CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-2438

    Last Modified: 23 Apr 2026

    Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2008-6760

    Last Modified: 23 Apr 2026

    ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2008-6762

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

    Published: 28 Apr 2009
    7.5
    High

    CVE-2008-6763

    Last Modified: 23 Apr 2026

    login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2008-6765

    Last Modified: 23 Apr 2026

    ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to access the contents of an arbitrary shopping cart via a modified cart_name parameter.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2009-1458

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and (3) the cat parameter in a reordercat action.

    Published: 28 Apr 2009
    6.8
    Medium

    CVE-2009-1459

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in razorCMS before 0.4 allows remote attackers to hijack the authentication of administrators for requests that create a web page containing PHP code.

    Published: 28 Apr 2009
    4.6
    Medium

    CVE-2009-1460

    Last Modified: 23 Apr 2026

    razorCMS before 0.4 uses weak permissions for (1) admin/core/admin_config.php, which allows local users to obtain the administrator's password hash and FTP user credentials; and (2) the root directory, (3) datastore/, and (4) admin/core/, which allows local users to have an unspecified impact.

    Published: 28 Apr 2009
    6.5
    Medium

    CVE-2009-1456

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2009-1457

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Apr 2009
    7.5
    High

    CVE-2009-1463

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in razorCMS before 0.4 allows remote attackers to inject arbitrary PHP code into any page by saving content as a .php file.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2008-6759

    Last Modified: 23 Apr 2026

    ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via a URL in the POST_DATA parameter to manuals_search.php, which reveals the installation path in an error message.

    Published: 28 Apr 2009
    7.2
    High

    CVE-2009-1462

    Last Modified: 23 Apr 2026

    The Security Manager in razorCMS before 0.4 does not verify the permissions of every file owned by the apache user account, which is inconsistent with the documentation and allows local users to have an unspecified impact.

    Published: 28 Apr 2009
    6.8
    Medium

    CVE-2008-6758

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to hijack the authentication of arbitrary users for requests that conduct persistent cross-site scripting (XSS) attacks via the cart_name parameter in a save action.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2008-6766

    Last Modified: 23 Apr 2026

    cart_save.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to cause a denial of service (excessive shopping carts) via a flood of requests.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2009-1454

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in tasks.php in WebCollab before 2.50 (aka Billy Goat) allows remote attackers to inject arbitrary web script or HTML via the selection parameter in a todo action.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2008-6757

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in manuals_search.php in ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to inject arbitrary web script or HTML via the manuals_search parameter.

    Published: 28 Apr 2009
    10
    Critical

    CVE-2008-6761

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject arbitrary PHP code into const.inc.php via the installdbname parameter (aka the Database Name field). NOTE: the installation instructions specify deleting admin/install.php.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2008-6764

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 28 Apr 2009
    10
    Critical

    CVE-2008-6767

    Last Modified: 23 Apr 2026

    wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

    Published: 28 Apr 2009
    7.5
    High

    CVE-2009-1452

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript parameters. NOTE: the _page_content vector is already is covered by CVE-2009-1450.

    Published: 28 Apr 2009
    6.8
    Medium

    CVE-2009-1453

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information.

    Published: 28 Apr 2009
    6.8
    Medium

    CVE-2009-1455

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in WebCollab before 2.50 (aka Billy Goat) allow remote attackers to hijack the authentication of administrators for requests that change an arbitrary password or have other unspecified impact.

    Published: 28 Apr 2009
    3.5
    Low

    CVE-2009-1461

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Create New Page form in razorCMS 0.3 RC2 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Page Title field.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2009-1451

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 28 Apr 2009
    7.5
    High

    CVE-2009-1450

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2009-1523

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.M2 allows remote attackers to access arbitrary files via directory traversal sequences in the URI.

    Published: 28 Apr 2009
    7.5
    High

    CVE-2009-0663

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbitrary code via unspecified input to an application that uses the getline and pg_getline functions to read database rows.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2009-1255

    Last Modified: 23 Apr 2026

    The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon's TCP port.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2009-1341

    Last Modified: 23 Apr 2026

    Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 for Perl allows context-dependent attackers to cause a denial of service (memory consumption) by fetching data with BYTEA columns.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2009-1494

    Last Modified: 23 Apr 2026

    The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port.

    Published: 28 Apr 2009
    4.3
    Medium

    CVE-2009-1524

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.

    Published: 28 Apr 2009
    5
    Medium

    CVE-2008-6755

    Last Modified: 23 Apr 2026

    ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.

    Published: 27 Apr 2009
    2.1
    Low

    CVE-2008-6756

    Last Modified: 23 Apr 2026

    ZoneMinder 1.23.3 on Gentoo Linux uses 0644 permissions for /etc/zm.conf, which allows local users to obtain the database username and password by reading this file.

    Published: 27 Apr 2009
    4.3
    Medium

    CVE-2009-1448

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 27 Apr 2009
    9.3
    Critical

    CVE-2009-1449

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSkin parameter. NOTE: this may overlap CVE-2008-5735.

    Published: 27 Apr 2009
    4
    Medium

    CVE-2008-6754

    Last Modified: 23 Apr 2026

    The Personal Sticky Threads addon 1.0.3c for vBulletin allows remote authenticated users to read the title, author, and pages of an arbitrary thread by toggling a personal sticky.

    Published: 27 Apr 2009
    10
    Critical

    CVE-2009-1443

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.

    Published: 27 Apr 2009
    7.5
    High

    CVE-2009-1444

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.

    Published: 27 Apr 2009
    6.5
    Medium

    CVE-2009-1446

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2009
    7.5
    High

    CVE-2009-1445

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local files via directory traversal sequences in the error parameter to index.php.

    Published: 27 Apr 2009
    6.8
    Medium

    CVE-2009-1447

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

    Published: 27 Apr 2009
    7.5
    High

    CVE-2008-6753

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SilverStripe before 2.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to AjaxUniqueTextField.

    Published: 27 Apr 2009
    2.1
    Low

    CVE-2009-1435

    Last Modified: 23 Apr 2026

    NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2009
    4.9
    Medium

    CVE-2009-1436

    Last Modified: 23 Apr 2026

    The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.

    Published: 27 Apr 2009
    6.8
    Medium

    CVE-2009-1440

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename.

    Published: 27 Apr 2009
    9.3
    Critical

    CVE-2009-1437

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.

    Published: 27 Apr 2009
    9.3
    Critical

    CVE-2009-1313

    Last Modified: 23 Apr 2026

    The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.

    Published: 27 Apr 2009
    4.4
    Medium

    CVE-2010-0427

    Last Modified: 11 Apr 2025

    sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.

    Published: 27 Apr 2009
    6.8
    Medium

    CVE-2009-1493

    Last Modified: 23 Apr 2026

    The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and UNIX allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that triggers a call to this method with a long string in the second argument.

    Published: 27 Apr 2009