CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2009-0927

    Last Modified: 22 Apr 2026

    Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.

    Published: 18 Mar 2009
    4.3
    Medium

    CVE-2009-0933

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrative interface in Dotclear before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Mar 2009
    5
    Medium

    CVE-2009-0929

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 17 Mar 2009
    4.7
    Medium

    CVE-2009-0924

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun OpenSolaris snv_39 through snv_45, when running in 64-bit mode on x86 architectures, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6442712.

    Published: 17 Mar 2009
    4.7
    Medium

    CVE-2009-0925

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Solaris 10 on SPARC sun4v systems, and OpenSolaris snv_47 through snv_85, allows local users to cause a denial of service (hang of UFS filesystem write) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6425723.

    Published: 17 Mar 2009
    7.8
    High

    CVE-2009-0923

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Kerberos Incremental Propagation in Solaris 10 and OpenSolaris snv_01 through snv_110 allows remote attackers to cause a denial of service (loss of incremental propagation requests to slave KDC servers) via unknown vectors related to the master Key Distribution Center (KDC) server.

    Published: 17 Mar 2009
    7.5
    High

    CVE-2008-6481

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

    Published: 17 Mar 2009
    4.9
    Medium

    CVE-2009-0926

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the UFS filesystem functionality in Sun OpenSolaris snv_86 through snv_91, when running in 32-bit mode on x86 systems, allows local users to cause a denial of service (panic) via unknown vectors related to the (1) ufs_getpage and (2) ufs_putapage routines, aka CR 6679732.

    Published: 17 Mar 2009
    4.6
    Medium

    CVE-2011-1164

    Last Modified: 11 Apr 2025

    Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which might make it easier for remote attackers to perform attacks.

    Published: 17 Mar 2009
    6.8
    Medium

    CVE-2008-6479

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the "change password" feature in the VZPP web interface for Parallels Virtuozzo 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to modify the password via a link or IMG tag to vz/cp/pwd.

    Published: 16 Mar 2009
    6.8
    Medium

    CVE-2008-6480

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in engine/modules/imagepreview.php in Datalife Engine 6.7 allows remote attackers to hijack the authentication of arbitrary users for requests that use a modified image parameter.

    Published: 16 Mar 2009
    7.5
    High

    CVE-2009-0508

    Last Modified: 23 Apr 2026

    The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1.0, 5.1.1.19, 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.23, and 7.0 before 7.0.0.3 allow remote attackers to read arbitrary files contained in war files in (1) web-inf, (2) meta-inf, and unspecified other directories via unknown vectors, related to (a) web-based applications and (b) the administrative console.

    Published: 16 Mar 2009
    7.5
    High

    CVE-2009-0918

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.

    Published: 16 Mar 2009
    6.8
    Medium

    CVE-2009-0915

    Last Modified: 23 Apr 2026

    Opera before 9.64 allows remote attackers to conduct cross-domain scripting attacks via unspecified vectors related to plug-ins.

    Published: 16 Mar 2009
    4.3
    Medium

    CVE-2009-0917

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in DFLabs PTK 1.0.0 through 1.0.4 allows remote attackers to inject arbitrary web script or HTML by providing a forensic image containing HTML documents, which are rendered in web browsers during inspection by PTK. NOTE: the vendor states that the product is intended for use in a laboratory with "no contact from / to internet."

    Published: 16 Mar 2009
    9.3
    Critical

    CVE-2009-0914

    Last Modified: 23 Apr 2026

    Opera before 9.64 allows remote attackers to execute arbitrary code via a crafted JPEG image that triggers memory corruption.

    Published: 16 Mar 2009
    6.8
    Medium

    CVE-2008-6478

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the file manager in the VZPP web interface for Parallels Virtuozzo 365.6.swsoft (build 4.0.0-365.6.swsoft) and 25.4.swsoft (build 3.0.0-25.4.swsoft) allows remote attackers to create and delete arbitrary files as the administrator via a link or IMG tag to (1) create-file and (2) list-control in vz/cp/vzdir/infrman/envs/files/; or modify system configuration via the path parameter to vz/cp/vzdir/infrman/envs/files/index.

    Published: 16 Mar 2009
    10
    Critical

    CVE-2009-0916

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."

    Published: 16 Mar 2009
    7.5
    High

    CVE-2009-0919

    Last Modified: 23 Apr 2026

    XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "lampp" default password for the "nobody" account within the included ProFTPD installation, (2) a blank default password for the "root" account within the included MySQL installation, (3) a blank default password for the "pma" account within the phpMyAdmin installation, and possibly other unspecified passwords. NOTE: this was originally reported as a problem in DFLabs PTK, but this issue affects any product that is installed within the XAMPP environment, and should not be viewed as a vulnerability within that product. NOTE: DFLabs states that PTK is intended for use in a laboratory with "no contact from / to internet."

    Published: 16 Mar 2009
    4.7
    Medium

    CVE-2009-0913

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the keysock kernel module in Solaris 10 and OpenSolaris builds snv_01 through snv_108 allows local users to cause a denial of service (system panic) via unknown vectors related to PF_KEY socket, probably related to setting socket options.

    Published: 16 Mar 2009
    7.2
    High

    CVE-2009-0912

    Last Modified: 23 Apr 2026

    perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors.

    Published: 16 Mar 2009
    4.3
    Medium

    CVE-2008-6476

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 16 Mar 2009
    7.5
    High

    CVE-2008-6477

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 16 Mar 2009
    6.4
    Medium

    CVE-2008-6473

    Last Modified: 23 Apr 2026

    _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.

    Published: 16 Mar 2009
    9
    Critical

    CVE-2008-6474

    Last Modified: 23 Apr 2026

    The management interface in F5 BIG-IP 9.4.3 allows remote authenticated users with Resource Manager privileges to inject arbitrary Perl code via unspecified configuration settings related to Perl EP3 with templates, probably triggering static code injection.

    Published: 16 Mar 2009
    7.5
    High

    CVE-2008-6475

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earlier allows remote attackers to execute arbitrary SQL commands via the Via HTTP header (HTTP_VIA) to index.php.

    Published: 16 Mar 2009
    4.9
    Medium

    CVE-2009-2287

    Last Modified: 23 Apr 2026

    The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, does not validate the page table root in a KVM_SET_SREGS call, which allows local users to cause a denial of service (crash or hang) via a crafted cr3 value, which triggers a NULL pointer dereference in the gfn_to_rmap function.

    Published: 15 Mar 2009
    5
    Medium

    CVE-2009-0016

    Last Modified: 23 Apr 2026

    Apple iTunes before 8.1 on Windows allows remote attackers to cause a denial of service (infinite loop) via a Digital Audio Access Protocol (DAAP) message with a crafted Content-Length header.

    Published: 14 Mar 2009
    4.3
    Medium

    CVE-2009-0143

    Last Modified: 23 Apr 2026

    Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication request, which makes it easier for remote podcast servers to trick a user into providing a username and password when subscribing to a crafted podcast.

    Published: 14 Mar 2009
    4.9
    Medium

    CVE-2009-0824

    Last Modified: 23 Apr 2026

    Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.

    Published: 14 Mar 2009
    5
    Medium

    CVE-2009-0661

    Last Modified: 23 Apr 2026

    Wee Enhanced Environment for Chat (WeeChat) 0.2.6 allows remote attackers to cause a denial of service (crash) via an IRC PRIVMSG command containing crafted color codes that trigger an out-of-bounds read.

    Published: 14 Mar 2009
    7.5
    High

    CVE-2008-6452

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 Mar 2009
    4.3
    Medium

    CVE-2008-6453

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6454

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands via the singerid parameter in a singers action.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6459

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the auto BE User Registration (autobeuser) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6460

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Simple Random Objects (mw_random_objects) extension 1.0.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6461

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Random Prayer 2 (ste_prayer2) extension before 0.0.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6462

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the My quiz and poll (myquizpoll) extension before 0.1.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6467

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitrary SQL commands via the job_id parameter.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6468

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the area parameter in a browse action.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6471

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a show action.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6464

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 Mar 2009
    5
    Medium

    CVE-2008-6470

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ClanSphere before 2008.2.1 allow remote attackers to obtain sensitive information, and possibly have unknown other impact, via vectors related to "javascript insert" and the (1) mods/messages/getusers.php and (2) mods/abcode/listimg.php files. NOTE: some of these details are obtained from third party information.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6451

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2004-2036 or CVE-2005-3509.

    Published: 13 Mar 2009
    6.8
    Medium

    CVE-2008-6455

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6456

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the HBook (h_book) extension 2.3.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6457

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Swigmore institute (cgswigmore) extension before 0.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6458

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the FE address edit for tt_address & direct mail (dmaddredit) extension 0.4.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6463

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Diocese of Portsmouth Church Search (pd_churchsearch) extension before 0.1.1, and 0.2.10 and earlier 0.2.x versions, an extension for TYPO3, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Mar 2009