CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-1787

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.

    Published: 26 May 2009
    4.3
    Medium

    CVE-2009-1790

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CGI RESCUE Trees before 2.11 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 26 May 2009
    7.2
    High

    CVE-2009-1476

    Last Modified: 23 Apr 2026

    Buffer overflow in lib/load_http.c in ippool in Darren Reed IPFilter (aka IP Filter) 4.1.31 allows local users to gain privileges via vectors involving a long hostname in a URL.

    Published: 26 May 2009
    6.9
    Medium

    CVE-2009-1786

    Last Modified: 23 Apr 2026

    The malloc subsystem in libc in IBM AIX 5.3 and 6.1 allows local users to create or overwrite arbitrary files via a symlink attack on the log file associated with the MALLOCDEBUG environment variable.

    Published: 26 May 2009
    10
    Critical

    CVE-2009-1636

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Internet Agent (aka GWIA) component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to execute arbitrary code via (1) a crafted e-mail address in an SMTP session or (2) an SMTP command.

    Published: 26 May 2009
    4.3
    Medium

    CVE-2009-1754

    Last Modified: 23 Apr 2026

    The PackageManagerService class in services/java/com/android/server/PackageManagerService.java in Android 1.5 through 1.5 CRB42 does not properly check developer certificates during processing of sharedUserId requests at an application's installation time, which allows remote user-assisted attackers to access application data by creating a package that specifies a shared user ID with an arbitrary application.

    Published: 26 May 2009
    7.5
    High

    CVE-2009-1634

    Last Modified: 23 Apr 2026

    The WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 does not properly implement session management mechanisms, which allows remote attackers to gain access to user accounts via unspecified vectors.

    Published: 26 May 2009
    4.3
    Medium

    CVE-2009-1789

    Last Modified: 23 Apr 2026

    mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.

    Published: 26 May 2009
    4.3
    Medium

    CVE-2009-1776

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via javascript: URIs in the (1) request and (2) return_link_url parameters.

    Published: 22 May 2009
    5
    Medium

    CVE-2009-1777

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the redirect parameter.

    Published: 22 May 2009
    6.8
    Medium

    CVE-2009-1778

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 22 May 2009
    7.5
    High

    CVE-2009-1779

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the form_include_template parameter.

    Published: 22 May 2009
    7.5
    High

    CVE-2009-1780

    Last Modified: 23 Apr 2026

    admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.

    Published: 22 May 2009
    10
    Critical

    CVE-2009-1783

    Last Modified: 23 Apr 2026

    Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.

    Published: 22 May 2009
    10
    Critical

    CVE-2009-1784

    Last Modified: 23 Apr 2026

    The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass malware detection via a crafted (1) RAR and (2) ZIP archive.

    Published: 22 May 2009
    4.3
    Medium

    CVE-2009-1785

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Ulteo Open Virtual Desktop 1.0 allows remote attackers to inject arbitrary web script or HTML via the error parameter to header.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 May 2009
    7.5
    High

    CVE-2009-1781

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inject arbitrary PHP code into phpre_config.php via the form_aula parameter.

    Published: 22 May 2009
    4.3
    Medium

    CVE-2009-1775

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ulteo Open Virtual Desktop 1.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) admin/applications.php, (2) admin/appsgroup.php, (3) admin/users.php, (4) admin/usersgroup.php, and (5) admin/tasks.php; (6) show parameter to admin/logs.php; and (7) mode parameter to admin/configuration-partial.php. NOTE: some of these details are obtained from third party information.

    Published: 22 May 2009
    6.8
    Medium

    CVE-2009-1782

    Last Modified: 23 Apr 2026

    Multiple F-Secure anti-virus products, including Anti-Virus for Microsoft Exchange 7.10 and earlier; Internet Gatekeeper for Windows 6.61 and earlier, Windows 6.61 and earlier, and Linux 2.16 and earlier; Internet Security 2009 and earlier, Anti-Virus 2009 and earlier, Client Security 8.0 and earlier, and others; allow remote attackers to bypass malware detection via a crafted (1) ZIP and (2) RAR archive.

    Published: 22 May 2009
    7.5
    High

    CVE-2009-1764

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a digg action.

    Published: 22 May 2009
    7.5
    High

    CVE-2009-1770

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 22 May 2009
    7.5
    High

    CVE-2009-1771

    Last Modified: 23 Apr 2026

    index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.

    Published: 22 May 2009
    4.3
    Medium

    CVE-2009-1772

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web script or HTML via the re_route parameter to the login script.

    Published: 22 May 2009
    6.4
    Medium

    CVE-2009-1766

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 May 2009
    9.3
    Critical

    CVE-2009-1774

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to example/index.php. NOTE: this was originally reported as an issue affecting the do parameter, but traversal with that parameter might depend on a modified example/index.php. NOTE: some of these details are obtained from third party information.

    Published: 22 May 2009
    6.8
    Medium

    CVE-2009-1765

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the langpref parameter to (1) data/modules/contactform/module_info.php, (2) data/modules/blog/module_info.php, and (3) data/modules/albums/module_info.php, different vectors than CVE-2008-3194.

    Published: 22 May 2009
    5
    Medium

    CVE-2009-1767

    Last Modified: 23 Apr 2026

    admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.

    Published: 22 May 2009
    5
    Medium

    CVE-2009-1773

    Last Modified: 23 Apr 2026

    activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to the login script, which reveals the installation path in an error message.

    Published: 22 May 2009
    5
    Medium

    CVE-2009-1768

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 22 May 2009
    4.3
    Medium

    CVE-2009-1635

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 and 8.x before 8.0 HP2 allow remote attackers to inject arbitrary web script or HTML via (1) the User.lang parameter to the login page (aka gw/webacc), (2) style expressions in a message that contains an HTML file, or (3) vectors associated with incorrect protection mechanisms against scripting, as demonstrated using whitespace between JavaScript event names and values.

    Published: 22 May 2009
    7.2
    High

    CVE-2009-1763

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_108 on the x86 platform allows local users to gain privileges or cause a denial of service (filesystem or memory corruption) via unknown vectors.

    Published: 22 May 2009
    4.3
    Medium

    CVE-2009-1762

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x before 7.03 HP2 allow remote attackers to inject arbitrary web script or HTML via the (1) GWAP.version or (2) User.Theme (aka User.Theme.index) parameter.

    Published: 22 May 2009
    6.8
    Medium

    CVE-2009-1757

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 22 May 2009
    7.5
    High

    CVE-2008-6812

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the det parameter.

    Published: 21 May 2009
    7.5
    High

    CVE-2008-6813

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQL commands via the id_kat parameter.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1747

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL commands via the forumid parameter in a post action.

    Published: 21 May 2009
    6
    Medium

    CVE-2009-1750

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1751

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1752

    Last Modified: 23 Apr 2026

    exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1748

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.

    Published: 21 May 2009
    4.3
    Medium

    CVE-2009-1749

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject arbitrary web script or HTML via the (1) userman_form and (2) webpages_form parameters.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1746

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 21 May 2009
    10
    Critical

    CVE-2009-1745

    Last Modified: 23 Apr 2026

    Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access.

    Published: 21 May 2009
    4
    Medium

    CVE-2009-0897

    Last Modified: 23 Apr 2026

    IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to obtain sensitive information via vectors related to the "schema DB2 instance id" and the bcgarchive (aka the archiver script).

    Published: 21 May 2009
    4.3
    Medium

    CVE-2009-1729

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the abperson_displayName parameter to uwc/abs/search.xml in the Add Contact implementation in the Personal Address Book component or (2) the temporaryCalendars parameter to uwc/base/UWCMain.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1594

    Last Modified: 23 Apr 2026

    Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encoded newline), as demonstrated by a %0A in a cross-site scripting (XSS) attack URL.

    Published: 21 May 2009
    10
    Critical

    CVE-2009-1161

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on Windows, as used in Cisco Unified Service Monitor, Security Manager, TelePresence Readiness Assessment Manager, Unified Operations Manager, Unified Provisioning Manager, and other products, allows remote attackers to access arbitrary files via unspecified vectors.

    Published: 21 May 2009
    4.3
    Medium

    CVE-2009-1593

    Last Modified: 23 Apr 2026

    Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modified end tag of a SCRIPT element.

    Published: 21 May 2009
    4.3
    Medium

    CVE-2009-1744

    Last Modified: 23 Apr 2026

    InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to cause a denial of service (application crash) via a crafted Hollywood FX Compressed Archive (.hfz) file.

    Published: 21 May 2009
    6.8
    Medium

    CVE-2009-1381

    Last Modified: 23 Apr 2026

    The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibly other operating systems and versions, allows remote attackers to execute arbitrary commands via shell metacharacters in a username string that is used by the ypmatch program. NOTE: this issue exists because of an incomplete fix for CVE-2009-1579.

    Published: 21 May 2009