CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2009-1901

    Last Modified: 23 Apr 2026

    The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.

    Published: 3 Jun 2009
    5
    Medium

    CVE-2009-1898

    Last Modified: 23 Apr 2026

    The secure login page in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 does not redirect to an https page upon receiving an http request, which makes it easier for remote attackers to read the contents of WAS sessions by sniffing the network.

    Published: 3 Jun 2009
    10
    Critical

    CVE-2009-1899

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticated users to obtain sensitive information via unknown use of the wsadmin scripting tool, related to a "security exposure in wsadmin."

    Published: 3 Jun 2009
    10
    Critical

    CVE-2009-0896

    Last Modified: 23 Apr 2026

    Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.

    Published: 3 Jun 2009
    4.3
    Medium

    CVE-2009-0899

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.24 and 7.0 through 7.0.0.4, IBM WebSphere Portal Server 5.1 through 6.0, and IBM Integrated Solutions Console (ISC) 6.0.1 do not properly set the IsSecurityEnabled security flag during migration of WebSphere Member Manager (WMM) to Virtual Member Manager (VMM) and a Federated Repository, which allows attackers to obtain sensitive information from repositories via unspecified vectors.

    Published: 3 Jun 2009
    5
    Medium

    CVE-2009-1902

    Last Modified: 23 Apr 2026

    The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference.

    Published: 3 Jun 2009
    6.8
    Medium

    CVE-2009-1932

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (ext/libpng/gstpngdec.c) in GStreamer Good Plug-ins (aka gst-plugins-good or gstreamer-plugins-good) 0.10.15 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted PNG file, which triggers a buffer overflow.

    Published: 3 Jun 2009
    4.3
    Medium

    CVE-2009-0023

    Last Modified: 23 Apr 2026

    The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache HTTP Server, (3) the mod_apreq2 module for the Apache HTTP Server, or (4) an application that uses the libapreq2 library, which triggers a heap-based buffer underflow.

    Published: 3 Jun 2009
    5
    Medium

    CVE-2009-0033

    Last Modified: 23 Apr 2026

    Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.

    Published: 3 Jun 2009
    4.3
    Medium

    CVE-2009-0580

    Last Modified: 23 Apr 2026

    Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.

    Published: 3 Jun 2009
    9.3
    Critical

    CVE-2009-0185

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted MS ADPCM encoded audio data in an AVI movie file.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0188

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie composed of a Sorenson 3 video file.

    Published: 2 Jun 2009
    10
    Critical

    CVE-2009-0894

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vectors involving the DirectShow (aka DShow) frontend and improper handling of the XVID_ERR_MEMORY return code during processing of a crafted movie file. NOTE: some of these details are obtained from third party information.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0950

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an itms: URL with a long URL component after a colon.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0951

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FLC compression file.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0952

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted compressed PSD image.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0954

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie file containing crafted Clipping Region (CRGN) atom types.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0955

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image description atoms in an Apple video file, related to a "sign extension issue."

    Published: 2 Jun 2009
    10
    Critical

    CVE-2009-0893

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MBlock) number in a video stream in a crafted movie file that triggers heap memory corruption, related to a "missing resync marker range check" and the (1) decoder_iframe, (2) decoder_pframe, and (3) decoder_bframe functions.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0956

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.6.2 does not properly initialize memory before use in handling movie files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a movie containing a user data atom of size zero.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0953

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.

    Published: 2 Jun 2009
    9.3
    Critical

    CVE-2009-0957

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.

    Published: 2 Jun 2009
    4.3
    Medium

    CVE-2009-1880

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MT312 REP-BBS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) model.php and (2) config.php with timestamps before 20090521.

    Published: 2 Jun 2009
    4.3
    Medium

    CVE-2009-1881

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MT312 IMG-BBS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to model.php with a timestamp before 20090521.

    Published: 2 Jun 2009
    10
    Critical

    CVE-2004-2764

    Last Modified: 23 Apr 2026

    Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and unprivileged servlets to gain privileges and read data from other applets via unspecified vectors related to classes in the XSLT processor, aka "XML sniffing."

    Published: 2 Jun 2009
    5
    Medium

    CVE-2009-1196

    Last Modified: 23 Apr 2026

    The directory-services functionality in the scheduler in CUPS 1.1.17 and 1.1.22 allows remote attackers to cause a denial of service (cupsd daemon outage or crash) via manipulations of the timing of CUPS browse packets, related to a "pointer use-after-delete flaw."

    Published: 2 Jun 2009
    7.5
    High

    CVE-2009-0949

    Last Modified: 23 Apr 2026

    The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags.

    Published: 2 Jun 2009
    5
    Medium

    CVE-2009-1386

    Last Modified: 23 Apr 2026

    ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

    Published: 2 Jun 2009
    5
    Medium

    CVE-2009-1387

    Last Modified: 23 Apr 2026

    The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence DTLS handshake message, related to a "fragment bug."

    Published: 2 Jun 2009
    5.8
    Medium

    CVE-2004-2763

    Last Modified: 23 Apr 2026

    The default configuration of Sun ONE/iPlanet Web Server 4.1 SP1 through SP12 and 6.0 SP1 through SP5 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulnerable to cross-site scripting.

    Published: 1 Jun 2009
    9.3
    Critical

    CVE-2003-1572

    Last Modified: 23 Apr 2026

    Sun Java Media Framework (JMF) 2.1.1 through 2.1.1c allows unsigned applets to cause a denial of service (JVM crash) and read or write unauthorized memory locations via the ReadEnv class, as demonstrated by reading environment variables using modified .data and .size fields.

    Published: 1 Jun 2009
    10
    Critical

    CVE-2003-1573

    Last Modified: 23 Apr 2026

    The PointBase 4.6 database component in the J2EE 1.4 reference implementation (J2EE/RI) allows remote attackers to execute arbitrary programs, conduct a denial of service, and obtain sensitive information via a crafted SQL statement, related to "inadequate security settings and library bugs in sun.* and org.apache.* packages."

    Published: 1 Jun 2009
    Unknown

    CVE-2009-3870

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3870. Reason: This candidate is a duplicate of CVE-2008-3870. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2008-3870 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Jun 2009
    4.3
    Medium

    CVE-2009-1845

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestName parameter.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1846

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the THEME_FOLDER parameter to (1) Corporate/homepage.php, (2) Fusion/homepage.php, (3) Joombo/homepage.php, (4) Streamline/homepage.php, and (5) Structure/homepage.php in themes/.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1847

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Easy PX 41 CMS 9.0 B1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fiche parameter.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1848

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1852

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1853

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1854

    Last Modified: 23 Apr 2026

    Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1850

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 1 Jun 2009
    4
    Medium

    CVE-2009-1805

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the VMware Descheduled Time Accounting driver in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745, VMware Fusion 2.x before 2.0.2 build 147997, VMware ESXi 3.5, and VMware ESX 3.0.2, 3.0.3, and 3.5, when the Descheduled Time Accounting Service is not running, allows guest OS users on Windows to cause a denial of service via unknown vectors.

    Published: 1 Jun 2009
    4.3
    Medium

    CVE-2009-1849

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Monitor_Bandwidth function in PRTG Traffic Grapher 6.2.2.977 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Jun 2009
    4.7
    Medium

    CVE-2008-6819

    Last Modified: 23 Apr 2026

    win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1851

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in include.php in phpBugTracker 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Jun 2009
    3.5
    Low

    CVE-2009-1844

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Drupal 5.x before 5.18 and 6.x before 6.12 allow (1) remote authenticated users to inject arbitrary web script or HTML via crafted UTF-8 byte sequences that are treated as UTF-7 by Internet Explorer 6 and 7, which are not properly handled in the "HTML exports of books" feature; and (2) allow remote authenticated users with administer taxonomy permissions to inject arbitrary web script or HTML via the help text of an arbitrary vocabulary. NOTE: vector 1 exists because of an incomplete fix for CVE-2009-1575.

    Published: 1 Jun 2009
    5
    Medium

    CVE-2008-6817

    Last Modified: 23 Apr 2026

    Mole Group Lastminute Script 4.0 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Jun 2009
    5
    Medium

    CVE-2008-6818

    Last Modified: 23 Apr 2026

    Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1842

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.

    Published: 1 Jun 2009
    7.5
    High

    CVE-2009-1843

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) results_table_web.php, and (f) question.php; and the (2) order_number parameter to (g) answers.php and (h) question.php.

    Published: 1 Jun 2009