CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2009-1222

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the WE_LANGUAGE parameter.

    Published: 2 Apr 2009
    5
    Medium

    CVE-2009-1223

    Last Modified: 23 Apr 2026

    aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for calendar/calendar.mdb.

    Published: 2 Apr 2009
    4.3
    Medium

    CVE-2009-1228

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter).

    Published: 2 Apr 2009
    7.5
    High

    CVE-2009-1229

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter.

    Published: 2 Apr 2009
    6.5
    Medium

    CVE-2009-1230

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.

    Published: 2 Apr 2009
    5
    Medium

    CVE-2003-1571

    Last Modified: 23 Apr 2026

    Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for database/WWGguestbook.mdb. NOTE: it was later reported that 8.21 is also affected.

    Published: 2 Apr 2009
    4.3
    Medium

    CVE-2009-0793

    Last Modified: 23 Apr 2026

    cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."

    Published: 2 Apr 2009
    6.8
    Medium

    CVE-2008-6575

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated users to cause a denial of service (resource consumption) via unknown vectors.

    Published: 1 Apr 2009
    7.8
    High

    CVE-2008-6576

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the "session limitation technique" in the FTP service on Nortel Communications Server 1000 (CS1K) 4.50.x, when running on VGMC or signaling nodes, allows remote attackers to cause a denial of service (resource exhaustion and failed updates) via unknown vectors that causes consumption of all available sessions.

    Published: 1 Apr 2009
    10
    Critical

    CVE-2008-6577

    Last Modified: 23 Apr 2026

    Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts and passwords, which allows remote attackers to gain privileges.

    Published: 1 Apr 2009
    5
    Medium

    CVE-2008-6579

    Last Modified: 23 Apr 2026

    Nortel Communication Server 1000 4.50.x allows remote attackers to obtain Web application structure via unknown vectors related to "web resources to phones and administrators."

    Published: 1 Apr 2009
    6.8
    Medium

    CVE-2008-6573

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Avaya SIP Enablement Services (SES) in Avaya Avaya Communication Manager 3.x, 4.0, and 5.0 (1) allow remote attackers to execute arbitrary SQL commands via unspecified vectors related to profiles in the SIP Personal Information Manager (SPIM) in the web interface; and allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to (2) permissions for SPIM profiles in the web interface and (3) a crafted SIP request to the SIP server.

    Published: 1 Apr 2009
    7.5
    High

    CVE-2008-6574

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges and cause a denial of service via unknown vectors related to reuse of valid credentials.

    Published: 1 Apr 2009
    10
    Critical

    CVE-2008-6578

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitrary commands to gain privileges, obtain sensitive information, or cause a denial of service via unknown vectors.

    Published: 1 Apr 2009
    5
    Medium

    CVE-2009-1219

    Last Modified: 23 Apr 2026

    Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.

    Published: 1 Apr 2009
    4.3
    Medium

    CVE-2009-1218

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml.

    Published: 1 Apr 2009
    9.3
    Critical

    CVE-2007-4475

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Level 9 allows remote attackers to execute arbitrary code via a long argument to the SaveViewToSessionFile method.

    Published: 1 Apr 2009
    4.3
    Medium

    CVE-2009-1220

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.

    Published: 1 Apr 2009
    4.3
    Medium

    CVE-2009-1217

    Last Modified: 23 Apr 2026

    Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."

    Published: 1 Apr 2009
    10
    Critical

    CVE-2009-1216

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2008, Windows Services for UNIX 3.0 and 3.5, and the Subsystem for UNIX-based Applications (SUA); as used in gunzip, gzip, pack, pcat, and unpack 7.x before 7.0.1701.48, 8.x before 8.0.1969.62, and 9.x before 9.0.3790.2076; allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 1 Apr 2009
    9.3
    Critical

    CVE-2008-3871

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via format string specifiers in the filename of a (1) DAA or (2) ISZ file.

    Published: 1 Apr 2009
    9.3
    Critical

    CVE-2008-4825

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) C2D, or (3) GI file.

    Published: 1 Apr 2009
    5.8
    Medium

    CVE-2009-1211

    Last Modified: 23 Apr 2026

    Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

    Published: 1 Apr 2009
    4.4
    Medium

    CVE-2009-1207

    Last Modified: 23 Apr 2026

    Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local users to overwrite arbitrary files, probably involving a symlink attack on temporary files.

    Published: 1 Apr 2009
    9.3
    Critical

    CVE-2009-1209

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.

    Published: 1 Apr 2009
    Unknown

    CVE-2009-1205

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4475. Reason: This candidate is a duplicate of CVE-2007-4475. Notes: All CVE users should reference CVE-2007-4475 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Apr 2009
    7.8
    High

    CVE-2009-1212

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods.

    Published: 1 Apr 2009
    7.2
    High

    CVE-2009-0686

    Last Modified: 23 Apr 2026

    The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to \Device\tmactmon that overwrites memory.

    Published: 1 Apr 2009
    7.5
    High

    CVE-2009-1208

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function instead of the mysql_real_escape_string function, which allows remote attackers to conduct SQL injection attacks using multibyte character encodings.

    Published: 1 Apr 2009
    7.5
    High

    CVE-2009-1206

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in futomi's CGI Cafe Access Analyzer CGI Professional Version 4.11.5 and earlier allows remote attackers to gain administrative privileges via unknown vectors.

    Published: 1 Apr 2009
    4.3
    Medium

    CVE-2009-1204

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php.

    Published: 1 Apr 2009
    4.4
    Medium

    CVE-2009-1962

    Last Modified: 23 Apr 2026

    Xfig, possibly 3.2.5, allows local users to read and write arbitrary files via a symlink attack on the (1) xfig-eps[PID], (2) xfig-pic[PID].pix, (3) xfig-pic[PID].err, (4) xfig-pcx[PID].pix, (5) xfig-xfigrc[PID], (6) xfig[PID], (7) xfig-print[PID], (8) xfig-export[PID].err, (9) xfig-batch[PID], (10) xfig-exp[PID], or (11) xfig-spell.[PID] temporary files, where [PID] is a process ID.

    Published: 1 Apr 2009
    2.6
    Low

    CVE-2009-0796

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 1 Apr 2009
    6.8
    Medium

    CVE-2008-6572

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Published: 31 Mar 2009
    7.8
    High

    CVE-2009-0843

    Last Modified: 23 Apr 2026

    The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to determine the existence of arbitrary files via a full pathname in the queryfile parameter, which triggers different error messages depending on whether this pathname exists.

    Published: 31 Mar 2009
    3.5
    Low

    CVE-2003-1570

    Last Modified: 23 Apr 2026

    The server in IBM Tivoli Storage Manager (TSM) 5.1.x, 5.2.x before 5.2.1.2, and 6.x before 6.1 does not require credentials to observe the server console in some circumstances, which allows remote authenticated administrators to monitor server operations by establishing a console mode session, related to "session exposure."

    Published: 31 Mar 2009
    5.5
    Medium

    CVE-2009-1073

    Last Modified: 23 Apr 2026

    nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for the LDAP server by reading the bindpw field.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-0839

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server has a map with a long IMAGEPATH or NAME attribute, allows remote attackers to execute arbitrary code via a crafted id parameter in a query action.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-0840

    Last Modified: 23 Apr 2026

    Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-0841

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when running on Windows with Cygwin, allows remote attackers to create arbitrary files via a .. (dot dot) in the id parameter.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2009-0842

    Last Modified: 23 Apr 2026

    mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files via a full pathname in the map parameter, which triggers the display of partial file contents within an error message, as demonstrated by a /tmp/sekrut.map symlink.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-1176

    Last Modified: 23 Apr 2026

    mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact via a long id parameter in a query action.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-1177

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 have unknown impact and remote attack vectors.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-1178

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has unknown impact and attack vectors related to the "admin command line."

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2004-2762

    Last Modified: 23 Apr 2026

    The server in IBM Tivoli Storage Manager (TSM) 4.2.x on MVS, 5.1.9.x before 5.1.9.1, 5.1.x before 5.1.10, 5.2.2.x before 5.2.2.3, 5.2.x before 5.2.3, 5.3.x before 5.3.0, and 6.x before 6.1, when the HTTP communication method is enabled, allows remote attackers to cause a denial of service (daemon crash or hang) via unspecified HTTP traffic, as demonstrated by the IBM port scanner 1.3.1.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2005-4879

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in jax_guestbook.php in Jax Guestbook 3.1 and 3.31 allow remote attackers to inject arbitrary web script or HTML via the (1) gmt_ofs and (2) language parameters. NOTE: the page parameter is already covered by CVE-2006-1913. NOTE: it was later reported that 3.50 is also affected.

    Published: 31 Mar 2009
    7.5
    High

    CVE-2006-7237

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mod/nc_phpmyadmin/core/libraries/Theme_Manager.class.php in Ixprim 2.0 allows remote attackers to execute arbitrary PHP code via a URL in an unspecified parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Mar 2009
    5
    Medium

    CVE-2007-6724

    Last Modified: 23 Apr 2026

    Vidalia bundle before 0.1.2.18, when running on Windows, installs Privoxy with a configuration file (config.txt or config) that contains an insecure enable-remote-http-toggle setting, which allows remote attackers to bypass intended access restrictions and modify configuration.

    Published: 31 Mar 2009
    1.9
    Low

    CVE-2008-6561

    Last Modified: 23 Apr 2026

    Citrix Presentation Server Client for Windows before 10.200 does not clear "credential information" from process memory in unspecified circumstances, which might allow local users to gain privileges.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2008-6562

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Mar 2009