CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2009-0908

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ACE shared folders implementation in the VMware Host Guest File System (HGFS) shared folders feature in VMware ACE 2.5.1 and earlier allows attackers to enable a disabled shared folder.

    Published: 6 Apr 2009
    6.8
    Medium

    CVE-2009-0910

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-436.

    Published: 6 Apr 2009
    4.9
    Medium

    CVE-2009-1146

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in an ioctl in hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 allows local users to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3761.

    Published: 6 Apr 2009
    5.5
    Medium

    CVE-2009-1243

    Last Modified: 23 Apr 2026

    net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which allows local users to cause a denial of service (panic) by reading zero bytes from the /proc/net/udp file and unspecified other files, related to the "udp seq_file infrastructure."

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6608

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DevelopItEasy Events Calendar 1.2 allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter (aka user field) to admin/index.php, (2) the user_pass parameter (aka pass field) to admin/index.php, or (3) the id parameter to calendar_details.php. NOTE: some of these details are obtained from third party information.

    Published: 6 Apr 2009
    7.5
    High

    CVE-2008-6606

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Apr 2009
    6.8
    Medium

    CVE-2008-6605

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 1701HG, 1800HW, 2071HG, and 2700HG with firmware 3.17.5, 3.7.1, 4.25.19, or 5.29.51 allows remote attackers to hijack the intranet connectivity of arbitrary users for requests that cause a denial of service (network outage) via a page parameter with a % (percent) character followed by a non-alphanumeric character.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2008-6607

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view.php in MatPo Link 1.2 Beta allows remote attackers to inject arbitrary web script or HTML via the thema parameter.

    Published: 6 Apr 2009
    4.7
    Medium

    CVE-2009-1961

    Last Modified: 23 Apr 2026

    The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.

    Published: 6 Apr 2009
    4.3
    Medium

    CVE-2008-2025

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apache Struts before 1.2.9-162.31.1 on SUSE Linux Enterprise (SLE) 11, before 1.2.9-108.2 on SUSE openSUSE 10.3, before 1.2.9-198.2 on SUSE openSUSE 11.0, and before 1.2.9-162.163.2 on SUSE openSUSE 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "insufficient quoting of parameters."

    Published: 6 Apr 2009
    10
    Critical

    CVE-2008-6604

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pagina parameter, a different vulnerability than CVE-2007-5390.

    Published: 4 Apr 2009
    5
    Medium

    CVE-2008-6599

    Last Modified: 23 Apr 2026

    cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path."

    Published: 3 Apr 2009
    4.3
    Medium

    CVE-2008-6597

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Apr 2009
    5
    Medium

    CVE-2008-6590

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to (1) index.php and (2) LightNEasy.php.

    Published: 3 Apr 2009
    9.3
    Critical

    CVE-2008-6583

    Last Modified: 23 Apr 2026

    Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .SRT file.

    Published: 3 Apr 2009
    6.8
    Medium

    CVE-2008-6585

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via the addUser action.

    Published: 3 Apr 2009
    6.8
    Medium

    CVE-2008-6587

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, allows remote attackers to hijack the authentication of users for requests that force the download of arbitrary torrent files via the upurl parameter.

    Published: 3 Apr 2009
    5
    Medium

    CVE-2008-6591

    Last Modified: 23 Apr 2026

    LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allows remote attackers to create arbitrary files via the page parameter to (1) index.php and (2) LightNEasy.php.

    Published: 3 Apr 2009
    7.5
    High

    CVE-2008-6592

    Last Modified: 23 Apr 2026

    thumbsup.php in Thumbs-Up 1.12, as used in LightNEasy "no database" (aka flat) and SQLite 1.2.2 and earlier, allows remote attackers to copy, rename, and read arbitrary files via directory traversal sequences in the image parameter with a modified cache_dir parameter containing a %00 (encoded null byte).

    Published: 3 Apr 2009
    7.5
    High

    CVE-2008-6593

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid parameter to index.php.

    Published: 3 Apr 2009
    7.5
    High

    CVE-2008-6594

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Apr 2009
    7.5
    High

    CVE-2008-6595

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the pmk_rssnewsexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Apr 2009
    4.3
    Medium

    CVE-2008-6600

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search feature in XMLPortal 3.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 3 Apr 2009
    5
    Medium

    CVE-2008-6601

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Epona 1.5rc3 allows remote attackers to obtain the real IP address of users via unknown vectors.

    Published: 3 Apr 2009
    10
    Critical

    CVE-2008-6602

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Download Center Lite before 2.1 has unknown impact and attack vectors related to "A minor security fix."

    Published: 3 Apr 2009
    10
    Critical

    CVE-2008-6598

    Last Modified: 23 Apr 2026

    Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."

    Published: 3 Apr 2009
    5
    Medium

    CVE-2009-1239

    Last Modified: 23 Apr 2026

    IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an INNER JOIN predicate and an OUTER JOIN predicate, which might allow attackers to obtain sensitive information via a crafted query.

    Published: 3 Apr 2009
    7.5
    High

    CVE-2009-1241

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RAR archive.

    Published: 3 Apr 2009
    8.8
    High

    CVE-2009-0556

    Last Modified: 22 Apr 2026

    Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that triggers memory corruption, as exploited in the wild in April 2009 by Exploit:Win32/Apptom.gen, aka "Memory Corruption Vulnerability."

    Published: 3 Apr 2009
    6.8
    Medium

    CVE-2008-6586

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests that force the download of arbitrary torrent files via the add-url action and (2) hijack the authentication of administrators for requests that modify the administrator account via the setsetting action.

    Published: 3 Apr 2009
    10
    Critical

    CVE-2008-6588

    Last Modified: 23 Apr 2026

    Aztech ADSL2/2+ 4-port router has a default "isp" account with a default "isp" password, which allows remote attackers to obtain access if this default is not changed.

    Published: 3 Apr 2009
    7.5
    High

    CVE-2008-6596

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL commands via the hash parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Apr 2009
    10
    Critical

    CVE-2009-1240

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Security System, Network Mail Security System Virtual Appliance, Desktop Endpoint Security, Network Multi-Function Security (MFS), and possibly other products, allows remote attackers to bypass detection of malware via a modified RAR archive.

    Published: 3 Apr 2009
    6
    Medium

    CVE-2008-6584

    Last Modified: 23 Apr 2026

    html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file containing an executable extension in the url_upload parameter, which is downloaded by TorrentFlux and can be accessed via a direct request in a html/downloads/ user directory.

    Published: 3 Apr 2009
    4.3
    Medium

    CVE-2008-6589

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in LightNEasy "no database" (aka flat) version 1.2.2, and possibly SQLite version 1.2.2, allow remote attackers to inject arbitrary web script or HTML via the page parameter to (1) index.php and (2) LightNEasy.php.

    Published: 3 Apr 2009
    4.3
    Medium

    CVE-2009-1234

    Last Modified: 23 Apr 2026

    Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.

    Published: 2 Apr 2009
    4.3
    Medium

    CVE-2009-1232

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and earlier are also affected.

    Published: 2 Apr 2009
    4.3
    Medium

    CVE-2009-1233

    Last Modified: 23 Apr 2026

    Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.

    Published: 2 Apr 2009
    7.2
    High

    CVE-2009-1235

    Last Modified: 23 Apr 2026

    XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.

    Published: 2 Apr 2009
    10
    Critical

    CVE-2009-1236

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.

    Published: 2 Apr 2009
    4.9
    Medium

    CVE-2009-1237

    Last Modified: 23 Apr 2026

    Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.

    Published: 2 Apr 2009
    7.2
    High

    CVE-2009-1238

    Last Modified: 23 Apr 2026

    Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.

    Published: 2 Apr 2009
    10
    Critical

    CVE-2009-1231

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.

    Published: 2 Apr 2009
    10
    Critical

    CVE-2009-1227

    Last Modified: 23 Apr 2026

    NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) Authorization or (2) Referer HTTP header to TCP port 18624. NOTE: the vendor has disputed this issue, stating "Check Point Security Alert Team has analyzed this report. We've tried to reproduce the attack on all VPN-1 versions from NG FP2 and above with and without HFAs. The issue was not reproduced. We have conducted a thorough analysis of the relevant code and verified that we are secure against this attack. We consider this attack to pose no risk to Check Point customers." In addition, the original researcher, whose reliability is unknown as of 20090407, also states that the issue "was discovered during a pen-test where the client would not allow further analysis.

    Published: 2 Apr 2009
    7.5
    High

    CVE-2009-1226

    Last Modified: 23 Apr 2026

    core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.

    Published: 2 Apr 2009
    4.3
    Medium

    CVE-2009-1225

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.

    Published: 2 Apr 2009
    7.5
    High

    CVE-2008-6582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action.

    Published: 2 Apr 2009
    7.5
    High

    CVE-2008-6581

    Last Modified: 23 Apr 2026

    login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter.

    Published: 2 Apr 2009
    5
    Medium

    CVE-2008-6580

    Last Modified: 23 Apr 2026

    The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb.

    Published: 2 Apr 2009
    7.5
    High

    CVE-2009-1224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.

    Published: 2 Apr 2009