CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-1050

    Last Modified: 23 Apr 2026

    Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie.

    Published: 24 Mar 2009
    5
    Medium

    CVE-2009-1051

    Last Modified: 23 Apr 2026

    FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.

    Published: 24 Mar 2009
    5
    Medium

    CVE-2009-1052

    Last Modified: 23 Apr 2026

    FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.

    Published: 24 Mar 2009
    5
    Medium

    CVE-2009-1053

    Last Modified: 23 Apr 2026

    chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv.

    Published: 24 Mar 2009
    9.3
    Critical

    CVE-2009-1054

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.

    Published: 24 Mar 2009
    4
    Medium

    CVE-2009-1055

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the web service in Sitecore CMS 5.3.1 rev. 071114 allows remote authenticated users to gain access to security databases, and obtain administrative and user credentials, via unknown vectors related to SOAP and XML requests.

    Published: 24 Mar 2009
    5
    Medium

    CVE-2009-1056

    Last Modified: 23 Apr 2026

    IBM Rational AppScan Enterprise before 5.5 FP1 allows remote attackers to read arbitrary exported reports by "forcefully browsing."

    Published: 24 Mar 2009
    10
    Critical

    CVE-2009-1057

    Last Modified: 23 Apr 2026

    MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, related to a "format string buffer overflow." NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.

    Published: 24 Mar 2009
    10
    Critical

    CVE-2009-1058

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file that triggers an SEH overwrite. NOTE: it is possible that this overlaps CVE-2005-3317. NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.

    Published: 24 Mar 2009
    5
    Medium

    CVE-2009-1273

    Last Modified: 23 Apr 2026

    pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames.

    Published: 24 Mar 2009
    6.4
    Medium

    CVE-2009-1103

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; 1.4.2_19 and earlier; and 1.3.1_24 and earlier allows remote attackers to access files and execute arbitrary code via unknown vectors related to "deserializing applets," aka CR 6646860.

    Published: 24 Mar 2009
    7.8
    High

    CVE-2009-0115

    Last Modified: 23 Apr 2026

    The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send arbitrary commands to the multipath daemon.

    Published: 24 Mar 2009
    7.5
    High

    CVE-2009-1105

    Last Modified: 23 Apr 2026

    The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 allows user-assisted remote attackers to cause a trusted applet to run in an older JRE version, which can be used to exploit vulnerabilities in that older version, aka CR 6706490.

    Published: 24 Mar 2009
    4.3
    Medium

    CVE-2008-6510

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.jsp in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 23 Mar 2009
    7.5
    High

    CVE-2008-6509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execute arbitrary SQL commands via the type parameter to sipark-log-summary.jsp.

    Published: 23 Mar 2009
    5.8
    Medium

    CVE-2008-6511

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.

    Published: 23 Mar 2009
    7.5
    High

    CVE-2008-6508

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows remote attackers to bypass authentication and access the admin interface via a .. (dot dot) in a URI that matches the Exclude-Strings list, as demonstrated by a /setup/setup-/.. sequence in a URI.

    Published: 23 Mar 2009
    4.3
    Medium

    CVE-2009-1047

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via vectors involving outbound HTML e-mail.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2008-6507

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2008-6506

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2009-1045

    Last Modified: 23 Apr 2026

    requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action.

    Published: 23 Mar 2009
    9.3
    Critical

    CVE-2009-1044

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

    Published: 23 Mar 2009
    10
    Critical

    CVE-2009-1043

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2008-6505

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.

    Published: 23 Mar 2009
    9.3
    Critical

    CVE-2009-1042

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple Safari on Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2009-1284

    Last Modified: 23 Apr 2026

    Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

    Published: 23 Mar 2009
    4.3
    Medium

    CVE-2009-1107

    Last Modified: 23 Apr 2026

    The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12 and earlier, and 5.0 Update 17 and earlier, allows remote attackers to trick a user into trusting a signed applet via unknown vectors that misrepresent the security warning dialog, related to a "Swing JLabel HTML parsing vulnerability," aka CR 6782871.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2009-1100

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allow remote attackers to cause a denial of service (disk consumption) via vectors related to temporary font files and (1) "limits on Font creation," aka CR 6522586, and (2) another unspecified vector, aka CR 6632886.

    Published: 23 Mar 2009
    5.8
    Medium

    CVE-2009-1104

    Last Modified: 23 Apr 2026

    The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier; 6 Update 12 and earlier; and 1.4.2_19 and earlier does not prevent Javascript that is loaded from the localhost from connecting to other ports on the system, which allows user-assisted attackers to bypass intended access restrictions via LiveConnect, aka CR 6724331. NOTE: this vulnerability can be leveraged with separate cross-site scripting (XSS) vulnerabilities for remote attack vectors.

    Published: 23 Mar 2009
    6.4
    Medium

    CVE-2009-1106

    Last Modified: 23 Apr 2026

    The Java Plug-in in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 6 Update 12, 11, and 10 does not properly parse crossdomain.xml files, which allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unknown vectors, aka CR 6798948.

    Published: 23 Mar 2009
    4.9
    Medium

    CVE-2009-0787

    Last Modified: 23 Apr 2026

    The ecryptfs_write_metadata_to_contents function in the eCryptfs functionality in the Linux kernel 2.6.28 before 2.6.28.9 uses an incorrect size when writing kernel memory to an eCryptfs file header, which triggers an out-of-bounds read and allows local users to obtain portions of kernel memory.

    Published: 23 Mar 2009
    7.5
    High

    CVE-2009-1099

    Last Modified: 23 Apr 2026

    Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow.

    Published: 23 Mar 2009
    5
    Medium

    CVE-2009-1037

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Send by e-mail module in the "Printer, e-mail and PDF versions" module 5.x before 5.x-4.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to send unlimited spam messages via unknown vectors related to the flood control API.

    Published: 20 Mar 2009
    10
    Critical

    CVE-2009-1034

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via values in the URI.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1032

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter.

    Published: 20 Mar 2009
    4.6
    Medium

    CVE-2008-6502

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room, leading to cross-site request forgery (CSRF), cross-site scripting (XSS), or other impacts.

    Published: 20 Mar 2009
    4.3
    Medium

    CVE-2009-1035

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Tasklist module 5.x-1.x before 5.x-1.3 and 5.x-2.x before 5.x-2.0-alpha1, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via Cascading Style Sheets (CSS).

    Published: 20 Mar 2009
    6.8
    Medium

    CVE-2009-1036

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Plus 1 module before 6.x-2.6, a module for Drupal, allows remote attackers to cast votes for content via unspecified aspects of the URI.

    Published: 20 Mar 2009
    6.5
    Medium

    CVE-2009-1038

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1039

    Last Modified: 23 Apr 2026

    Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file.

    Published: 20 Mar 2009
    9.3
    Critical

    CVE-2009-1040

    Last Modified: 23 Apr 2026

    Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted project (.wap) file.

    Published: 20 Mar 2009
    4.3
    Medium

    CVE-2008-6500

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CodeToad ASP Shopping Cart Script allows remote attackers to inject arbitrary web script or HTML via the query string to the default URI.

    Published: 20 Mar 2009
    4.3
    Medium

    CVE-2008-6501

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter.

    Published: 20 Mar 2009
    4.3
    Medium

    CVE-2008-6503

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PrestaShop 1.1.0.3 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/login.php and (2) order.php.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1033

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in misc.php in DeluxeBB 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the qorder parameter, a different vector than CVE-2005-2989 and CVE-2006-2503.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-0946

    Last Modified: 23 Apr 2026

    Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.

    Published: 20 Mar 2009
    5.5
    Medium

    CVE-2008-6499

    Last Modified: 23 Apr 2026

    security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to spoof critical variables, as demonstrated by setting the REMOTE_ADDR variable to 127.0.0.1.

    Published: 20 Mar 2009
    9.3
    Critical

    CVE-2009-1028

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file.

    Published: 20 Mar 2009
    7.8
    High

    CVE-2008-6497

    Last Modified: 23 Apr 2026

    The Neostrada Livebox ADSL Router allows remote attackers to cause a denial of service (network outage) via multiple HTTP requests for the /- URI.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1025

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 20 Mar 2009