CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-6566

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Octopussy before 0.9.5.8 has unknown impact and attack vectors related to a "major security" vulnerability.

    Published: 31 Mar 2009
    6.8
    Medium

    CVE-2008-6568

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Yehe 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the envoyer feature. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2008-6570

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the RSS reader in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2008-6571

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php, and unspecified vectors.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2008-6565

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.

    Published: 31 Mar 2009
    5
    Medium

    CVE-2007-6722

    Last Modified: 23 Apr 2026

    Vidalia bundle before 0.1.2.18, when running on Windows and Mac OS X, installs Privoxy with a configuration file (config.txt or config) that contains insecure (1) enable-remote-toggle and (2) enable-edit-actions settings, which allows remote attackers to bypass intended access restrictions and modify configuration.

    Published: 31 Mar 2009
    5
    Medium

    CVE-2005-4880

    Last Modified: 23 Apr 2026

    Jax Guestbook 3.1 and 3.31 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain IP addresses of users via a direct request to (1) guestbook, (2) guestbook_ips2block, (3) ips2block, and (4) formmailer/logfile.csv.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2007-6723

    Last Modified: 23 Apr 2026

    TorK before 0.22, when running on Windows and Mac OS X, installs Privoxy with a configuration file (config.txt or config) that contains insecure (1) enable-remote-toggle and (2) enable-edit-actions settings, which allows remote attackers to bypass intended access restrictions and modify configuration.

    Published: 31 Mar 2009
    9.3
    Critical

    CVE-2008-6563

    Last Modified: 23 Apr 2026

    Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DTD file.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2008-6567

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Gallarific Free Edition allow remote attackers to inject arbitrary web script or HTML via (1) the e-mail address, (2) a comment, which is not properly handled during moderation, and (3) the tag parameter to gallery/tags.php.

    Published: 31 Mar 2009
    6.8
    Medium

    CVE-2008-6569

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login page.

    Published: 31 Mar 2009
    7.6
    High

    CVE-2008-6564

    Last Modified: 23 Apr 2026

    Nortel UNIStim protocol, as used in Communication Server 1000 and other products, uses predictable sequence numbers, which allows remote attackers to hijack sessions via sniffing or brute force attacks.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-1174

    Last Modified: 23 Apr 2026

    The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2009-1175

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the server parameter, which is not properly handled in an error message.

    Published: 31 Mar 2009
    7.8
    High

    CVE-2008-6560

    Last Modified: 23 Apr 2026

    Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.

    Published: 31 Mar 2009
    5.5
    Medium

    CVE-2009-0892

    Last Modified: 23 Apr 2026

    The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessions in "specific scenarios" related to a forced logout.

    Published: 31 Mar 2009
    10
    Critical

    CVE-2009-1172

    Last Modified: 23 Apr 2026

    The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknown impact and attack vectors.

    Published: 31 Mar 2009
    2.1
    Low

    CVE-2009-1173

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecified "interim fixes," which allows attackers to modify files that would not have been accessible if the intended 755 permissions were used.

    Published: 31 Mar 2009
    4.3
    Medium

    CVE-2009-1171

    Last Modified: 23 Apr 2026

    The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2008-6554

    Last Modified: 23 Apr 2026

    cgi-bin/script in Aztech ADSL2/2+ 4-port router 3.7.0 build 070426 allows remote attackers to execute arbitrary commands via shell metacharacters in the query string.

    Published: 30 Mar 2009
    7.2
    High

    CVE-2008-6558

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges by modifying the RELIANT_PATH environment variable to point to a malicious bin/hvenv program.

    Published: 30 Mar 2009
    7.2
    High

    CVE-2008-6559

    Last Modified: 23 Apr 2026

    Merge mcd in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local users to gain root privileges via a crafted -d argument that contains .. (dot dot) sequences that point to a directory containing a file whose name includes shell metacharacters.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2008-6555

    Last Modified: 23 Apr 2026

    cgi-bin/webutil.pl in The Puppet Master WebUtil allows remote attackers to execute arbitrary commands via shell metacharacters in the dig command.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2008-6556

    Last Modified: 23 Apr 2026

    cgi-bin/webutil.pl in The Puppet Master WebUtil 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the whois command.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2008-6557

    Last Modified: 23 Apr 2026

    cgi-bin/webutil.pl in The Puppet Master WebUtil 2.7 allows remote attackers to execute arbitrary commands via shell metacharacters in the details command.

    Published: 30 Mar 2009
    6.9
    Medium

    CVE-2009-1170

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global zone, to execute arbitrary code in the global zone when a global-zone user is using mdb on a non-global zone process.

    Published: 30 Mar 2009
    5.1
    Medium

    CVE-2008-6551

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in e-Vision CMS 2.0.2 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) an adminlang cookie to admin/ind_ex.php; or the module parameter to (2) 3rdparty/adminpart/add3rdparty.php, (3) polling/adminpart/addpolling.php, (4) contact/adminpart/addcontact.php, (5) brandnews/adminpart/addbrandnews.php, (6) newsletter/adminpart/addnewsletter.php, (7) game/adminpart/addgame.php, (8) tour/adminpart/addtour.php, (9) articles/adminpart/addarticles.php, (10) product/adminpart/addproduct.php, or (11) plain/adminpart/addplain.php in modules/.

    Published: 30 Mar 2009
    7.5
    High

    CVE-2008-6553

    Last Modified: 23 Apr 2026

    microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows remote attackers to (1) create administrative accounts via an add_admin action, (2) remove administrative accounts via a delete_admin action, and (3) modify administrative passwords via a change_password action.

    Published: 30 Mar 2009
    4.3
    Medium

    CVE-2008-6550

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in glossaire.php in Glossaire 2.0 allows remote attackers to inject arbitrary web script or HTML via the letter parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Mar 2009
    5
    Medium

    CVE-2008-6548

    Last Modified: 23 Apr 2026

    The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

    Published: 30 Mar 2009
    7.5
    High

    CVE-2008-6547

    Last Modified: 23 Apr 2026

    schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2008-6536

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).

    Published: 30 Mar 2009
    6.5
    Medium

    CVE-2008-6539

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

    Published: 30 Mar 2009
    7.5
    High

    CVE-2008-6544

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) settings[default_theme_dir] parameter to Sources/Subs-Graphics.php and (2) settings[default_theme_dir] parameter to Sources/Themes.php. NOTE: CVE and multiple third parties dispute this issue because the files contain a protection mechanism against direct request

    Published: 30 Mar 2009
    7.5
    High

    CVE-2008-6545

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2008-6546

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in phpns before 2.1.3 has unknown impact and attack vectors related to "activation permissions."

    Published: 30 Mar 2009
    5.1
    Medium

    CVE-2008-6540

    Last Modified: 24 Apr 2026

    DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.

    Published: 30 Mar 2009
    6.8
    Medium

    CVE-2008-6541

    Last Modified: 24 Apr 2026

    Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.

    Published: 30 Mar 2009
    4.6
    Medium

    CVE-2008-6542

    Last Modified: 24 Apr 2026

    Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.

    Published: 30 Mar 2009
    5
    Medium

    CVE-2008-6537

    Last Modified: 23 Apr 2026

    LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the administrator password via the setup "do" action to LightNEasy.php, which is cleared from $_GET but later accessed using $_REQUEST.

    Published: 30 Mar 2009
    5
    Medium

    CVE-2008-6538

    Last Modified: 23 Apr 2026

    DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

    Published: 30 Mar 2009
    5
    Medium

    CVE-2008-6549

    Last Modified: 23 Apr 2026

    The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.

    Published: 30 Mar 2009
    7.5
    High

    CVE-2008-6543

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parameter to (1) index.php3, (2) locate.php3, (3) search_results.php3, (4) classifieds/index.php3, and (5) classifieds/view.php3; (6) index.php3, (7) manager.php3, (8) pass.php3, (9) remember.php3 (10) sign-up.php3, (11) update.php3, (12) userSet.php3, and (13) verify.php3 in controlcenter/; (14) alterCats.php3, (15) alterFeatured.php3, (16) alterHomepage.php3, (17) alterNews.php3, (18) alterTheme.php3, (19) color_help.php3, (20) createdb.php3, (21) createFeatured.php3, (22) createHomepage.php3, (23) createL.php3, (24) createM.php3, (25) createNews.php3, (26) createP.php3, (27) createS.php3, (28) createT.php3, (29) index.php3, (30) mailadmin.php3, and (31) setUp.php3 in controlpannel/; (32) include/sendit.php3 and (33) include/sendit2.php3; and possibly (34) include/adminHead.inc, (35) include/usersHead.inc, and (36) style/default.scheme.inc.

    Published: 30 Mar 2009
    5
    Medium

    CVE-2009-0790

    Last Modified: 23 Apr 2026

    The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before 4.2.14 and 2.8 before 2.8.9, allows remote attackers to cause a denial of service (daemon crash and restart) via a crafted (1) R_U_THERE or (2) R_U_THERE_ACK Dead Peer Detection (DPD) IPsec IKE Notification message that triggers a NULL pointer dereference related to inconsistent ISAKMP state and the lack of a phase2 state association in DPD.

    Published: 30 Mar 2009
    10
    Critical

    CVE-2009-1210

    Last Modified: 23 Apr 2026

    Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.

    Published: 30 Mar 2009
    6.8
    Medium

    CVE-2009-1213

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote attackers to hijack the authentication of arbitrary users for requests that use attachment editing.

    Published: 30 Mar 2009
    Unknown

    CVE-2008-4312

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 29 Mar 2009
    7.8
    High

    CVE-2009-0626

    Last Modified: 23 Apr 2026

    The SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (device reload or hang) via a crafted HTTPS packet.

    Published: 27 Mar 2009
    9
    Critical

    CVE-2009-0628

    Last Modified: 23 Apr 2026

    Memory leak in the SSLVPN feature in Cisco IOS 12.3 through 12.4 allows remote attackers to cause a denial of service (memory consumption and device crash) by disconnecting an SSL session in an abnormal manner, leading to a Transmission Control Block (TCB) leak.

    Published: 27 Mar 2009
    7.1
    High

    CVE-2009-0633

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.

    Published: 27 Mar 2009