CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2009-1031

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create arbitrary directories via a \.. (backslash dot dot) in an MKD request.

    Published: 20 Mar 2009
    6.8
    Medium

    CVE-2008-6492

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in process.php in Tizag Countdown Creator 3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via index.php, then accessing the uploaded file via a direct request to the file in pics/. NOTE: some of these details are obtained from third party information.

    Published: 20 Mar 2009
    5
    Medium

    CVE-2008-6493

    Last Modified: 23 Apr 2026

    Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Database/News.mdb.

    Published: 20 Mar 2009
    5
    Medium

    CVE-2008-6494

    Last Modified: 23 Apr 2026

    ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for users.mdb.

    Published: 20 Mar 2009
    4.3
    Medium

    CVE-2008-6495

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Published: 20 Mar 2009
    8.8
    High

    CVE-2008-6496

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.

    Published: 20 Mar 2009
    5
    Medium

    CVE-2009-1375

    Last Modified: 23 Apr 2026

    The PurpleCircBuffer implementation in Pidgin (formerly Gaim) before 2.5.6 does not properly maintain a certain buffer, which allows remote attackers to cause a denial of service (memory corruption and application crash) via vectors involving the (1) XMPP or (2) Sametime protocol.

    Published: 20 Mar 2009
    6.8
    Medium

    CVE-2008-6498

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentication of users for requests that change a certain .htaccess password via the xampppasswd parameter.

    Published: 20 Mar 2009
    9.3
    Critical

    CVE-2009-1022

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a long text field in a subtitle (.srt) file.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1026

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1027

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1024

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL commands via the linkid parameter to edlink.php, and unspecified other vectors.

    Published: 20 Mar 2009
    9.3
    Critical

    CVE-2009-1029

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a long Date header, related to Imap.dll.

    Published: 20 Mar 2009
    7.5
    High

    CVE-2009-1023

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands via the entry_id parameter.

    Published: 20 Mar 2009
    4.3
    Medium

    CVE-2009-0971

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in futomi's CGI Cafe Access Analyzer CGI Standard Version 3.8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2009-0963

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.

    Published: 19 Mar 2009
    4
    Medium

    CVE-2009-0967

    Last Modified: 23 Apr 2026

    The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service hang) via a large number of SMNT commands without an argument.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2009-0968

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 19 Mar 2009
    6.8
    Medium

    CVE-2009-0969

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authentication of administrators for requests that change the email address via the act[update] action.

    Published: 19 Mar 2009
    6.8
    Medium

    CVE-2009-0970

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/class_image.php in PHP Pro Bid 6.05, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the fileExtension parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2008-6490

    Last Modified: 23 Apr 2026

    function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2009-0964

    Last Modified: 23 Apr 2026

    UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2009-0965

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers to execute arbitrary SQL commands via the node parameter in a browse action to gdl.php.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2008-6489

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the album parameter to index.php.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2008-6491

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in connexion.php in PHPGKit 0.9 allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2009-0966

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cross.php in YABSoft Mega File Hosting 1.2 allows remote attackers to execute arbitrary PHP code via a URL in the url parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

    Published: 19 Mar 2009
    4.9
    Medium

    CVE-2009-1072

    Last Modified: 23 Apr 2026

    nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as demonstrated on a filesystem that has been exported with the root_squash option.

    Published: 19 Mar 2009
    9.3
    Critical

    CVE-2009-0723

    Last Modified: 23 Apr 2026

    Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Published: 19 Mar 2009
    7.5
    High

    CVE-2009-0962

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Futomi's CGI Cafe MP Form Mail CGI eCommerce 1.3.0 and earlier, and CGI Professional 3.2.2 and earlier, allows remote attackers to gain administrative privileges via unknown attack vectors.

    Published: 19 Mar 2009
    9.3
    Critical

    CVE-2009-0584

    Last Modified: 23 Apr 2026

    icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

    Published: 19 Mar 2009
    4.3
    Medium

    CVE-2009-0581

    Last Modified: 23 Apr 2026

    Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.

    Published: 19 Mar 2009
    9.3
    Critical

    CVE-2009-0583

    Last Modified: 23 Apr 2026

    Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

    Published: 19 Mar 2009
    9.3
    Critical

    CVE-2009-0733

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.

    Published: 19 Mar 2009
    5.1
    Medium

    CVE-2009-0940

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders allow remote attackers to hijack the intranet connectivity of arbitrary users for requests that (1) print documents via unknown vectors, (2) modify the network configuration via a NetIPChange request to hp/device/config_result_YesNo.html/config, or (3) change the password via the Password and ConfirmPassword parameters to hp/device/set_config_password.html/config.

    Published: 18 Mar 2009
    7.6
    High

    CVE-2009-0941

    Last Modified: 23 Apr 2026

    The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes it easier for remote attackers to obtain access.

    Published: 18 Mar 2009
    9.3
    Critical

    CVE-2008-4564

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.

    Published: 18 Mar 2009
    7.5
    High

    CVE-2008-6485

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.

    Published: 18 Mar 2009
    6.8
    Medium

    CVE-2008-6486

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in slideshow_uploadvideo.content.php in SharedLog, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_dir] parameter.

    Published: 18 Mar 2009
    7.5
    High

    CVE-2008-6487

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields.

    Published: 18 Mar 2009
    7.5
    High

    CVE-2008-6488

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.

    Published: 18 Mar 2009
    6.8
    Medium

    CVE-2008-6482

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_live_site parameter.

    Published: 18 Mar 2009
    7.5
    High

    CVE-2008-6483

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin.googlebase.php in the Ecom Solutions VirtueMart Google Base (aka com_googlebase or Froogle) component 1.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 18 Mar 2009
    7.5
    High

    CVE-2008-6484

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attackers to execute arbitrary SQL commands via the user field.

    Published: 18 Mar 2009
    4.6
    Medium

    CVE-2009-0538

    Last Modified: 23 Apr 2026

    Format string vulnerability in Symantec pcAnywhere before 12.5 SP1 allows local users to read and modify arbitrary memory locations, and cause a denial of service (application crash) or possibly have unspecified other impact, via format string specifiers in the pathname of a remote control file (aka .CHF file).

    Published: 18 Mar 2009
    9.3
    Critical

    CVE-2007-5543

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Miranda IM 0.6.8 and 0.7.0 allows remote attackers to execute arbitrary code via a crafted Yahoo! Messenger packet. NOTE: this might overlap CVE-2007-5590.

    Published: 18 Mar 2009
    9.3
    Critical

    CVE-2007-5542

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Miranda IM 0.6.8 allows remote attackers to execute arbitrary code via a crafted Yahoo! Messenger packet. NOTE: this might overlap CVE-2007-5590.

    Published: 18 Mar 2009
    5
    Medium

    CVE-2009-0936

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Tor before 0.2.0.34 allows attackers to cause a denial of service (infinite loop) via "corrupt votes."

    Published: 18 Mar 2009
    10
    Critical

    CVE-2009-0939

    Last Modified: 23 Apr 2026

    Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.

    Published: 18 Mar 2009
    5
    Medium

    CVE-2009-0937

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service via unknown vectors.

    Published: 18 Mar 2009
    5
    Medium

    CVE-2009-0938

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Tor before 0.2.0.34 allows directory mirrors to cause a denial of service (exit node crash) via "malformed input."

    Published: 18 Mar 2009