CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-1759

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.

    Published: 20 Apr 2009
    4.9
    Medium

    CVE-2009-1192

    Last Modified: 23 Apr 2026

    The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsystem in the Linux kernel before 2.6.30-rc3 do not zero out pages that may later be available to a user-space process, which allows local users to obtain sensitive information by reading these pages.

    Published: 20 Apr 2009
    4.3
    Medium

    CVE-2009-1482

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or (2) multiple vectors related to package file errors in the upload_form function, different vectors than CVE-2009-0260.

    Published: 18 Apr 2009
    4.3
    Medium

    CVE-2009-0038

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.

    Published: 17 Apr 2009
    6.8
    Medium

    CVE-2009-0039

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.

    Published: 17 Apr 2009
    5
    Medium

    CVE-2009-1332

    Last Modified: 23 Apr 2026

    The Online Help feature in Sun Java System Directory Server 5.2 and Enterprise Edition 5 allows remote attackers to determine the existence of files and directories, and possibly obtain partial contents of files, via unspecified vectors.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2009-1333

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in refresh_rate.htm in the web interface on the HP Deskjet 6840 printer with firmware XF1M131A allows remote attackers to inject arbitrary web script or HTML via the POST request body.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2009-1334

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2009-1335

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1331

    Last Modified: 23 Apr 2026

    Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid.

    Published: 17 Apr 2009
    9.4
    Critical

    CVE-2008-5518

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows allow remote attackers to upload files to arbitrary directories via directory traversal sequences in the (1) group, (2) artifact, (3) version, or (4) fileType parameter to console/portal//Services/Repository (aka the Services/Repository portlet); the (5) createDB parameter to console/portal/Embedded DB/DB Manager (aka the Embedded DB/DB Manager portlet); or the (6) filename parameter to the createKeystore script in the Security/Keystores portlet.

    Published: 17 Apr 2009
    6
    Medium

    CVE-2008-6726

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CMScout 2.06, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the bit parameter to (1) admin.php and (2) index.php, different vectors than CVE-2008-3415.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2009-1315

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id parameters to adv_cat.php, and the (4) URL to blogs_full.php.

    Published: 17 Apr 2009
    7.5
    High

    CVE-2009-1316

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.

    Published: 17 Apr 2009
    6.8
    Medium

    CVE-2009-1317

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php.

    Published: 17 Apr 2009
    6.5
    Medium

    CVE-2009-1318

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.

    Published: 17 Apr 2009
    7.5
    High

    CVE-2009-1319

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.

    Published: 17 Apr 2009
    7.5
    High

    CVE-2009-1323

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1324

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1325

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1326

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1327

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1328

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Published: 17 Apr 2009
    5
    Medium

    CVE-2009-1322

    Last Modified: 23 Apr 2026

    ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2009-1321

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1330

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2008-6724

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.pl in Perl Nopaste 1.0 allows remote attackers to inject arbitrary web script or HTML via the language parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Apr 2009
    6
    Medium

    CVE-2008-6725

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.

    Published: 17 Apr 2009
    4.3
    Medium

    CVE-2009-1320

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in include/zstore.php in Zazzle Store Builder 1.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) gridPage and (2) gridSort parameters. NOTE: some of these details are obtained from third party information.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2009-1329

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2008-1107

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.48, and possibly earlier versions, allow remote attackers to execute arbitrary code via long arguments to unspecified methods, which are not properly handled by a logging function.

    Published: 17 Apr 2009
    10
    Critical

    CVE-2009-1314

    Last Modified: 23 Apr 2026

    body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.

    Published: 17 Apr 2009
    9.3
    Critical

    CVE-2008-5259

    Last Modified: 23 Apr 2026

    Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow.

    Published: 16 Apr 2009
    7.5
    High

    CVE-2009-1285

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x before 3.1.3.2 allows remote attackers to inject arbitrary PHP code into configuration files.

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-1294

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

    Published: 16 Apr 2009
    10
    Critical

    CVE-2009-1301

    Last Modified: 23 Apr 2026

    Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value. NOTE: some of these details are obtained from third party information.

    Published: 16 Apr 2009
    9.3
    Critical

    CVE-2008-4830

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 Patch 5 (KWEDIT.DLL 7100.1.1.43) allows remote attackers to (1) overwrite arbitrary files via the SaveDocumentAs method or (2) read or execute arbitrary files via the OpenDocument method.

    Published: 16 Apr 2009
    9.3
    Critical

    CVE-2007-2238

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.

    Published: 16 Apr 2009
    5
    Medium

    CVE-2009-1293

    Last Modified: 23 Apr 2026

    The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.

    Published: 16 Apr 2009
    10
    Critical

    CVE-2009-1300

    Last Modified: 23 Apr 2026

    apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.

    Published: 16 Apr 2009
    6.4
    Medium

    CVE-2009-0164

    Last Modified: 23 Apr 2026

    The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easier for remote attackers to conduct DNS rebinding attacks.

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-0166

    Last Modified: 23 Apr 2026

    The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a free of uninitialized memory.

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-0799

    Last Modified: 23 Apr 2026

    The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers an out-of-bounds read.

    Published: 16 Apr 2009
    6.8
    Medium

    CVE-2009-0800

    Last Modified: 23 Apr 2026

    Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allow remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 16 Apr 2009
    6.8
    Medium

    CVE-2009-1179

    Last Modified: 23 Apr 2026

    Integer overflow in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file.

    Published: 16 Apr 2009
    6.8
    Medium

    CVE-2009-1180

    Last Modified: 23 Apr 2026

    The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a free of invalid data.

    Published: 16 Apr 2009
    6.8
    Medium

    CVE-2009-0163

    Last Modified: 23 Apr 2026

    Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted TIFF image, which is not properly handled by the (1) _cupsImageReadTIFF function in the imagetops filter and (2) imagetoraster filter, leading to a heap-based buffer overflow.

    Published: 16 Apr 2009
    5
    Medium

    CVE-2009-1188

    Last Modified: 23 Apr 2026

    Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.10.6, as used in GPdf and kdegraphics KPDF, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

    Published: 16 Apr 2009
    4.3
    Medium

    CVE-2009-1181

    Last Modified: 23 Apr 2026

    The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products allows remote attackers to cause a denial of service (crash) via a crafted PDF file that triggers a NULL pointer dereference.

    Published: 16 Apr 2009
    5
    Medium

    CVE-2009-1187

    Last Modified: 23 Apr 2026

    Integer overflow in the JBIG2 decoding feature in Poppler before 0.10.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to CairoOutputDev (CairoOutputDev.cc).

    Published: 16 Apr 2009