CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6837

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Zoph 0.7.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different issue than CVE-2008-3258. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jun 2009
    4.3
    Medium

    CVE-2008-6839

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TGS Content Management 0.3.2r2 allow remote attackers to inject arbitrary web script or HTML via the (1) msg and (2) goodmsg parameters to (a) login.php and (b) index.php, and the (3) dir and (4) id parameters to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jun 2009
    7.5
    High

    CVE-2009-2237

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Views Bulk Operations 5.x-1.x before 5.x-1.4 and 6.x-1.x before 6.x-1.7, a module for Drupal, allows remote attackers to bypass intended access restrictions and modify "nodes or classes of nodes" via unknown vectors, probably related to registered procedures (aka actions).

    Published: 27 Jun 2009
    7.5
    High

    CVE-2009-2239

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the (1) casinobase (com_casinobase), (2) casino_blackjack (com_casino_blackjack), and (3) casino_videopoker (com_casino_videopoker) components 0.3.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Published: 27 Jun 2009
    4.3
    Medium

    CVE-2009-2240

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Jun 2009
    10
    Critical

    CVE-2009-1628

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet.

    Published: 26 Jun 2009
    10
    Critical

    CVE-2009-2227

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810.

    Published: 26 Jun 2009
    4.3
    Medium

    CVE-2009-2228

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web script or HTML via the url parameter in a redirect action.

    Published: 26 Jun 2009
    7.5
    High

    CVE-2009-2233

    Last Modified: 23 Apr 2026

    The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the awse_logged cookie to 1.

    Published: 26 Jun 2009
    7.5
    High

    CVE-2009-2231

    Last Modified: 23 Apr 2026

    MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.

    Published: 26 Jun 2009
    7.5
    High

    CVE-2009-2232

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in image.php in Softbiz Banner Ad Management Script allows remote attackers to execute arbitrary SQL commands via the size_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jun 2009
    9.3
    Critical

    CVE-2009-1394

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.

    Published: 26 Jun 2009
    7.5
    High

    CVE-2009-2230

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.

    Published: 26 Jun 2009
    5
    Medium

    CVE-2009-2229

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter during a download action, a different vector than CVE-2008-3087. NOTE: some of these details are obtained from third party information.

    Published: 26 Jun 2009
    4.3
    Medium

    CVE-2009-2224

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter.

    Published: 26 Jun 2009
    4.3
    Medium

    CVE-2009-2226

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Let's PHP! Tree BBS 2004/11/23 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2009
    4.3
    Medium

    CVE-2009-2221

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2009
    9.3
    Critical

    CVE-2009-2225

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in SureThing CD/DVD Labeler 5.1.616 trial version allows user-assisted remote attackers to execute arbitrary code via a crafted (1) m3u or (2) pls playlist file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jun 2009
    5.1
    Medium

    CVE-2009-2220

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Tribiq CMS 5.0.12c, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to include and possibly execute arbitrary files via directory traversal sequences in the template_path parameter to (1) masthead.inc.php, (2) toppanel.inc.php, and (3) contact.inc.php in templates/mytribiqsite/tribiq-CL-9000/includes; and the use_template_family parameter to (4) templates/mytribiqsite/tribiq-CL-9000/includes/nlarlist_content.inc.php. NOTE: the tribal-GPL-1066/includes/header.inc.php vector is already covered by CVE-2008-4894.

    Published: 26 Jun 2009
    5
    Medium

    CVE-2009-2222

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in PHP-I-BOARD 1.2 and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors, probably related to mail.

    Published: 26 Jun 2009
    9.3
    Critical

    CVE-2009-2223

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote file inclusion attacks may be possible.

    Published: 26 Jun 2009
    5.8
    Medium

    CVE-2010-0744

    Last Modified: 11 Apr 2025

    aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof an MSN server via an arbitrary certificate.

    Published: 26 Jun 2009
    5
    Medium

    CVE-2009-2260

    Last Modified: 23 Apr 2026

    stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 26 Jun 2009
    7.1
    High

    CVE-2009-1891

    Last Modified: 23 Apr 2026

    The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption).

    Published: 26 Jun 2009
    7.2
    High

    CVE-2009-1895

    Last Modified: 23 Apr 2026

    The personality subsystem in the Linux kernel before 2.6.31-rc3 has a PER_CLEAR_ON_SETID setting that does not clear the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags when executing a setuid or setgid program, which makes it easier for local users to leverage the details of memory usage to (1) conduct NULL pointer dereference attacks, (2) bypass the mmap_min_addr protection mechanism, or (3) defeat address space layout randomization (ASLR).

    Published: 26 Jun 2009
    4.3
    Medium

    CVE-2009-2217

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag.

    Published: 25 Jun 2009
    4.3
    Medium

    CVE-2009-2215

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in URD before 0.6.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the fatal_error page and unspecified other components.

    Published: 25 Jun 2009
    5
    Medium

    CVE-2009-2214

    Last Modified: 23 Apr 2026

    The Secure Gateway service in Citrix Secure Gateway 3.1 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an unspecified request.

    Published: 25 Jun 2009
    6.8
    Medium

    CVE-2009-2218

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the home parameter to (1) i_head.php, (2) i_nav.php, (3) user_new_2.php, or (4) house/myrents.php; or (5) allbooks.php, (6) home.php, or (7) mybooks.php in books/. NOTE: house/myrents.php was also separately reported as a local file inclusion issue.

    Published: 25 Jun 2009
    6.5
    Medium

    CVE-2009-2213

    Last Modified: 23 Apr 2026

    The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1, and earlier specifies Allow for the Default Authorization Action option, which might allow remote authenticated users to bypass intended access restrictions.

    Published: 25 Jun 2009
    4.3
    Medium

    CVE-2009-2219

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpCollegeExchange 0.1.5c allow remote attackers to inject arbitrary web script or HTML via the (1) _SESSION[handle] parameter to (a) home.php, (b) books/allbooks.php, or (c) books/home.php; or the (2) home parameter to (d) i_head.php or (e) i_nav.php, or (f) allbooks.php, (g) home.php, or (h) i_nav.php in books/.

    Published: 25 Jun 2009
    6.1
    Medium

    CVE-2009-2216

    Last Modified: 16 Dec 2025

    Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request.

    Published: 25 Jun 2009
    4.3
    Medium

    CVE-2009-1201

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.

    Published: 25 Jun 2009
    4.3
    Medium

    CVE-2009-2211

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Jun 2009
    5
    Medium

    CVE-2009-2212

    Last Modified: 23 Apr 2026

    The CQWeb server in IBM Rational ClearQuest 7.0.0 before 7.0.0.6 and 7.0.1 before 7.0.1.5 allows attackers to discover a (1) username or (2) password via unspecified vectors.

    Published: 25 Jun 2009
    4.3
    Medium

    CVE-2009-1202

    Last Modified: 23 Apr 2026

    WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass certain protection mechanisms involving URL rewriting and HTML rewriting, and conduct cross-site scripting (XSS) attacks, by modifying the first hex-encoded character in a /+CSCO+ URI, aka Bug ID CSCsy80705.

    Published: 25 Jun 2009
    6
    Medium

    CVE-2009-1203

    Last Modified: 23 Apr 2026

    WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.

    Published: 25 Jun 2009
    10
    Critical

    CVE-2009-2688

    Last Modified: 23 Apr 2026

    Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Jun 2009
    5
    Medium

    CVE-2009-1887

    Last Modified: 23 Apr 2026

    agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309.

    Published: 25 Jun 2009
    7.5
    High

    CVE-2009-2209

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Published: 24 Jun 2009
    3.6
    Low

    CVE-2009-2208

    Last Modified: 23 Apr 2026

    FreeBSD 6.3, 6.4, 7.1, and 7.2 does not enforce permissions on the SIOCSIFINFO_IN6 IOCTL, which allows local users to modify or disable IPv6 network interfaces, as demonstrated by modifying the MTU.

    Published: 24 Jun 2009
    6.8
    Medium

    CVE-2009-2046

    Last Modified: 23 Apr 2026

    The embedded web server on the Cisco Video Surveillance 2500 Series IP Camera with firmware before 2.1 allows remote attackers to read arbitrary files via a (1) http or (2) https request, related to the (a) SD Camera Web Server and the (b) Wireless Camera HTTP Server, aka Bug IDs CSCsu05515 and CSCsr96497.

    Published: 24 Jun 2009
    9.3
    Critical

    CVE-2009-2186

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave Player 11.0.0.465."

    Published: 24 Jun 2009
    9.3
    Critical

    CVE-2009-1860

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content.

    Published: 24 Jun 2009
    7.8
    High

    CVE-2009-2045

    Last Modified: 23 Apr 2026

    The Cisco Video Surveillance Stream Manager firmware before 5.3, as used on Cisco Video Surveillance Services Platforms and Video Surveillance Integrated Services Platforms, allows remote attackers to cause a denial of service (reboot) via a malformed payload in a UDP packet to port 37000, related to the xvcrman process, aka Bug ID CSCsj47924.

    Published: 24 Jun 2009
    4.9
    Medium

    CVE-2009-2187

    Last Modified: 23 Apr 2026

    Multiple memory leaks in the (1) IP and (2) IPv6 multicast implementation in the kernel in Sun Solaris 10, and OpenSolaris snv_67 through snv_93, allow local users to cause a denial of service (memory consumption) via vectors related to the association of (a) DL_ENABMULTI_REQ and (b) DL_DISABMULTI_REQ messages with ARP messages.

    Published: 24 Jun 2009
    7.5
    High

    CVE-2009-0903

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3, and the Feature Pack for Web Services for WAS 6.1 before 6.1.0.25, when a WS-Security policy is established at the operation level, does not properly handle inbound requests that lack a SOAPAction or WS-Addressing Action, which allows remote attackers to bypass intended access restrictions via a crafted request to a JAX-WS application.

    Published: 24 Jun 2009
    7.8
    High

    CVE-2009-1163

    Last Modified: 23 Apr 2026

    Memory leak on the Cisco Physical Access Gateway with software before 1.1 allows remote attackers to cause a denial of service (memory consumption) via unspecified TCP packets.

    Published: 24 Jun 2009
    9.3
    Critical

    CVE-2009-2663

    Last Modified: 23 Apr 2026

    libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.

    Published: 24 Jun 2009
    9.3
    Critical

    CVE-2009-0690

    Last Modified: 23 Apr 2026

    The Foxit JPEG2000/JBIG2 Decoder add-on before 2.0.2009.616 for Foxit Reader 3.0 before Build 1817 does not properly handle a negative value for the stream offset in a JPEG2000 (aka JPX) stream, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted PDF file that triggers an out-of-bounds read.

    Published: 23 Jun 2009