CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-1743

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote attackers to create and overwrite arbitrary files via a filename containing a ..\ (dot dot backslash) sequence in a Hollywood FX Compressed Archive (.hfz) file. NOTE: this can be leveraged for code execution by decompressing a file to a Startup folder. NOTE: some of these details are obtained from third party information.

    Published: 21 May 2009
    5
    Medium

    CVE-2009-1829

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PCNFSD dissector in Wireshark 0.8.20 through 1.0.7 allows remote attackers to cause a denial of service (crash) via crafted PCNFSD packets.

    Published: 21 May 2009
    7.5
    High

    CVE-2009-1739

    Last Modified: 23 Apr 2026

    PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including administrative privileges, by setting the authuser cookie parameter to a valid username.

    Published: 20 May 2009
    7.5
    High

    CVE-2009-1734

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 20 May 2009
    4.3
    Medium

    CVE-2009-1735

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web script or HTML via the searchtxt parameter. NOTE: some of these details are obtained from third party information.

    Published: 20 May 2009
    3.5
    Low

    CVE-2009-1738

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."

    Published: 20 May 2009
    9.3
    Critical

    CVE-2009-1740

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remote attackers to execute arbitrary code via a long argument to the (1) SetFilePath and (2) SetClientCookie methods. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 May 2009
    6.8
    Medium

    CVE-2009-1741

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

    Published: 20 May 2009
    4.3
    Medium

    CVE-2009-1732

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/usermanager in IPplan 4.91a allows remote attackers to inject arbitrary web script or HTML via the grp parameter.

    Published: 20 May 2009
    6.8
    Medium

    CVE-2009-1733

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of administrators for requests that (1) change the password, (2) add users, or (3) delete users via unknown vectors.

    Published: 20 May 2009
    7.5
    High

    CVE-2009-1736

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewCategory action to index.php.

    Published: 20 May 2009
    7.8
    High

    CVE-2009-1737

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories via a .. (dot dot) in the dir parameter.

    Published: 20 May 2009
    7.5
    High

    CVE-2009-1742

    Last Modified: 23 Apr 2026

    code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql function.

    Published: 20 May 2009
    10
    Critical

    CVE-2009-1730

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command.

    Published: 20 May 2009
    7.5
    High

    CVE-2009-1731

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands via a base64-encoded supervisor cookie.

    Published: 20 May 2009
    4.3
    Medium

    CVE-2009-1724

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other platforms, allows remote attackers to inject arbitrary web script or HTML via vectors related to parent and top objects.

    Published: 20 May 2009
    4.3
    Medium

    CVE-2009-1418

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 May 2009
    6.8
    Medium

    CVE-2009-3605

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Poppler 0.10.5 and earlier allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, related to (1) glib/poppler-page.cc; (2) ArthurOutputDev.cc, (3) CairoOutputDev.cc, (4) GfxState.cc, (5) JBIG2Stream.cc, (6) PSOutputDev.cc, and (7) SplashOutputDev.cc in poppler/; and (8) SplashBitmap.cc, (9) Splash.cc, and (10) SplashFTFont.cc in splash/. NOTE: this may overlap CVE-2009-0791.

    Published: 19 May 2009
    6.8
    Medium

    CVE-2009-0791

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Xpdf 2.x and 3.x and Poppler 0.x, as used in the pdftops filter in CUPS 1.1.17, 1.1.22, and 1.3.7, GPdf, and kdegraphics KPDF, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file that triggers a heap-based buffer overflow, possibly related to (1) Decrypt.cxx, (2) FoFiTrueType.cxx, (3) gmem.c, (4) JBIG2Stream.cxx, and (5) PSOutputDev.cxx in pdftops/. NOTE: the JBIG2Stream.cxx vector may overlap CVE-2009-1179.

    Published: 19 May 2009
    5
    Medium

    CVE-2009-1755

    Last Modified: 23 Apr 2026

    Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.c in nsd 2.3.7, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a buffer overflow.

    Published: 19 May 2009
    9.3
    Critical

    CVE-2009-1667

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long entry in a .m3u file, a different vector than CVE-2009-5137.

    Published: 18 May 2009
    4
    Medium

    CVE-2009-1668

    Last Modified: 23 Apr 2026

    TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort) command without an active file transfer.

    Published: 18 May 2009
    9.3
    Critical

    CVE-2009-1672

    Last Modified: 23 Apr 2026

    The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allows remote attackers to (1) execute arbitrary code via a .jnlp URL in the argument to the launch method, and might allow remote attackers to launch JRE installation processes via the (2) installLatestJRE or (3) installJRE method.

    Published: 18 May 2009
    4.9
    Medium

    CVE-2009-1673

    Last Modified: 23 Apr 2026

    The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.

    Published: 18 May 2009
    9.3
    Critical

    CVE-2009-1674

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code via a long .cof pathname in a [TOOL_SETTINGS] section in a .mcp file, possibly a related issue to CVE-2009-1608.

    Published: 18 May 2009
    9.3
    Critical

    CVE-2009-1675

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV command.

    Published: 18 May 2009
    Unknown

    CVE-2009-1676

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1535. Reason: This candidate is a duplicate of CVE-2009-1535. Notes: All CVE users should reference CVE-2009-1535 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 May 2009
    9.3
    Critical

    CVE-2009-1671

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType, (2) setAdditionalPackages, (3) compareVersion, (4) getStaticCLSID, or (5) launch method.

    Published: 18 May 2009
    7.5
    High

    CVE-2009-1670

    Last Modified: 23 Apr 2026

    user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin accounts via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 18 May 2009
    7.5
    High

    CVE-2009-1678

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the version parameter to boards/boards_rss.php.

    Published: 18 May 2009
    9.3
    Critical

    CVE-2009-1666

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, related to improper dereferencing. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 May 2009
    10
    Critical

    CVE-2009-0721

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Easy Login in the Sender module in HP Remote Graphics Software (RGS) 4.0.0 through 5.2.4 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 18 May 2009
    6.5
    Medium

    CVE-2009-1677

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account's "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php.

    Published: 18 May 2009
    6.8
    Medium

    CVE-2009-1252

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.

    Published: 18 May 2009
    2.1
    Low

    CVE-2009-1756

    Last Modified: 23 Apr 2026

    SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.

    Published: 18 May 2009
    5
    Medium

    CVE-2009-1769

    Last Modified: 23 Apr 2026

    The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different error messages depending on whether a username is valid, which allows remote attackers to enumerate valid usernames.

    Published: 18 May 2009
    6.8
    Medium

    CVE-2008-6811

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/plugins/wp-shopping-cart/.

    Published: 17 May 2009
    7.5
    High

    CVE-2008-6810

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allow remote attackers to execute arbitrary SQL commands via the (1) myusername (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Published: 17 May 2009
    6.8
    Medium

    CVE-2009-1659

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/uploadimage.php in eLitius 1.0 allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files via an avatar file with an accepted Content-Type such as image/gif, then requesting the file in admin/banners/.

    Published: 17 May 2009
    9.3
    Critical

    CVE-2009-1660

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file entry in a .vpl file.

    Published: 17 May 2009
    7.5
    High

    CVE-2009-1664

    Last Modified: 23 Apr 2026

    myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges via modified userid, txtpassword, and txtRpassword parameters.

    Published: 17 May 2009
    7.5
    High

    CVE-2009-1657

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Starrating plugin before 0.7.7 for b2evolution allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 17 May 2009
    6.8
    Medium

    CVE-2009-1661

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php.

    Published: 17 May 2009
    7.5
    High

    CVE-2009-1662

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) Password fields, as reachable from admin/index.php.

    Published: 17 May 2009
    6.8
    Medium

    CVE-2009-1663

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the uploads/[username] directory.

    Published: 17 May 2009
    7.5
    High

    CVE-2008-6809

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 allows remote attackers to execute arbitrary SQL commands via the HotelID parameter.

    Published: 17 May 2009
    7.5
    High

    CVE-2009-1658

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Published: 17 May 2009
    6.4
    Medium

    CVE-2009-1665

    Last Modified: 23 Apr 2026

    myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.

    Published: 17 May 2009
    7.8
    High

    CVE-2009-1653

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the script parameter.

    Published: 16 May 2009
    7.5
    High

    CVE-2009-1649

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in arch.php in beLive 0.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the arch parameter.

    Published: 16 May 2009