CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-1650

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) albumID, (2) tagID, and (3) photoID parameters to index.html.

    Published: 16 May 2009
    7.5
    High

    CVE-2009-1651

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/member_details.php in 2daybiz Business Community Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 16 May 2009
    10
    Critical

    CVE-2009-1656

    Last Modified: 23 Apr 2026

    Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulnerability."

    Published: 16 May 2009
    7.5
    High

    CVE-2009-1652

    Last Modified: 23 Apr 2026

    admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.

    Published: 16 May 2009
    4.3
    Medium

    CVE-2009-1654

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in questiondetail.php in Easy Scripts Answer and Question Script allows remote attackers to inject arbitrary web script or HTML via the questionid parameter.

    Published: 16 May 2009
    6.5
    Medium

    CVE-2009-1655

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in myaccount.php in Easy Scripts Answer and Question Script allow remote authenticated users to execute arbitrary SQL commands via the (1) user name (userid parameter) and (2) password.

    Published: 16 May 2009
    7.5
    High

    CVE-2009-1638

    Last Modified: 23 Apr 2026

    Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access by setting the JobCareerAdmin cookie to Login.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1639

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Novell 4.03 allows user-assisted attackers to execute arbitrary code via a crafted .NKNT file.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1640

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1641

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1643

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1647

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. NOTE: some of these details are obtained from third party information.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1646

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1644

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.

    Published: 15 May 2009
    6.4
    Medium

    CVE-2009-1637

    Last Modified: 23 Apr 2026

    profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1642

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. NOTE: the latter was also subsequently reported in "prior to 3.1.3.7."

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1645

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.

    Published: 15 May 2009
    7.5
    High

    CVE-2009-3553

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS 1.3.7 and 1.3.10 allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, related to improperly maintaining a reference count. NOTE: some of these details are obtained from third party information.

    Published: 15 May 2009
    9.8
    Critical

    CVE-2009-0948

    Last Modified: 21 Nov 2024

    Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.

    Published: 15 May 2009
    9.8
    Critical

    CVE-2009-0947

    Last Modified: 21 Nov 2024

    Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1788

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value.

    Published: 15 May 2009
    9.3
    Critical

    CVE-2009-1791

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value.

    Published: 15 May 2009
    7.2
    High

    CVE-2009-0714

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.

    Published: 14 May 2009
    7.5
    High

    CVE-2009-1465

    Last Modified: 23 Apr 2026

    Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it easier for remote attackers to obtain access.

    Published: 14 May 2009
    5.5
    Medium

    CVE-2009-1466

    Last Modified: 23 Apr 2026

    Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.

    Published: 14 May 2009
    6.8
    Medium

    CVE-2009-1464

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate processes via a killprocess job.

    Published: 14 May 2009
    9.3
    Critical

    CVE-2009-0945

    Last Modified: 23 Apr 2026

    Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Google Chrome Stable before 1.0.154.65, and possibly other products allows remote attackers to execute arbitrary code via a document with a SVGPathList data structure containing a negative index in the (1) SVGTransformList, (2) SVGStringList, (3) SVGNumberList, (4) SVGPathSegList, (5) SVGPointList, or (6) SVGLengthList SVGList object, which triggers memory corruption.

    Published: 13 May 2009
    9.3
    Critical

    CVE-2009-0010

    Last Modified: 23 Apr 2026

    Integer underflow in QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, and Apple QuickTime before 7.6.2, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a crafted 0x77 Poly tag and a crafted length field, which triggers a heap-based buffer overflow.

    Published: 13 May 2009
    4.3
    Medium

    CVE-2009-0144

    Last Modified: 23 Apr 2026

    CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0145

    Last Modified: 23 Apr 2026

    CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.

    Published: 13 May 2009
    4.4
    Medium

    CVE-2009-0150

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0158

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0160

    Last Modified: 23 Apr 2026

    QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption.

    Published: 13 May 2009
    6.4
    Medium

    CVE-2009-0161

    Last Modified: 23 Apr 2026

    The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate.

    Published: 13 May 2009
    4.3
    Medium

    CVE-2009-0156

    Last Modified: 23 Apr 2026

    Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0157

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0944

    Last Modified: 23 Apr 2026

    The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0942

    Last Modified: 23 Apr 2026

    Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

    Published: 13 May 2009
    7.2
    High

    CVE-2008-1517

    Last Modified: 23 Apr 2026

    Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (system shutdown) via unspecified vectors related to workqueues.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0154

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.

    Published: 13 May 2009
    4.3
    Medium

    CVE-2009-0162

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.

    Published: 13 May 2009
    4.4
    Medium

    CVE-2009-0149

    Last Modified: 23 Apr 2026

    Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.

    Published: 13 May 2009
    7.5
    High

    CVE-2009-0152

    Last Modified: 23 Apr 2026

    iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0155

    Last Modified: 23 Apr 2026

    Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers a heap-based buffer overflow.

    Published: 13 May 2009
    6.8
    Medium

    CVE-2009-0943

    Last Modified: 23 Apr 2026

    Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files.

    Published: 13 May 2009
    5
    Medium

    CVE-2009-1758

    Last Modified: 23 Apr 2026

    The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and probably other versions allows guest user applications to cause a denial of service (kernel oops) of the guest OS by triggering a segmentation fault in "certain address ranges."

    Published: 13 May 2009
    10
    Critical

    CVE-2009-1669

    Last Modified: 23 Apr 2026

    The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are obtained from third party information.

    Published: 13 May 2009
    9.3
    Critical

    CVE-2009-0225

    Last Modified: 23 Apr 2026

    Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnerability."

    Published: 12 May 2009
    9.3
    Critical

    CVE-2009-1128

    Last Modified: 23 Apr 2026

    Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to memory corruption, aka "PP7 Memory Corruption Vulnerability," a different vulnerability than CVE-2009-1129.

    Published: 12 May 2009
    9.3
    Critical

    CVE-2009-1131

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of Bounds Vulnerability."

    Published: 12 May 2009