CVE Feed

    Dashboard / CVE

    4.4
    Medium

    CVE-2009-1253

    Last Modified: 23 Apr 2026

    James Stone Tunapie 2.1 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary file.

    Published: 9 Apr 2009
    5
    Medium

    CVE-2009-1274

    Last Modified: 23 Apr 2026

    Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows remote attackers to execute arbitrary code via a Quicktime movie file with a large count value in an STTS atom, which triggers a heap-based buffer overflow.

    Published: 8 Apr 2009
    7.8
    High

    CVE-2009-1270

    Last Modified: 23 Apr 2026

    libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a crafted TAR file that causes (1) clamd and (2) clamscan to hang.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6680

    Last Modified: 23 Apr 2026

    libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6664

    Last Modified: 23 Apr 2026

    action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies to non-zero values.

    Published: 8 Apr 2009
    6.8
    Medium

    CVE-2008-6665

    Last Modified: 23 Apr 2026

    change.php in Ananta CMS 1.0b5, with magic_quotes_gpc disabled, allows remote attackers to gain administrator privileges via a crafted email parameter, possibly related to code injection.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6667

    Last Modified: 23 Apr 2026

    A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuser and mobspass cookies to 1.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6672

    Last Modified: 23 Apr 2026

    Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service ("runtime error") via a crafted join packet to UDP port 27960, probably related to an invalid nickname command.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6674

    Last Modified: 23 Apr 2026

    mailPage.asp in QuickerSite 1.8.5 allows remote attackers to flood e-mail accounts with messages via a large number of requests with a modified sEmail parameter.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6676

    Last Modified: 23 Apr 2026

    QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to showThumb.aspx without any parameters, which reveals the installation path in an error message.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6671

    Last Modified: 23 Apr 2026

    Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted join packet to UDP port 27960.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6669

    Last Modified: 23 Apr 2026

    viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6677

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in fckeditor251/editor/filemanager/connectors/asp/upload.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6663

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the auction_id parameter, a different vector than CVE-2009-0106.

    Published: 8 Apr 2009
    4.3
    Medium

    CVE-2008-6666

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kronos webTA allow remote attackers to inject arbitrary web script or HTML via the description field to (1) servlet/com.threeis.webta.H710selProject and (2) servlet/com.threeis.webta.H720editProjectInfo. NOTE: BID:29610 states that the initial report was incorrect, but the reason for this conclusion is unknown.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6668

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) id parameter to comm.php and (2) var_filename parameter to viewrq.php.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2008-6670

    Last Modified: 23 Apr 2026

    Integer overflow in Vertex4 SunAge 1.08.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted packet to UDP port 27960.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6673

    Last Modified: 23 Apr 2026

    asp/bs_login.asp in QuickerSite 1.8.5 does not properly restrict access to administrative functionality, which allows remote attackers to (1) change the admin password via the cSaveAdminPW action; (2) modify site information, such as the contact address, via the saveAdmin; and (3) modify the site design via the saveDesign action.

    Published: 8 Apr 2009
    4.3
    Medium

    CVE-2008-6675

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in QuickerSite 1.8.5 allow remote attackers to inject arbitrary web script or HTML via (1) the close parameter to showThumb.aspx; (2) SB_redirect and (3) SB_feedback parameters in process_send.asp, as reachable through default.asp; (4) paramCode and (5) cColor parameters to picker.asp; and the (6) query string, (7) Referer header, and (8) X-FORWARDED-FOR header to rss.asp.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2008-6678

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in asp/includes/contact.asp in QuickerSite 1.8.5 allows remote attackers to execute arbitrary SQL commands via the sNickName parameter in a profile action to default.asp.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2009-1265

    Last Modified: 23 Apr 2026

    Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1, might allow remote attackers to obtain sensitive information via a large length value, which causes "garbage" memory to be sent.

    Published: 8 Apr 2009
    Unknown

    CVE-2009-0795

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-0796, CVE-2009-1265. Reason: this candidate was intended for one issue, but a typo caused it to be associated with a different issue. Notes: All CVE users should consult CVE-2009-0796 and CVE-2009-1265 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Apr 2009
    9.3
    Critical

    CVE-2009-0196

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.

    Published: 8 Apr 2009
    9.3
    Critical

    CVE-2009-0792

    Last Modified: 23 Apr 2026

    Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.

    Published: 8 Apr 2009
    5
    Medium

    CVE-2009-1269

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Wireshark 0.99.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.

    Published: 8 Apr 2009
    4.3
    Medium

    CVE-2009-1268

    Last Modified: 23 Apr 2026

    The Check Point High-Availability Protocol (CPHAP) dissector in Wireshark 0.9.6 through 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FWHA_MY_STATE packet.

    Published: 8 Apr 2009
    7.5
    High

    CVE-2009-1258

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the RD-Autos (com_rdautos) component 1.5.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the makeid parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2009-1256

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6662

    Last Modified: 23 Apr 2026

    AVG Anti-Virus for Linux 7.5.51, and possibly earlier, allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via a malformed UPX compressed file, which triggers memory corruption.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2009-1263

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php.

    Published: 7 Apr 2009
    7.2
    High

    CVE-2009-1262

    Last Modified: 23 Apr 2026

    Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string specifiers in the VPN connection name.

    Published: 7 Apr 2009
    4
    Medium

    CVE-2009-1264

    Last Modified: 23 Apr 2026

    Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access rights, which allows remote authenticated users to obtain sensitive information such as passwords via unknown attack vectors.

    Published: 7 Apr 2009
    5
    Medium

    CVE-2008-6661

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the scanning engine in Bitdefender for Linux 7.60825 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed (1) NeoLite and (2) ASProtect packed PE file.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2009-1261

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Apr 2009
    9.3
    Critical

    CVE-2009-1260

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.

    Published: 7 Apr 2009
    6.8
    Medium

    CVE-2009-1259

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a topic action to index.php.

    Published: 7 Apr 2009
    9
    Critical

    CVE-2009-1257

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file.

    Published: 7 Apr 2009
    4
    Medium

    CVE-2008-6658

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated administrators to install packages from arbitrary directories via a .. (dot dot) in the package parameter during an install2 action, as demonstrated by a predictable package filename in attachments/ that was uploaded through a post2 action to index.php.

    Published: 7 Apr 2009
    6.8
    Medium

    CVE-2008-6660

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute arbitrary code by uploading a file with an executable extension followed by a .sql extension, then accessing this file via a direct request. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2009
    5.5
    Medium

    CVE-2008-6659

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote authenticated users to configure arbitrary local files for execution via directory traversal sequences in the value of the theme_dir field during a jsoption action, related to Sources/QueryString.php and Sources/Themes.php, as demonstrated by a local .gif file in attachments/ with PHP code that was uploaded through a profile2 action to index.php.

    Published: 7 Apr 2009
    6.8
    Medium

    CVE-2008-6657

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 allows remote attackers to hijack the authentication of admins for requests that install packages via the package parameter in an install2 action.

    Published: 7 Apr 2009
    4.3
    Medium

    CVE-2008-6655

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web script or HTML via the (1) nom_branche and (2) nom parameters to php/prenom.php; the (3) nom_branche parameter to php/index.php; and the (4) nom_branche, (5) nom, and (6) prenom parameters to php/info.php.

    Published: 7 Apr 2009
    7.8
    High

    CVE-2008-6630

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the wt_gallery extension 2.5.0 and earlier for TYPO3 allows remote attackers to read arbitrary image files and determine directory structure via unspecified vectors.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6632

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header ($_SERVER['HTTP_USER_AGENT']).

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6633

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idresa parameter to resaopen.php.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6634

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idroom parameter to weekview.php.

    Published: 7 Apr 2009
    6.8
    Medium

    CVE-2008-6635

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in skins/default.php in Geody Labs Dagger - The Cutting Edge r12feb2008, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir_inc parameter.

    Published: 7 Apr 2009
    6.8
    Medium

    CVE-2008-6639

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin.php in AjaXplorer 2.3.3 and 2.3.4 allows remote attackers to hijack the authentication of administrators for requests that modify passwords via the update_user_pwd action.

    Published: 7 Apr 2009
    7.5
    High

    CVE-2008-6642

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL commands via the sid parameter. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2009
    5
    Medium

    CVE-2008-6643

    Last Modified: 23 Apr 2026

    LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php.

    Published: 7 Apr 2009