CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2009-2154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 22 Jun 2009
    9.3
    Critical

    CVE-2009-2210

    Last Modified: 23 Apr 2026

    Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type.

    Published: 22 Jun 2009
    5
    Medium

    CVE-2009-2185

    Last Modified: 23 Apr 2026

    The ASN.1 parser (pluto/asn1.c, libstrongswan/asn1/asn1.c, libstrongswan/asn1/asn1_parser.c) in (a) strongSwan 2.8 before 2.8.10, 4.2 before 4.2.16, and 4.3 before 4.3.2; and (b) openSwan 2.6 before 2.6.22 and 2.4 before 2.4.15 allows remote attackers to cause a denial of service (pluto IKE daemon crash) via an X.509 certificate with (1) crafted Relative Distinguished Names (RDNs), (2) a crafted UTCTIME string, or (3) a crafted GENERALIZEDTIME string.

    Published: 22 Jun 2009
    4.9
    Medium

    CVE-2009-2135

    Last Modified: 23 Apr 2026

    Multiple race conditions in the Solaris Event Port API in Sun Solaris 10 and OpenSolaris before snv_107 allow local users to cause a denial of service (panic) via unspecified vectors related to a race between the port_dissociate and close functions.

    Published: 19 Jun 2009
    7.8
    High

    CVE-2009-2136

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TCP/IP networking stack in Sun Solaris 10, and OpenSolaris snv_01 through snv_82 and snv_111 through snv_117, when a Cassini GigaSwift Ethernet Adapter (aka CE) interface is used, allows remote attackers to cause a denial of service (panic) via vectors involving jumbo frames.

    Published: 19 Jun 2009
    7.8
    High

    CVE-2009-2137

    Last Modified: 23 Apr 2026

    Memory leak in the Ultra-SPARC T2 crypto provider device driver (aka n2cp) in Sun Solaris 10, and OpenSolaris snv_54 through snv_112, allows context-dependent attackers to cause a denial of service (memory consumption) via unspecified vectors related to a large keylen value.

    Published: 19 Jun 2009
    4.3
    Medium

    CVE-2009-2138

    Last Modified: 23 Apr 2026

    Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the returnto parameter to login.php or (2) the returnto parameter in a delete action to news.php. NOTE: this can be leveraged for cross-site scripting (XSS) by redirecting to a data: URI.

    Published: 19 Jun 2009
    5
    Medium

    CVE-2009-2134

    Last Modified: 23 Apr 2026

    pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error message.

    Published: 19 Jun 2009
    7.5
    High

    CVE-2009-2122

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 19 Jun 2009
    4
    Medium

    CVE-2009-2125

    Last Modified: 23 Apr 2026

    delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs.

    Published: 19 Jun 2009
    4.3
    Medium

    CVE-2009-2127

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 19 Jun 2009
    7.5
    High

    CVE-2009-2128

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field.

    Published: 19 Jun 2009
    6.8
    Medium

    CVE-2009-2129

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authentication of arbitrary users via a logout action.

    Published: 19 Jun 2009
    5
    Medium

    CVE-2009-2130

    Last Modified: 23 Apr 2026

    Elvin 1.2.0 allows remote attackers to read the PHP source code of (1) login.ei, (2) jump_bug.ei, or (3) create_account.ei in inc/ via a direct request.

    Published: 19 Jun 2009
    4.3
    Medium

    CVE-2009-2126

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the title (aka subject) field.

    Published: 19 Jun 2009
    7.5
    High

    CVE-2009-2124

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in page.php in Elvin 1.2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter.

    Published: 19 Jun 2009
    3.5
    Low

    CVE-2009-2131

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage parameter to member.php, and then posting a comment associated with a picture.

    Published: 19 Jun 2009
    4.3
    Medium

    CVE-2009-2133

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter to pivot/index.php, (3) the value of a check array parameter in a delete action to pivot/index.php, (4) the element name in a check array parameter in a delete action to pivot/index.php, (5) the edituser parameter in an edituser action to pivot/index.php, (6) the edit parameter in a templates action to pivot/index.php, (7) the blog parameter in a blog_edit1 action to pivot/index.php, (8) the cat parameter in a cat_edit action to pivot/index.php, (9) a certain form field in a doaction=1 request to pivot/index.php, (10) the url field in a my_weblog edit_prefs action to pivot/user.php, or (11) the username (aka name) field in a my_weblog reg_user action to pivot/user.php.

    Published: 19 Jun 2009
    7.5
    High

    CVE-2009-2123

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2.

    Published: 19 Jun 2009
    6.8
    Medium

    CVE-2009-2132

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the l parameter.

    Published: 19 Jun 2009
    7.1
    High

    CVE-2009-0959

    Last Modified: 23 Apr 2026

    The MPEG-4 video codec in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted MPEG-4 video file that triggers an "input validation issue."

    Published: 19 Jun 2009
    5
    Medium

    CVE-2009-0961

    Last Modified: 23 Apr 2026

    The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.

    Published: 19 Jun 2009
    4.3
    Medium

    CVE-2009-0960

    Last Modified: 23 Apr 2026

    The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not provide an option to disable remote image loading in HTML email, which allows remote attackers to determine the device address and when an e-mail is read via an HTML email containing an image URL.

    Published: 19 Jun 2009
    7.8
    High

    CVE-2009-1683

    Last Modified: 23 Apr 2026

    The Telephony component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to cause a denial of service (device reset) via a crafted ICMP echo request, which triggers an assertion error related to a "logic issue."

    Published: 19 Jun 2009
    2.1
    Low

    CVE-2009-1679

    Last Modified: 23 Apr 2026

    The Profiles component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1, when installing a configuration profile, can replace the password policy from Exchange ActiveSync with a weaker password policy, which allows physically proximate attackers to bypass the intended policy.

    Published: 19 Jun 2009
    4.3
    Medium

    CVE-2009-0958

    Last Modified: 23 Apr 2026

    Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 stores an exception for a hostname when the user accepts an untrusted Exchange server certificate, which causes it to be accepted without prompting in future usage and allows remote Exchange servers to obtain sensitive information such as credentials.

    Published: 19 Jun 2009
    2.1
    Low

    CVE-2009-1680

    Last Modified: 23 Apr 2026

    Safari in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 does not properly clear the search history when it is cleared from the Settings application, which allows physically proximate attackers to obtain the search history.

    Published: 19 Jun 2009
    7.1
    High

    CVE-2009-1692

    Last Modified: 23 Apr 2026

    WebKit before r41741, as used in Apple iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Safari, and other software, allows remote attackers to cause a denial of service (memory consumption or device reset) via a web page containing an HTMLSelectElement object with a large length attribute, related to the length property of a Select object.

    Published: 19 Jun 2009
    7.5
    High

    CVE-2009-2112

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _FORUM[settings_design_style] parameter.

    Published: 18 Jun 2009
    7.5
    High

    CVE-2009-2113

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) name parameter to player.php and the (2) hash parameter to song.php.

    Published: 18 Jun 2009
    4.3
    Medium

    CVE-2009-2114

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters.

    Published: 18 Jun 2009
    7.5
    High

    CVE-2009-2117

    Last Modified: 23 Apr 2026

    uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a valid username.

    Published: 18 Jun 2009
    6.8
    Medium

    CVE-2009-2118

    Last Modified: 23 Apr 2026

    Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.

    Published: 18 Jun 2009
    4.3
    Medium

    CVE-2009-2119

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.

    Published: 18 Jun 2009
    6.5
    Medium

    CVE-2009-2120

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors. NOTE: vector 1 requires administrative access.

    Published: 18 Jun 2009
    5
    Medium

    CVE-2009-2109

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) language parameter to charts.php and the (2) fretsweb_language cookie parameter to unspecified vectors, possibly related to admin/common.php.

    Published: 18 Jun 2009
    6.8
    Medium

    CVE-2009-2115

    Last Modified: 23 Apr 2026

    admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message.

    Published: 18 Jun 2009
    7.6
    High

    CVE-2009-2110

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the u parameter to (1) full.php, (2) index.php, and (3) contact.php.

    Published: 18 Jun 2009
    10
    Critical

    CVE-2009-2111

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP code via a crafted (1) url and (2) location parameter.

    Published: 18 Jun 2009
    4
    Medium

    CVE-2009-2116

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to list directory contents via a .. (dot dot) in the dir parameter.

    Published: 18 Jun 2009
    5
    Medium

    CVE-2009-2108

    Last Modified: 23 Apr 2026

    git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a request containing extra unrecognized arguments.

    Published: 18 Jun 2009
    4.9
    Medium

    CVE-2009-1935

    Last Modified: 23 Apr 2026

    Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.

    Published: 18 Jun 2009
    7.5
    High

    CVE-2009-2288

    Last Modified: 23 Apr 2026

    statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) ping or (2) Traceroute parameters.

    Published: 18 Jun 2009
    4.3
    Medium

    CVE-2009-2687

    Last Modified: 23 Apr 2026

    The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.

    Published: 18 Jun 2009
    6.8
    Medium

    CVE-2009-2095

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the top parameter. NOTE: when allow_url_fopen is disabled, directory traversal attacks are possible to include and execute arbitrary local files.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2096

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute arbitrary SQL commands via the itemnr parameter.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2097

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) allows remote attackers to execute arbitrary SQL commands via the search_text parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2098

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Jun 2009
    6.8
    Medium

    CVE-2009-2101

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote attackers to delete arbitrary files via a .. (dot dot) in the deleteTorrent parameter.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2102

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote attackers to execute arbitrary SQL commands via the fileid parameter to index.php.

    Published: 17 Jun 2009