CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6526

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2008-1838.

    Published: 25 Mar 2009
    7.5
    High

    CVE-2008-6527

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the iFor parameter.

    Published: 25 Mar 2009
    6.5
    Medium

    CVE-2008-6524

    Last Modified: 23 Apr 2026

    resetpass.php in openInvoice 0.90 beta and earlier allows remote authenticated users to change the passwords of arbitrary users via a modified uid parameter. NOTE: this can be leveraged with a separate vulnerability in auth.php to modify passwords without authentication.

    Published: 25 Mar 2009
    10
    Critical

    CVE-2008-6520

    Last Modified: 23 Apr 2026

    Multiple format string vulnerabilities in the SSI filter in Xitami Web Server 2.5c2, and possibly other versions, allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a URI that ends in (1) .ssi, (2) .shtm, or (3) .shtml, which triggers incorrect logging code involving the sendfmt function in the SMT kernel.

    Published: 25 Mar 2009
    4.3
    Medium

    CVE-2009-1080

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID 19033.

    Published: 25 Mar 2009
    5
    Medium

    CVE-2009-1075

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the Forgot Password feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

    Published: 25 Mar 2009
    5
    Medium

    CVE-2009-1074

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs.

    Published: 25 Mar 2009
    9.3
    Critical

    CVE-2009-0215

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 25 Mar 2009
    4.3
    Medium

    CVE-2009-1081

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19595 and 19661.

    Published: 25 Mar 2009
    4.3
    Medium

    CVE-2009-1079

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager (IdM) 7.0 through 8.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs 19659, 19660, and 19683.

    Published: 25 Mar 2009
    4
    Medium

    CVE-2009-1078

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the expected privilege requirements for (1) deleting audit policies and (2) modifying workflows, which allows remote authenticated users to have an unspecified impact.

    Published: 25 Mar 2009
    6.5
    Medium

    CVE-2009-1077

    Last Modified: 23 Apr 2026

    The Change My Password implementation in the admin interface in Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not enforce the RequiresChallenge property setting, which allows remote authenticated users to change the passwords of other users, as demonstrated by changing the administrator's password.

    Published: 25 Mar 2009
    5
    Medium

    CVE-2009-1076

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 responds differently to failed use of the end-user question-based login feature depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

    Published: 25 Mar 2009
    9
    Critical

    CVE-2009-1082

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 allows remote authenticated users to gain privileges by submitting crafted commands to the Admin Console, as demonstrated by privileges for account creation and other administrative capabilities, related to the saveNoValidate action and saveNoValidateAllowedFormsAndWorkflows IDs.

    Published: 25 Mar 2009
    9
    Critical

    CVE-2009-1083

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 on Linux, AIX, Solaris, and HP-UX permits "control characters" in the passwords of user accounts, which allows remote attackers to execute arbitrary commands via vectors involving "resource adapters."

    Published: 25 Mar 2009
    6.4
    Medium

    CVE-2009-1084

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object.

    Published: 25 Mar 2009
    5.5
    Medium

    CVE-2009-0891

    Last Modified: 23 Apr 2026

    The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 before Fix Pack 33 (6.0.2.33) does not properly enforce (1) nonce and (2) timestamp expiration values in WS-Security bindings as stored in the com.ibm.wsspi.wssecurity.core custom property, which allows remote authenticated users to conduct session hijacking attacks.

    Published: 25 Mar 2009
    7.5
    High

    CVE-2009-0920

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.

    Published: 25 Mar 2009
    10
    Critical

    CVE-2009-0921

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww.so.4.

    Published: 25 Mar 2009
    6.8
    Medium

    CVE-2009-0207

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.

    Published: 25 Mar 2009
    4.9
    Medium

    CVE-2009-1242

    Last Modified: 23 Apr 2026

    The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to the x86_64 platform.

    Published: 25 Mar 2009
    9.3
    Critical

    CVE-2009-1169

    Last Modified: 23 Apr 2026

    The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.

    Published: 25 Mar 2009
    6.4
    Medium

    CVE-2009-1102

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Virtual Machine in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "code generation."

    Published: 25 Mar 2009
    9.3
    Critical

    CVE-2009-1097

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allow remote attackers to access files or execute arbitrary code via (1) a crafted PNG image that triggers an integer overflow during memory allocation for display on the splash screen, aka CR 6804996; and (2) a crafted GIF image from which unspecified values are used in calculation of offsets, leading to object-pointer corruption, aka CR 6804997.

    Published: 25 Mar 2009
    10
    Critical

    CVE-2009-1095

    Last Modified: 23 Apr 2026

    Integer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.

    Published: 25 Mar 2009
    10
    Critical

    CVE-2009-1094

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the LDAP implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier allows remote LDAP servers to execute arbitrary code via unknown vectors related to serialized data.

    Published: 25 Mar 2009
    5
    Medium

    CVE-2009-1093

    Last Modified: 23 Apr 2026

    LdapCtx in the LDAP service in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; SDK and JRE 1.3.1_24 and earlier; and 1.4.2_19 and earlier does not close the connection when initialization fails, which allows remote attackers to cause a denial of service (LDAP service hang).

    Published: 25 Mar 2009
    2.6
    Low

    CVE-2009-0591

    Last Modified: 23 Apr 2026

    The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid but was actually invalid.

    Published: 25 Mar 2009
    9.3
    Critical

    CVE-2009-1098

    Last Modified: 23 Apr 2026

    Buffer overflow in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files or execute arbitrary code via a crafted GIF image, aka CR 6804998.

    Published: 25 Mar 2009
    5
    Medium

    CVE-2009-1101

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the lightweight HTTP server implementation in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier allows remote attackers to cause a denial of service (probably resource consumption) for a JAX-WS service endpoint via a connection without any data, which triggers a file descriptor "leak."

    Published: 25 Mar 2009
    5
    Medium

    CVE-2009-0590

    Last Modified: 23 Apr 2026

    The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.

    Published: 25 Mar 2009
    6.3
    Medium

    CVE-2009-0784

    Last Modified: 23 Apr 2026

    Race condition in the SystemTap stap tool 0.0.20080705 and 0.0.20090314 allows local users in the stapusr group to insert arbitrary SystemTap kernel modules and gain privileges via unknown vectors.

    Published: 25 Mar 2009
    10
    Critical

    CVE-2009-1096

    Last Modified: 23 Apr 2026

    Buffer overflow in unpack200 in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via a JAR file with crafted Pack200 headers.

    Published: 25 Mar 2009
    7.5
    High

    CVE-2009-0364

    Last Modified: 23 Apr 2026

    Format string vulnerability in the mini_calendar component in Citadel.org WebCit 7.22, and other versions before 7.39, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 24 Mar 2009
    4.3
    Medium

    CVE-2009-1070

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.

    Published: 24 Mar 2009
    9.3
    Critical

    CVE-2009-1071

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file.

    Published: 24 Mar 2009
    4.3
    Medium

    CVE-2009-1069

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the node edit form feature in Drupal Content Construction Kit (CCK) 6.x before 6.x-2.2, a module for Drupal, allow remote attackers to inject arbitrary web script or HTML via the (1) titles of candidate referenced nodes in the Node reference sub-module and the (2) names of candidate referenced users in the User reference sub-module.

    Published: 24 Mar 2009
    6.8
    Medium

    CVE-2009-1063

    Last Modified: 23 Apr 2026

    Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file.

    Published: 24 Mar 2009
    5.8
    Medium

    CVE-2009-1064

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method.

    Published: 24 Mar 2009
    7.5
    High

    CVE-2009-1065

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the x parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2009
    7.5
    High

    CVE-2009-1066

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request.

    Published: 24 Mar 2009
    4.3
    Medium

    CVE-2009-1067

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter.

    Published: 24 Mar 2009
    9.3
    Critical

    CVE-2009-1068

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long hostname in a .bsl playlist file.

    Published: 24 Mar 2009
    7.2
    High

    CVE-2009-1041

    Last Modified: 23 Apr 2026

    The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.

    Published: 24 Mar 2009
    7.5
    High

    CVE-2009-1049

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Mar 2009
    6.8
    Medium

    CVE-2008-6513

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a link that is listed by authors.php.

    Published: 24 Mar 2009
    6.8
    Medium

    CVE-2008-6512

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in the WorkerPool API in Google Gears before 0.5.4.2 allows remote attackers to bypass the Same Origin Policy and the intended access restrictions of the allowCrossOrigin function by hosting an assumed-safe file type containing Google Gear commands on the target domain, then accessing that file from the attacking domain, whose response headers are not checked and cause the worker code to run in the target domain.

    Published: 24 Mar 2009
    4.3
    Medium

    CVE-2008-6515

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

    Published: 24 Mar 2009
    9.3
    Critical

    CVE-2009-1060

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Charlie Miller during a PWN2OWN competition at CanSecWest 2009.

    Published: 24 Mar 2009
    9.3
    Critical

    CVE-2009-1059

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted .zip file. NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.

    Published: 24 Mar 2009