CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-1549

    Last Modified: 23 Apr 2026

    AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accept cookie to "correcto."

    Published: 6 May 2009
    5
    Medium

    CVE-2009-1550

    Last Modified: 23 Apr 2026

    Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator login name and password via a direct request.

    Published: 6 May 2009
    7.5
    High

    CVE-2009-1551

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_root parameter to bin/qte_init.php.

    Published: 6 May 2009
    4.4
    Medium

    CVE-2009-1184

    Last Modified: 23 Apr 2026

    The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kernel before 2.6.27.22, and 2.6.28.x before 2.6.28.10, when compat_net is enabled, omits calls to avc_has_perm for the (1) node and (2) port, which allows local users to bypass intended restrictions on network traffic. NOTE: this was incorrectly reported as an issue fixed in 2.6.27.21.

    Published: 5 May 2009
    6.5
    Medium

    CVE-2009-1468

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.

    Published: 5 May 2009
    6.9
    Medium

    CVE-2009-1526

    Last Modified: 16 Dec 2025

    JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arbitrary file in a certain temporary directory, related to a request for this temporary file in the PATH_INFO to the CMD_DB script during a backup action.

    Published: 5 May 2009
    4.3
    Medium

    CVE-2009-1467

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.

    Published: 5 May 2009
    4.3
    Medium

    CVE-2009-1469

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.

    Published: 5 May 2009
    6.9
    Medium

    CVE-2009-1527

    Last Modified: 23 Apr 2026

    Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users to gain privileges via a PTRACE_ATTACH ptrace call during an exec system call that is launching a setuid application, related to locking an incorrect cred_exec_mutex object.

    Published: 5 May 2009
    8.5
    High

    CVE-2009-1525

    Last Modified: 16 Dec 2025

    CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.

    Published: 5 May 2009
    9.3
    Critical

    CVE-2009-1491

    Last Modified: 23 Apr 2026

    McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.

    Published: 5 May 2009
    10
    Critical

    CVE-2009-0720

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 5 May 2009
    7.5
    High

    CVE-2009-1521

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java GUI in the IBM Tivoli Storage Manager (TSM) client 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.5, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17, and the TSM Express client 5.3.3.0 through 5.3.6.5, allows attackers to read or modify arbitrary files via unknown vectors.

    Published: 5 May 2009
    7.1
    High

    CVE-2009-1522

    Last Modified: 23 Apr 2026

    The IBM Tivoli Storage Manager (TSM) client 5.5.0.0 through 5.5.1.17 on AIX and Windows, when SSL is used, allows remote attackers to conduct unspecified man-in-the-middle attacks and read arbitrary files via unknown vectors.

    Published: 5 May 2009
    10
    Critical

    CVE-2008-4828

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express client 5.3.3.0 through 5.3.6.4, allow remote attackers to execute arbitrary code via (1) a request packet that is not properly parsed by an unspecified "generic string handling function" or (2) a crafted NodeName in a dicuGetIdentifyRequest request packet, related to the (a) Web GUI and (b) Java GUI.

    Published: 5 May 2009
    10
    Critical

    CVE-2009-1520

    Last Modified: 23 Apr 2026

    Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors.

    Published: 5 May 2009
    5.5
    Medium

    CVE-2009-3238

    Last Modified: 23 Apr 2026

    The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function's tendency to "return the same value over and over again for long stretches of time."

    Published: 5 May 2009
    5.1
    Medium

    CVE-2008-6788

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.

    Published: 4 May 2009
    5.1
    Medium

    CVE-2008-6789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.

    Published: 4 May 2009
    5.1
    Medium

    CVE-2008-6790

    Last Modified: 23 Apr 2026

    The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.

    Published: 4 May 2009
    5
    Medium

    CVE-2009-1519

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the language parameter.

    Published: 4 May 2009
    5
    Medium

    CVE-2008-6791

    Last Modified: 23 Apr 2026

    PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode field.

    Published: 4 May 2009
    6.8
    Medium

    CVE-2009-1518

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Beltane before 2.3.11 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 May 2009
    7.5
    High

    CVE-2009-1516

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent attackers to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.

    Published: 4 May 2009
    4.3
    Medium

    CVE-2009-1517

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1) GetBackupLocationPath, (2) CallUninstall, (3) SetupDeleteVolume, (4) CanUseEasySetup, (5) CallAddInitialProtection, and (6) CallTour methods.

    Published: 4 May 2009
    5
    Medium

    CVE-2009-1514

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.53 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a throw statement with a long exception value.

    Published: 4 May 2009
    5
    Medium

    CVE-2009-1374

    Last Modified: 23 Apr 2026

    Buffer overflow in the decrypt_out function in Pidgin (formerly Gaim) before 2.5.6 allows remote attackers to cause a denial of service (application crash) via a QQ packet.

    Published: 3 May 2009
    3.3
    Low

    CVE-2009-1753

    Last Modified: 23 Apr 2026

    Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."

    Published: 2 May 2009
    7.1
    High

    CVE-2009-1373

    Last Modified: 23 Apr 2026

    Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information.

    Published: 2 May 2009
    9.3
    Critical

    CVE-2009-1376

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.

    Published: 2 May 2009
    4.6
    Medium

    CVE-2009-1573

    Last Modified: 23 Apr 2026

    xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.

    Published: 2 May 2009
    6.5
    Medium

    CVE-2009-1512

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveConfig.php.

    Published: 1 May 2009
    5
    Medium

    CVE-2008-6786

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in geekigeeki.py in GeekiGeeki before 3.0 allow remote attackers to read arbitrary files via directory traversal sequences in a pagename argument in the (1) handle_edit and (2) handle_raw functions.

    Published: 1 May 2009
    7.5
    High

    CVE-2008-6787

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the user.

    Published: 1 May 2009
    7.5
    High

    CVE-2009-1508

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the cookie_username parameter to Configure.php.

    Published: 1 May 2009
    7.5
    High

    CVE-2009-1509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 1 May 2009
    6.8
    Medium

    CVE-2008-6785

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, as demonstrated by creating a name.php file.

    Published: 1 May 2009
    7.5
    High

    CVE-2009-1510

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the file parameter to (1) ki_makepic.php and (2) ki_nojsdisplayimage.php in ki_base/.

    Published: 1 May 2009
    7.8
    High

    CVE-2009-1511

    Last Modified: 23 Apr 2026

    GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file that contains a certain large btChunkLen value.

    Published: 1 May 2009
    7.5
    High

    CVE-2008-6776

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to execute arbitrary SQL commands via the phid parameter.

    Published: 1 May 2009
    7.5
    High

    CVE-2008-6778

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 1 May 2009
    7.5
    High

    CVE-2008-6779

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.php.

    Published: 1 May 2009
    7.5
    High

    CVE-2008-6780

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Published: 1 May 2009
    7.5
    High

    CVE-2008-6781

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Published: 1 May 2009
    7.5
    High

    CVE-2009-1365

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media Interactive Server and Flash Media Streaming Server, allows remote attackers to execute arbitrary remote procedures within an ActionScript file on the server via RPC requests.

    Published: 1 May 2009
    4.3
    Medium

    CVE-2009-1501

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via EXIF tags in an image.

    Published: 1 May 2009
    6.8
    Medium

    CVE-2009-1506

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to banner-details.php.

    Published: 1 May 2009
    7.5
    High

    CVE-2009-1504

    Last Modified: 23 Apr 2026

    Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by setting the xlaAFPadmin cookie to "lvl=1&userid=1."

    Published: 1 May 2009
    6.5
    Medium

    CVE-2009-1505

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, with News Page nodes create and edit privileges, to execute arbitrary SQL commands via the Include Words (aka keywords) field.

    Published: 1 May 2009
    7.5
    High

    CVE-2009-1503

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 1 May 2009