CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-2103

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Jun 2009
    4.3
    Medium

    CVE-2009-2104

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2105

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the References database (t3references) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2106

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 Jun 2009
    7.5
    High

    CVE-2009-2099

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in an xml action to index.php.

    Published: 17 Jun 2009
    5
    Medium

    CVE-2009-2100

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.

    Published: 17 Jun 2009
    4.3
    Medium

    CVE-2009-2107

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remote attackers to inject arbitrary web script or HTML via event handlers such as onmouseover in the (1) search or (2) tag parameters; (3) arbitrary invalid parameter names that are not properly handled when triggered on a column; (4) bookmark parameter in an edit action; or (5) email parameter in a remember action.

    Published: 17 Jun 2009
    5
    Medium

    CVE-2012-5568

    Last Modified: 11 Apr 2025

    Apache Tomcat through 7.0.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris.

    Published: 17 Jun 2009
    5
    Medium

    CVE-2009-5005

    Last Modified: 11 Apr 2025

    The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.

    Published: 17 Jun 2009
    5
    Medium

    CVE-2007-6750

    Last Modified: 11 Apr 2025

    The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.

    Published: 17 Jun 2009
    6.8
    Medium

    CVE-2009-1391

    Last Modified: 23 Apr 2026

    Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.

    Published: 16 Jun 2009
    5
    Medium

    CVE-2009-1761

    Last Modified: 23 Apr 2026

    The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of service (crash) via (1) an invalid 0x13 message, which is not properly handled in the ASCORE module, or (2) a 0x3B message with invalid stub data that triggers an RPC marshalling error.

    Published: 16 Jun 2009
    7.2
    High

    CVE-2009-2084

    Last Modified: 23 Apr 2026

    Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary groups before invoking (1) sbcast from the slurmd daemon or (2) strigger from the slurmctld daemon, which might allow local SLURM users to modify files and gain privileges.

    Published: 16 Jun 2009
    7.5
    High

    CVE-2009-1719

    Last Modified: 23 Apr 2026

    The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary code via a call to the undocumented apple.laf.CColourUIResource constructor with a crafted value in the first argument, which is dereferenced as a pointer.

    Published: 16 Jun 2009
    9.3
    Critical

    CVE-2009-2011

    Last Modified: 23 Apr 2026

    Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbitrary commands via a .dxstudio file that invokes this method.

    Published: 16 Jun 2009
    7.5
    High

    CVE-2009-2082

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in insidepage.php in Creative Web Solutions Multi-Level CMS 1.21 allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: some of these details are obtained from third party information.

    Published: 16 Jun 2009
    3.5
    Low

    CVE-2009-2083

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via "Parent and related terms."

    Published: 16 Jun 2009
    3.5
    Low

    CVE-2009-2074

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, allows remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via vocabulary names.

    Published: 16 Jun 2009
    7.5
    High

    CVE-2009-2075

    Last Modified: 23 Apr 2026

    Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, does not properly restrict access when displaying node titles, which has unknown impact and attack vectors.

    Published: 16 Jun 2009
    3.5
    Low

    CVE-2009-2076

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via (1) exposed filters in the Views UI administrative interface and in the (2) view name parameter in the define custom views feature. NOTE: vector 2 is only exploitable by users with administer views permissions.

    Published: 16 Jun 2009
    4.3
    Medium

    CVE-2009-2081

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the module parameter.

    Published: 16 Jun 2009
    3.5
    Low

    CVE-2009-2079

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users, with administer taxonomy privileges or the ability to use free tagging to add taxonomy terms, to inject arbitrary web script or HTML via (1) vocabulary names, (2) synonyms, and (3) term names.

    Published: 16 Jun 2009
    4
    Medium

    CVE-2009-2077

    Last Modified: 23 Apr 2026

    Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) read unpublished content from anonymous users when a view is already configured to display the content, and (2) read private content in generated queries.

    Published: 16 Jun 2009
    4.3
    Medium

    CVE-2009-2078

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Booktree 5.x before 5.x-7.3 and 6.x before 6.x-1.1, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) node title and (2) node body in a tree root page.

    Published: 16 Jun 2009
    7.5
    High

    CVE-2009-2080

    Last Modified: 23 Apr 2026

    admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.

    Published: 16 Jun 2009
    6.8
    Medium

    CVE-2009-2058

    Last Modified: 23 Apr 2026

    Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2059

    Last Modified: 23 Apr 2026

    Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

    Published: 15 Jun 2009
    5.8
    Medium

    CVE-2009-2060

    Last Modified: 23 Apr 2026

    src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

    Published: 15 Jun 2009
    9.3
    Critical

    CVE-2009-2061

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2066

    Last Modified: 23 Apr 2026

    Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2067

    Last Modified: 23 Apr 2026

    Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

    Published: 15 Jun 2009
    5.8
    Medium

    CVE-2009-2068

    Last Modified: 23 Apr 2026

    Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

    Published: 15 Jun 2009
    5.4
    Medium

    CVE-2009-2072

    Last Modified: 23 Apr 2026

    Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to spoof an arbitrary https site by sending the browser a crafted (1) 4xx or (2) 5xx CONNECT response page for an https request sent through a proxy server.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2073

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows remote attackers to hijack the authentication of other users for unspecified requests via unknown vectors, as demonstrated using administrator privileges and actions.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2065

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2070

    Last Modified: 23 Apr 2026

    Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.

    Published: 15 Jun 2009
    5.8
    Medium

    CVE-2009-2069

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.

    Published: 15 Jun 2009
    5.8
    Medium

    CVE-2009-2057

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2062

    Last Modified: 23 Apr 2026

    Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2063

    Last Modified: 23 Apr 2026

    Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2064

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying an http page to include an https iframe that references a script file on an http site, related to "HTTP-Intended-but-HTTPS-Loadable (HPIHSL) pages."

    Published: 15 Jun 2009
    6.8
    Medium

    CVE-2009-2071

    Last Modified: 23 Apr 2026

    Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attackers to spoof an arbitrary https site by letting a browser obtain a valid certificate from this site during one request, and then sending the browser a crafted 502 response page upon a subsequent request.

    Published: 15 Jun 2009
    4.3
    Medium

    CVE-2009-2043

    Last Modified: 23 Apr 2026

    nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.

    Published: 12 Jun 2009
    4.3
    Medium

    CVE-2009-2044

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.

    Published: 12 Jun 2009
    4.3
    Medium

    CVE-2009-2041

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab 0.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2009-1772.

    Published: 12 Jun 2009
    4.3
    Medium

    CVE-2009-2033

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Yogurt 0.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 12 Jun 2009
    6.4
    Medium

    CVE-2009-2035

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Services 6.x before 6.x-0.14, a module for Drupal, when key-based access is enabled, allows remote attackers to read or add keys and access unauthorized services via unspecified vectors.

    Published: 12 Jun 2009
    7.5
    High

    CVE-2009-2036

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 12 Jun 2009
    10
    Critical

    CVE-2009-2038

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges.

    Published: 12 Jun 2009
    10
    Critical

    CVE-2009-2039

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.

    Published: 12 Jun 2009