CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-1364

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WMF file.

    Published: 27 Apr 2009
    9.3
    Critical

    CVE-2009-1492

    Last Modified: 23 Apr 2026

    The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a PDF file that contains an annotation, and has an OpenAction entry with JavaScript code that calls this method with crafted integer arguments.

    Published: 27 Apr 2009
    6.8
    Medium

    CVE-2009-1515

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the cdf_read_sat function in src/cdf.c in Christos Zoulas file 5.00 allows user-assisted remote attackers to execute arbitrary code via a crafted compound document file, as demonstrated by a .msi, .doc, or .mpp file. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2009
    7.5
    High

    CVE-2009-1433

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to execute arbitrary SQL commands via the filename parameter.

    Published: 24 Apr 2009
    4.3
    Medium

    CVE-2009-1414

    Last Modified: 23 Apr 2026

    Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for attackers to conduct Universal XSS attacks via unspecified vectors.

    Published: 24 Apr 2009
    4.3
    Medium

    CVE-2009-1413

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Universal XSS attacks by calling setTimeout to trigger future execution of JavaScript code, and then modifying document.location to arrange for JavaScript execution in the context of an arbitrary web site. NOTE: this can be leveraged for a remote attack by exploiting a chromehtml: argument-injection vulnerability.

    Published: 24 Apr 2009
    4.3
    Medium

    CVE-2009-0063

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 24 Apr 2009
    9
    Critical

    CVE-2009-0064

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow remote authenticated users to gain privileges, and possibly obtain sensitive information or hijack sessions of arbitrary users, via vectors involving (1) administrative scripts or (2) console functions.

    Published: 24 Apr 2009
    7.8
    High

    CVE-2009-1412

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by Internet Explorer, allows remote attackers to determine the existence of files, and open tabs for URLs that do not satisfy the IsWebSafeScheme restriction, via a web page that sets document.location to a chromehtml: value, as demonstrated by use of a (1) javascript: or (2) data: URL. NOTE: this can be leveraged for Universal XSS by exploiting certain behavior involving persistence across page transitions.

    Published: 24 Apr 2009
    9.3
    Critical

    CVE-2008-6748

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2008-6751

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in settings/my_photo.

    Published: 24 Apr 2009
    7.5
    High

    CVE-2008-6752

    Last Modified: 23 Apr 2026

    adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original password before changing passwords, which allows remote attackers to change the administrator's password and gain privileges via a direct request with modified newpass1 and newpass2 parameters in a Change operation.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2009-1405

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2009-1406

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include parameter.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2009-1407

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.

    Published: 24 Apr 2009
    5.1
    Medium

    CVE-2009-1409

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.

    Published: 24 Apr 2009
    7.5
    High

    CVE-2009-1403

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.

    Published: 24 Apr 2009
    7.5
    High

    CVE-2009-1411

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2008-6749

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2008-6750

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in add.php in FlexPHPDirectory 0.0.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in photo/.

    Published: 24 Apr 2009
    6.8
    Medium

    CVE-2009-1404

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.

    Published: 24 Apr 2009
    4.3
    Medium

    CVE-2009-1408

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.

    Published: 24 Apr 2009
    7.5
    High

    CVE-2009-1410

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Apr 2009
    6.4
    Medium

    CVE-2009-1956

    Last Modified: 23 Apr 2026

    Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input.

    Published: 24 Apr 2009
    10
    Critical

    CVE-2009-0165

    Last Modified: 23 Apr 2026

    Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, as used in Poppler and other products, when running on Mac OS X, has unspecified impact, related to "g*allocn."

    Published: 23 Apr 2009
    6.8
    Medium

    CVE-2008-6744

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Cybozu Office 6, Cybozu Dezie before 6.0(1.0), and Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 23 Apr 2009
    6.8
    Medium

    CVE-2008-6747

    Last Modified: 23 Apr 2026

    dotProject before 2.1.2 does not properly restrict access to administrative pages, which allows remote attackers to gain privileges. NOTE: some of these details are obtained from third party information.

    Published: 23 Apr 2009
    6.8
    Medium

    CVE-2009-1357

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.

    Published: 23 Apr 2009
    7.5
    High

    CVE-2008-6745

    Last Modified: 23 Apr 2026

    index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a register2 action.

    Published: 23 Apr 2009
    4.3
    Medium

    CVE-2009-0664

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0.x before 1.0.11 and 1.1.x before 1.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the introduction field in a user profile or (2) an arbitrary text block in a user view.

    Published: 23 Apr 2009
    5
    Medium

    CVE-2009-1371

    Last Modified: 23 Apr 2026

    The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding.

    Published: 23 Apr 2009
    10
    Critical

    CVE-2009-1372

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted URL.

    Published: 23 Apr 2009
    4.3
    Medium

    CVE-2009-1366

    Last Modified: 24 Apr 2026

    Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."

    Published: 22 Apr 2009
    7.5
    High

    CVE-2008-6743

    Last Modified: 23 Apr 2026

    RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.

    Published: 22 Apr 2009
    4.3
    Medium

    CVE-2009-1367

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue than CVE-2008-6127.2a.

    Published: 22 Apr 2009
    7.5
    High

    CVE-2009-1368

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the same issue as CVE-2008-6126.2, which may have been fixed in 1.10.3.

    Published: 22 Apr 2009
    5
    Medium

    CVE-2009-1369

    Last Modified: 23 Apr 2026

    moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message.

    Published: 22 Apr 2009
    9.3
    Critical

    CVE-2009-1370

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .cue file.

    Published: 22 Apr 2009
    6.8
    Medium

    CVE-2009-1362

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Apr 2009
    10
    Critical

    CVE-2009-1361

    Last Modified: 23 Apr 2026

    dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Apr 2009
    4.3
    Medium

    CVE-2009-0307

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.

    Published: 22 Apr 2009
    7.1
    High

    CVE-2009-1360

    Last Modified: 23 Apr 2026

    The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Namespace Support (aka NET_NS) is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) via vectors involving IPv6 packets.

    Published: 22 Apr 2009
    4.9
    Medium

    CVE-2009-1359

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SCTP sockets implementation in Sun OpenSolaris snv_106 through snv_107 allows local users to cause a denial of service (panic) via unknown vectors.

    Published: 22 Apr 2009
    4.9
    Medium

    CVE-2009-1195

    Last Modified: 23 Apr 2026

    The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec element in a .shtml file.

    Published: 22 Apr 2009
    5
    Medium

    CVE-2009-1574

    Last Modified: 23 Apr 2026

    racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafted fragmented packets without a payload, which triggers a NULL pointer dereference.

    Published: 22 Apr 2009
    4
    Medium

    CVE-2012-3417

    Last Modified: 11 Apr 2025

    The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.

    Published: 22 Apr 2009
    5
    Medium

    CVE-2009-1632

    Last Modified: 23 Apr 2026

    Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) signature verification during user authentication with X.509 certificates, related to the eay_check_x509sign function in src/racoon/crypto_openssl.c; and (2) the NAT-Traversal (aka NAT-T) keepalive implementation, related to src/racoon/nattraversal.c.

    Published: 22 Apr 2009
    5
    Medium

    CVE-2009-1190

    Last Modified: 23 Apr 2026

    Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containing multiple optional groups, a related issue to CVE-2004-2540.

    Published: 22 Apr 2009
    10
    Critical

    CVE-2009-1358

    Last Modified: 23 Apr 2026

    apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository as valid even when it has been signed with a key that has been revoked or expired, which might allow remote attackers to trick apt into installing malicious repositories.

    Published: 21 Apr 2009
    4.3
    Medium

    CVE-2008-6742

    Last Modified: 23 Apr 2026

    Foxy P2P software allows remote attackers to cause a denial of service (memory consumption) via a foxy URI with a download action and a large fs value.

    Published: 21 Apr 2009