23 Apr 2026

    The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access.

    Published: 1 Jul 2009
    5
    Medium

    CVE-2009-2273

    Last Modified: 23 Apr 2026

    The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

    Published: 1 Jul 2009
    7.8
    High

    CVE-2009-2274

    Last Modified: 23 Apr 2026

    The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, (2) wlan_basic_cfg.asp, or (3) lancfg.asp in en/, related to use of JavaScript to protect against reading file contents.

    Published: 1 Jul 2009
    5
    Medium

    CVE-2009-2275

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2009-2276

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote attackers to execute arbitrary SQL commands via the out parameter.

    Published: 1 Jul 2009
    4.3
    Medium

    CVE-2009-2284

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted SQL bookmark.

    Published: 1 Jul 2009
    4.3
    Medium

    CVE-2009-2286

    Last Modified: 23 Apr 2026

    Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a long declaration in a .xbm file. NOTE: this issue only affects compface on distributions that used a certain patch.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2009-2290

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) account or (2) event task to index.php.

    Published: 1 Jul 2009
    6.8
    Medium

    CVE-2009-2291

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow users to login using their e-mail address" is enabled, allows remote blocked users to bypass intended access restrictions via unspecified vectors.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2009-2293

    Last Modified: 23 Apr 2026

    Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the usernamed cookie parameter.

    Published: 1 Jul 2009
    4.3
    Medium

    CVE-2009-2289

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject arbitrary web script or HTML via the q parameter in a gamelist action.

    Published: 1 Jul 2009
    4.3
    Medium

    CVE-2009-2283

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5, and Sun Java Web Console in Solaris 10, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2009-2269

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2009-2272

    Last Modified: 23 Apr 2026

    The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-dependent attackers to obtain sensitive information by (1) reading a cookie file, by (2) sniffing the network for HTTP headers, and possibly by using unspecified other vectors.

    Published: 1 Jul 2009
    4.3
    Medium

    CVE-2009-2292

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Jul 2009
    6.8
    Medium

    CVE-2009-0689

    Last Modified: 23 Apr 2026

    Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

    Published: 1 Jul 2009
    6.8
    Medium

    CVE-2009-2270

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbitrary code by uploading a file with a double extension in the filename, then accessing this file via unspecified vectors, as demonstrated by a .jpg.php filename.

    Published: 1 Jul 2009
    4.6
    Medium

    CVE-2009-2282

    Last Modified: 23 Apr 2026

    The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain privileges via unknown vectors.

    Published: 1 Jul 2009
    4.7
    Medium

    CVE-2009-2849

    Last Modified: 23 Apr 2026

    The md driver (drivers/md/md.c) in the Linux kernel before 2.6.30.2 might allow local users to cause a denial of service (NULL pointer dereference) via vectors related to "suspend_* sysfs attributes" and the (1) suspend_lo_store or (2) suspend_hi_store functions. NOTE: this is only a vulnerability when sysfs is writable by an attacker.

    Published: 1 Jul 2009
    7.5
    High

    CVE-2009-2254

    Last Modified: 23 Apr 2026

    Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue.

    Published: 30 Jun 2009
    6.8
    Medium

    CVE-2009-2255

    Last Modified: 23 Apr 2026

    Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to execute arbitrary code by uploading a .php file via the record_company_image parameter in conjunction with a PATH_INFO of password_forgotten.php, then accessing this file via a direct request to the file in images/.

    Published: 30 Jun 2009
    7.8
    High

    CVE-2009-2258

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.

    Published: 30 Jun 2009
    7.8
    High

    CVE-2009-2257

    Last Modified: 23 Apr 2026

    The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/.

    Published: 30 Jun 2009
    Unknown

    CVE-2009-2259

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of CVE-2009-2608. Notes: All CVE users should reference CVE-2009-2608 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 Jun 2009
    9.3
    Critical

    CVE-2009-2261

    Last Modified: 23 Apr 2026

    PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .zip archive with a .txt file whose name contains | (pipe) characters and a command.

    Published: 30 Jun 2009
    7.5
    High

    CVE-2009-2263

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 30 Jun 2009
    7.8
    High

    CVE-2009-2256

    Last Modified: 23 Apr 2026

    The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.

    Published: 30 Jun 2009
    7.5
    High

    CVE-2009-2262

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the pathtoserverdata parameter. NOTE: the installation instructions specify deleting the install/ folder.

    Published: 30 Jun 2009
    5
    Medium

    CVE-2009-2855

    Last Modified: 23 Apr 2026

    The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

    Published: 28 Jun 2009
    4.3
    Medium

    CVE-2008-6838

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to inject arbitrary web script or HTML via the _off parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jun 2009
    7.5
    High

    CVE-2009-2236

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in yad-admin/login.php in Your Article Directory allows remote attackers to execute arbitrary SQL commands via the txtAdminEmail parameter. NOTE: some of these details are obtained from third party information.

    Published: 27 Jun 2009
    7.5
    High

    CVE-2009-2234

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin.php in VICIDIAL Call Center Suite 2.0.5-173 allow remote attackers to execute arbitrary SQL commands via the (1) Username parameter ($PHP_AUTH_USER) and (2) Password parameter ($PHP_AUTH_PW).

    Published: 27 Jun 2009
    7.5
    High

    CVE-2009-2235

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Jun 2009
    4.3
    Medium

    CVE-2009-2241

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in ASP Inline Corporate Calendar allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Published: 27 Jun 2009
    6.8
    Medium

    CVE-2009-2242

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 27 Jun 2009
    7.5
    High

    CVE-2009-2243

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jun 2009
    6.8
    Medium

    CVE-2009-2238

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in includes/shared_scripts/wysiwyg_editor/assetmanager/assetmanager.asp in DMXReady Registration Manager 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in assets/webblogmanager.

    Published: 27 Jun 2009
    4.3
    Medium

    CVE-2008-6835

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Jun 2009
    6.8
    Medium

    CVE-2008-6836

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authentication of unspecified victims to delete OpenID identities via unknown vectors.

    Published: 27 Jun 2009