CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6692

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Diocese of Portsmouth Training Courses (pd_trainingcourses) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6686

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CoolURI (cooluri) 1.0.11 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6694

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Random Prayer (ste_prayer) 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6695

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in TIMTAB social bookmark icons (timtab_sociable) 2.0.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6696

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Fussballtippspiel (toto) 0.1.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6697

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6701

    Last Modified: 23 Apr 2026

    NetScout (formerly Network General) Visualizer V2100 and InfiniStream i1730 do not restrict access to ResourceManager/en_US/domains/add_domain.jsp, which allows remote attackers to gain administrator privileges via a direct request.

    Published: 10 Apr 2009
    5
    Medium

    CVE-2008-6702

    Last Modified: 23 Apr 2026

    S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.

    Published: 10 Apr 2009
    10
    Critical

    CVE-2008-6703

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.

    Published: 10 Apr 2009
    5
    Medium

    CVE-2008-6704

    Last Modified: 23 Apr 2026

    Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory.

    Published: 10 Apr 2009
    5
    Medium

    CVE-2008-6705

    Last Modified: 23 Apr 2026

    The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction.

    Published: 10 Apr 2009
    9
    Critical

    CVE-2008-6710

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated administrators to gain root privileges via unknown vectors related to "configuring data viewing or restoring credentials."

    Published: 10 Apr 2009
    5
    Medium

    CVE-2008-6712

    Last Modified: 23 Apr 2026

    The HTTP/XML-RPC service in Crysis 1.21 (game version 1.1.1.6156) and earlier allows remote attackers to cause a denial of service (crash) via a long HTTP request, which triggers a NULL pointer dereference.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6685

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Frontend Filemanager (air_filemanager) 0.6.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6693

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Download system (sb_downloader) extension 0.1.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Published: 10 Apr 2009
    9
    Critical

    CVE-2008-6709

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allows remote authenticated users to execute arbitrary commands via unknown vectors related to configuration of "local data viewing or restoring parameters."

    Published: 10 Apr 2009
    5
    Medium

    CVE-2008-6713

    Last Modified: 23 Apr 2026

    World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference.

    Published: 10 Apr 2009
    4.3
    Medium

    CVE-2008-6698

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in TARGET-E WorldCup Bets (worldcup) 2.0.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 10 Apr 2009
    4.3
    Medium

    CVE-2008-6699

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Resource Library (tjs_reslib) 0.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 10 Apr 2009
    4.3
    Medium

    CVE-2008-6700

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) mytable parameter to view.php, (2) mytable parameter to viewdb2.php, (3) tablehere parameter to category-rename.php, and (4) letter parameter to module-contacts.php.

    Published: 10 Apr 2009
    7.8
    High

    CVE-2008-6706

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, allow remote attackers to obtain (1) application server configuration, (2) database server configuration including encrypted passwords, (3) a system utility that decrypts "subscriber table passwords," (4) a system utility that decrypts database passwords, and (5) a system utility that encrypts "subscriber table passwords."

    Published: 10 Apr 2009
    6.4
    Medium

    CVE-2008-6707

    Last Modified: 23 Apr 2026

    The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform authentication for certain functionality, which allows remote attackers to obtain sensitive information and access restricted functionality via (1) the certificate installation utility, (2) unspecified scripts in the objects folder, (3) an "unnecessary default application," (4) unspecified scripts in the states folder, (5) an unspecified "default application" that lists server configuration, and (6) "full system help."

    Published: 10 Apr 2009
    9
    Critical

    CVE-2008-6708

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x and 4.x, allows remote authenticated administrators to gain root privileges via unknown vectors related to configuration of "data viewing or restoring parameters."

    Published: 10 Apr 2009
    9
    Critical

    CVE-2008-6711

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 allows remote authenticated users to execute arbitrary commands via unknown vectors related to "viewing system logs."

    Published: 10 Apr 2009
    7.5
    High

    CVE-2008-6714

    Last Modified: 23 Apr 2026

    admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username cookie.

    Published: 10 Apr 2009
    6.8
    Medium

    CVE-2009-1280

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 9 Apr 2009
    7.5
    High

    CVE-2009-1278

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to index.php.

    Published: 9 Apr 2009
    6.8
    Medium

    CVE-2009-1283

    Last Modified: 23 Apr 2026

    glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.

    Published: 9 Apr 2009
    2.6
    Low

    CVE-2009-1279

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to the (1) com_admin component, (2) com_search component when "Gather Search Statistics" is enabled, and (3) the category view in the com_content component.

    Published: 9 Apr 2009
    4.3
    Medium

    CVE-2009-1281

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Apr 2009
    7.5
    High

    CVE-2009-1282

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.

    Published: 9 Apr 2009
    7.5
    High

    CVE-2009-1277

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action. NOTE: the board_id issue is already covered by CVE-2008-2996.2.

    Published: 9 Apr 2009
    6.8
    Medium

    CVE-2009-1275

    Last Modified: 23 Apr 2026

    Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressions twice in certain circumstances, which allows remote attackers to conduct cross-site scripting (XSS) attacks or obtain sensitive information via unspecified vectors, related to the (1) tiles:putAttribute and (2) tiles:insertTemplate JSP tags.

    Published: 9 Apr 2009
    7.8
    High

    CVE-2009-1159

    Last Modified: 23 Apr 2026

    Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2 before 7.2(4)26, 8.0 before 8.0(4)22, and 8.1 before 8.1(2)12, when SQL*Net inspection is enabled, allows remote attackers to cause a denial of service (traceback and device reload) via a series of SQL*Net packets.

    Published: 9 Apr 2009
    4.3
    Medium

    CVE-2008-6681

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dijit.Editor in Dojo before 1.1 allows remote attackers to inject arbitrary web script or HTML via XML entities in a TEXTAREA element.

    Published: 9 Apr 2009
    9.3
    Critical

    CVE-2009-0197

    Last Modified: 23 Apr 2026

    Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.

    Published: 9 Apr 2009
    7.8
    High

    CVE-2009-1158

    Last Modified: 23 Apr 2026

    Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)26, 8.0 before 8.0(4)24, and 8.1 before 8.1(2)14, when H.323 inspection is enabled, allows remote attackers to cause a denial of service (device reload) via a crafted H.323 packet.

    Published: 9 Apr 2009
    4.3
    Medium

    CVE-2009-1160

    Last Modified: 23 Apr 2026

    Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74, 7.2 before 7.2(4)9, and 8.0 before 8.0(4)5 do not properly implement the implicit deny statement, which might allow remote attackers to successfully send packets that bypass intended access restrictions, aka Bug ID CSCsq91277.

    Published: 9 Apr 2009
    2.1
    Low

    CVE-2009-1276

    Last Modified: 23 Apr 2026

    XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, as demonstrated by Thunderbird new-mail notifications.

    Published: 9 Apr 2009
    4.3
    Medium

    CVE-2007-6726

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Dojo 0.4.1 and 0.4.2, as used in Apache Struts and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) xip_client.html and (2) xip_server.html in src/io/.

    Published: 9 Apr 2009
    6.9
    Medium

    CVE-2009-1144

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library.

    Published: 9 Apr 2009
    7.8
    High

    CVE-2009-1157

    Last Modified: 23 Apr 2026

    Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 before 7.1(2)82, 7.2 before 7.2(4)30, 8.0 before 8.0(4)28, and 8.1 before 8.1(2)19 allows remote attackers to cause a denial of service (memory consumption or device reload) via a crafted TCP packet.

    Published: 9 Apr 2009
    4.3
    Medium

    CVE-2008-6682

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.x before 2.0.11.1 and 2.1.x before 2.1.1 allow remote attackers to inject arbitrary web script or HTML via vectors associated with improper handling of (1) " (double quote) characters in the href attribute of an s:a tag and (2) parameters in the action attribute of an s:url tag.

    Published: 9 Apr 2009
    7.8
    High

    CVE-2009-1155

    Last Modified: 23 Apr 2026

    Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, and 8.1 before 8.1(2)15, when AAA override-account-disable is entered in a general-attributes field, allow remote attackers to bypass authentication and establish a VPN session to an ASA device via unspecified vectors.

    Published: 9 Apr 2009
    5.7
    Medium

    CVE-2009-1156

    Last Modified: 23 Apr 2026

    Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 8.0 before 8.0(4)25 and 8.1 before 8.1(2)15, when an SSL VPN or ASDM access is configured, allows remote attackers to cause a denial of service (device reload) via a crafted (1) SSL or (2) HTTP packet.

    Published: 9 Apr 2009
    6.9
    Medium

    CVE-2009-1897

    Last Modified: 23 Apr 2026

    The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894.

    Published: 9 Apr 2009
    6.8
    Medium

    CVE-2009-1254

    Last Modified: 23 Apr 2026

    James Stone Tunapie 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a stream URL.

    Published: 9 Apr 2009
    7.8
    High

    CVE-2009-1250

    Last Modified: 23 Apr 2026

    The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, on Linux allows remote attackers to cause a denial of service (system crash) via an RX response with a large error-code value that is interpreted as a pointer and dereferenced, related to use of the ERR_PTR macro.

    Published: 9 Apr 2009
    6.8
    Medium

    CVE-2009-0159

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the cookedprint function in ntpq/ntpq.c in ntpq in NTP before 4.2.4p7-RC2 allows remote NTP servers to execute arbitrary code via a crafted response.

    Published: 9 Apr 2009
    10
    Critical

    CVE-2009-1251

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on Unix platforms allows remote attackers to cause a denial of service (system crash) or possibly execute arbitrary code via an RX response containing more data than specified in a request, related to use of XDR arrays.

    Published: 9 Apr 2009