CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-1957

    Last Modified: 23 Apr 2026

    charon/sa/ike_sa.c in the charon daemon in strongSWAN before 4.3.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid IKE_SA_INIT request that triggers "an incomplete state," followed by a CREATE_CHILD_SA request.

    Published: 6 Jun 2009
    4.6
    Medium

    CVE-2009-1953

    Last Modified: 23 Apr 2026

    IBM FileNet Content Manager 4.0, 4.0.1, and 4.5, as used in IBM WebSphere Application Server (WAS) and Oracle BEA WebLogic Application Server, when the CE Web Services listener has a certain WSEAF configuration, does not properly restrict use of a cached Subject, which allows remote attackers to obtain access with the credentials of a recently authenticated user via unspecified vectors.

    Published: 6 Jun 2009
    5
    Medium

    CVE-2009-1959

    Last Modified: 23 Apr 2026

    Off-by-one error in the event_wallops function in fe-common/irc/fe-events.c in irssi 0.8.13 allows remote IRC servers to cause a denial of service (crash) via an empty command, which triggers a one-byte buffer under-read and a one-byte buffer underflow.

    Published: 6 Jun 2009
    9.3
    Critical

    CVE-2009-1960

    Last Modified: 23 Apr 2026

    inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.

    Published: 6 Jun 2009
    4
    Medium

    CVE-2009-1419

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.0.0 through 2.52, 7.50, and 7.51 on Windows allows remote attackers to access DDMI agents via unknown vectors.

    Published: 6 Jun 2009
    7.8
    High

    CVE-2009-1954

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in portmapper (aka portmap) in IBM AIX 5.3 allows attackers to cause a denial of service (daemon hang) via unknown vectors, related to libtli.

    Published: 6 Jun 2009
    6.8
    Medium

    CVE-2009-1952

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 5 Jun 2009
    7.8
    High

    CVE-2009-1949

    Last Modified: 23 Apr 2026

    import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Published: 5 Jun 2009
    5.1
    Medium

    CVE-2009-1948

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in forum.php in Unclassified NewsBoard (UNB) 1.6.4, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to (1) read arbitrary recently-modified files via a .. (dot dot) in the GLOBALS[filename] parameter or (2) include and execute arbitrary local files via a .. (dot dot) in the GLOBALS[UTE][__tplCollection][a][file] parameter.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1951

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action.

    Published: 5 Jun 2009
    7.5
    High

    CVE-2009-1947

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to execute arbitrary SQL commands via the Query parameter in a search action to forum.php, a different vector than CVE-2005-3686.

    Published: 5 Jun 2009
    10
    Critical

    CVE-2009-1943

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514.

    Published: 5 Jun 2009
    9.3
    Critical

    CVE-2009-1944

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag.

    Published: 5 Jun 2009
    6.8
    Medium

    CVE-2008-6825

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the langChoice parameter.

    Published: 5 Jun 2009
    7.5
    High

    CVE-2009-1950

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL commands via the mesajid parameter.

    Published: 5 Jun 2009
    7.5
    High

    CVE-2009-1945

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.

    Published: 5 Jun 2009
    6.8
    Medium

    CVE-2009-1946

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in latestposts.php in AdaptBB 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the forumspath parameter.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1938

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to database output and the frontend administrative panel.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1937

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the comment posting feature in LightNEasy 2.2.1 "no database" (aka flat) and 2.2.2 SQLite allows remote attackers to inject arbitrary web script or HTML via the (1) commentname (aka Author), (2) commentemail (aka Email), and (3) commentmessage (aka Comment) parameters. NOTE: some of these details are obtained from third party information.

    Published: 5 Jun 2009
    9.8
    Critical

    CVE-2009-1936

    Last Modified: 23 Apr 2026

    _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1940

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrator panel in the com_users core component for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2009
    3.5
    Low

    CVE-2009-1942

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2009
    5
    Medium

    CVE-2009-1941

    Last Modified: 23 Apr 2026

    PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1939

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the JA_Purity template for Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1162

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Series C, M, and X appliances allows remote attackers to inject arbitrary web script or HTML via the referrer parameter.

    Published: 5 Jun 2009
    6.8
    Medium

    CVE-2009-1717

    Last Modified: 23 Apr 2026

    Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1934

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allows remote attackers to inject arbitrary web script or HTML via the query string in situations that result in a 502 Gateway error.

    Published: 5 Jun 2009
    4.7
    Medium

    CVE-2009-1933

    Last Modified: 23 Apr 2026

    Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage credential caches, which allows local users to access Kerberized NFS mount points and Kerberized NFS shares via unspecified vectors.

    Published: 5 Jun 2009
    4.3
    Medium

    CVE-2009-1915

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial of service (persistent crash) and possibly execute arbitrary code via an Internet shortcut .URL file containing a long URL parameter, which triggers a crash when browsing a folder that contains this file.

    Published: 4 Jun 2009
    10
    Critical

    CVE-2009-1916

    Last Modified: 23 Apr 2026

    dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.

    Published: 4 Jun 2009
    6.8
    Medium

    CVE-2009-1912

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.

    Published: 4 Jun 2009
    7.5
    High

    CVE-2008-6822

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by an upload with an image/jpeg content type. NOTE: some of these details are obtained from third party information.

    Published: 4 Jun 2009
    6.8
    Medium

    CVE-2009-1911

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as used in TinyWebGallery (TWG) 1.7.6 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter to admin/index.php.

    Published: 4 Jun 2009
    6.8
    Medium

    CVE-2008-6823

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2 access points before firmware 1.4.2-eng1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify the network configuration via certain parameters to goform/formWanTcpipSetup or (2) modify credentials via certain parameters to goform/formPasswordSetup.

    Published: 4 Jun 2009
    4.9
    Medium

    CVE-2009-1914

    Last Modified: 23 Apr 2026

    The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc64 platform allows local users to cause a denial of service (system crash) by reading the /proc/iomem file, related to uninitialized pointers and the request_resource function.

    Published: 4 Jun 2009
    10
    Critical

    CVE-2008-6824

    Last Modified: 23 Apr 2026

    The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier for remote attackers to obtain access.

    Published: 4 Jun 2009
    4.3
    Medium

    CVE-2009-1908

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2009
    7.5
    High

    CVE-2009-1909

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Jun 2009
    7.5
    High

    CVE-2009-1910

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands via the AlbumId parameter.

    Published: 4 Jun 2009
    5.1
    Medium

    CVE-2009-1913

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authentication is used, allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Published: 4 Jun 2009
    4.3
    Medium

    CVE-2009-1907

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

    Published: 4 Jun 2009
    4.3
    Medium

    CVE-2009-2042

    Last Modified: 23 Apr 2026

    libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, which causes libpng to include uninitialized bits in certain rows of a PNG file and might allow remote attackers to read portions of sensitive memory via "out-of-bounds pixels" in the file.

    Published: 4 Jun 2009
    4.2
    Medium

    CVE-2009-0783

    Last Modified: 23 Apr 2026

    Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.

    Published: 4 Jun 2009
    4.3
    Medium

    CVE-2009-1906

    Last Modified: 23 Apr 2026

    The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32.

    Published: 3 Jun 2009
    6
    Medium

    CVE-2008-2154

    Last Modified: 23 Apr 2026

    IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, which allows remote authenticated users to create or overwrite arbitrary files via unspecified calls.

    Published: 3 Jun 2009
    10
    Critical

    CVE-2008-6820

    Last Modified: 23 Apr 2026

    The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and attack vectors, a different vulnerability than CVE-2008-3856.

    Published: 3 Jun 2009
    2.6
    Low

    CVE-2009-1905

    Last Modified: 23 Apr 2026

    The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors.

    Published: 3 Jun 2009
    10
    Critical

    CVE-2008-6821

    Last Modified: 23 Apr 2026

    Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-2007-3676 and CVE-2008-3853.

    Published: 3 Jun 2009
    4.3
    Medium

    CVE-2009-1903

    Last Modified: 23 Apr 2026

    The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.

    Published: 3 Jun 2009
    5
    Medium

    CVE-2009-1900

    Last Modified: 23 Apr 2026

    The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool.

    Published: 3 Jun 2009