CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-6465

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.

    Published: 13 Mar 2009
    7.5
    High

    CVE-2008-6466

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action.

    Published: 13 Mar 2009
    4.3
    Medium

    CVE-2009-0934

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ejabberd before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to links and MUC logs.

    Published: 13 Mar 2009
    5
    Medium

    CVE-2009-0845

    Last Modified: 23 Apr 2026

    The spnego_gss_accept_sec_context function in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3, when SPNEGO is used, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via invalid ContextFlags data in the reqFlags field in a negTokenInit token.

    Published: 13 Mar 2009
    9
    Critical

    CVE-2009-0632

    Last Modified: 23 Apr 2026

    The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.1, 4.2 before 4.2(3)SR4b, 4.3 before 4.3(2)SR1b, 5.x before 5.1(3e), 6.x before 6.1(3), and 7.0 before 7.0(2) sends privileged directory-service account credentials to the client in cleartext, which allows remote attackers to modify the CUCM configuration and perform other privileged actions by intercepting these credentials, and then using them in requests unrelated to the intended synchronization task, as demonstrated by (1) DC Directory account credentials in CUCM 4.x and (2) TabSyncSysUser account credentials in CUCM 5.x through 7.x.

    Published: 12 Mar 2009
    6.9
    Medium

    CVE-2009-0876

    Last Modified: 23 Apr 2026

    Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain privileges via a hardlink attack, which preserves setuid/setgid bits on Linux, related to DT_RPATH:$ORIGIN.

    Published: 12 Mar 2009
    4.3
    Medium

    CVE-2009-0877

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express allow remote attackers to inject arbitrary web script or HTML via the (1) Full Name or (2) Subject field.

    Published: 12 Mar 2009
    5
    Medium

    CVE-2009-0879

    Last Modified: 23 Apr 2026

    The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of service (daemon crash) via a long consumer name, as demonstrated by an M-POST request to a long /CIMListener/ URI.

    Published: 12 Mar 2009
    6.8
    Medium

    CVE-2009-0883

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the BlueEyeCMS_login cookie parameter.

    Published: 12 Mar 2009
    4.3
    Medium

    CVE-2009-0884

    Last Modified: 23 Apr 2026

    Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets.

    Published: 12 Mar 2009
    9.3
    Critical

    CVE-2009-0885

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.

    Published: 12 Mar 2009
    5
    Medium

    CVE-2009-0886

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the default_language parameter.

    Published: 12 Mar 2009
    7.5
    High

    CVE-2009-0882

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to showtheme.php and the (2) user parameter to userinfo.php.

    Published: 12 Mar 2009
    7.5
    High

    CVE-2009-0881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Mar 2009
    6.8
    Medium

    CVE-2009-0880

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.

    Published: 12 Mar 2009
    4.3
    Medium

    CVE-2009-0366

    Last Modified: 23 Apr 2026

    The uncompress_buffer function in src/server/simple_wml.cpp in Wesnoth before r33069 allows remote attackers to cause a denial of service via a large compressed WML document.

    Published: 12 Mar 2009
    4.9
    Medium

    CVE-2009-0874

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allow local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors including ones related to (1) an argument handling deadlock in a door server and (2) watchpoint problems in the door_call function.

    Published: 12 Mar 2009
    6.9
    Medium

    CVE-2009-0875

    Last Modified: 23 Apr 2026

    Race condition in the Doors subsystem in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_94, allows local users to cause a denial of service (process hang), or possibly bypass file permissions or gain kernel-context privileges, via vectors involving the time at which control is transferred from a caller to a door server.

    Published: 12 Mar 2009
    4.6
    Medium

    CVE-2008-4316

    Last Modified: 23 Apr 2026

    Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation.

    Published: 12 Mar 2009
    5.8
    Medium

    CVE-2009-0582

    Last Modified: 23 Apr 2026

    The ntlm_challenge function in the NTLM SASL authentication mechanism in camel/camel-sasl-ntlm.c in Camel in Evolution Data Server (aka evolution-data-server) 2.24.5 and earlier, and 2.25.92 and earlier 2.25.x versions, does not validate whether a certain length value is consistent with the amount of data in a challenge packet, which allows remote mail servers to read information from the process memory of a client, or cause a denial of service (client crash), via an NTLM authentication type 2 packet with a length value that exceeds the amount of packet data.

    Published: 12 Mar 2009
    7.5
    High

    CVE-2009-0585

    Last Modified: 23 Apr 2026

    Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.

    Published: 12 Mar 2009
    7.5
    High

    CVE-2009-0587

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Evolution Data Server (aka evolution-data-server) before 2.24.5 allow context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation in (1) addressbook/libebook/e-vcard.c in evc or (2) camel/camel-mime-utils.c in libcamel.

    Published: 12 Mar 2009
    7.5
    High

    CVE-2009-0586

    Last Modified: 23 Apr 2026

    Integer overflow in the gst_vorbis_tag_add_coverart function (gst-libs/gst/tag/gstvorbistag.c) in vorbistag in gst-plugins-base (aka gstreamer-plugins-base) before 0.10.23 in GStreamer allows context-dependent attackers to execute arbitrary code via a crafted COVERART tag that is converted from a base64 representation, which triggers a heap-based buffer overflow.

    Published: 12 Mar 2009
    4.3
    Medium

    CVE-2009-0660

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mahara 1.0 before 1.0.10 and 1.1 before 1.1.2 allow remote attackers to inject arbitrary web script or HTML via a (1) profile and (2) blog, a different vulnerability than CVE-2009-0487.

    Published: 11 Mar 2009
    7.2
    High

    CVE-2009-0712

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows local users to gain privileges via unknown vectors.

    Published: 11 Mar 2009
    5
    Medium

    CVE-2009-0713

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in WMI Mapper for HP Systems Insight Manager before 2.5.2.0 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 11 Mar 2009
    4.4
    Medium

    CVE-2009-0848

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in GTK2 in OpenSUSE 11.0 and 11.1 allows local users to execute arbitrary code via a Trojan horse GTK module in an unspecified "relative search path."

    Published: 11 Mar 2009
    6.9
    Medium

    CVE-2009-0854

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in dash 0.5.4, when used as a login shell, allows local users to execute arbitrary code via a Trojan horse .profile file in the current working directory.

    Published: 11 Mar 2009
    6.8
    Medium

    CVE-2009-0872

    Last Modified: 23 Apr 2026

    The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combination with other security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the AUTH_NONE and AUTH_SYS security modes.

    Published: 11 Mar 2009
    5.8
    Medium

    CVE-2009-0233

    Last Modified: 23 Apr 2026

    The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easier for remote attackers to predict transaction IDs and poison caches by simultaneously sending crafted DNS queries and responses, aka "DNS Server Query Validation Vulnerability."

    Published: 11 Mar 2009
    10
    Critical

    CVE-2008-4563

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.

    Published: 11 Mar 2009
    6.8
    Medium

    CVE-2009-0873

    Last Modified: 23 Apr 2026

    The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security modes, which allows remote attackers to bypass intended access restrictions and read or modify files, as demonstrated by a combination of the sec=sys and sec=krb5 security modes, related to modes that "override each other."

    Published: 11 Mar 2009
    3.5
    Low

    CVE-2009-0093

    Last Modified: 23 Apr 2026

    Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) feature, and conduct man-in-the-middle attacks by spoofing a proxy server, via a Dynamic Update request for this hostname, aka "DNS Server Vulnerability in WPAD Registration Vulnerability," a related issue to CVE-2007-1692.

    Published: 11 Mar 2009
    5.5
    Medium

    CVE-2009-0094

    Last Modified: 23 Apr 2026

    The WINS server in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 does not restrict registration of the (1) "wpad" and (2) "isatap" NetBIOS names, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery (WPAD) and Intra-Site Automatic Tunnel Addressing Protocol (ISATAP) features, and conduct man-in-the-middle attacks by spoofing a proxy server or ISATAP route, by registering one of these names in the WINS database, aka "WPAD WINS Server Registration Vulnerability," a related issue to CVE-2007-1692.

    Published: 11 Mar 2009
    6.4
    Medium

    CVE-2009-0234

    Last Modified: 23 Apr 2026

    The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and poison caches by sending many crafted DNS queries that trigger "unnecessary lookups," aka "DNS Server Response Validation Vulnerability."

    Published: 11 Mar 2009
    4
    Medium

    CVE-2009-0786

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally intended for a report about TCP Wrappers and the hosts_ctl API function, but further investigation showed that this was documented behavior by that function. Notes: Future CVE identifiers might be assigned to applications that mis-use the API in a security-relevant fashion.

    Published: 11 Mar 2009
    9
    Critical

    CVE-2008-3547

    Last Modified: 23 Apr 2026

    Buffer overflow in the server in OpenTTD 0.6.1 and earlier allows remote authenticated users to cause a denial of service (persistent game disruption) or possibly execute arbitrary code via vectors involving many long names for "companies and clients."

    Published: 10 Mar 2009
    9.3
    Critical

    CVE-2009-0081

    Last Modified: 23 Apr 2026

    The graphics device interface (GDI) implementation in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate input received from user mode, which allows remote attackers to execute arbitrary code via a crafted (1) Windows Metafile (aka WMF) or (2) Enhanced Metafile (aka EMF) image file, aka "Windows Kernel Input Validation Vulnerability."

    Published: 10 Mar 2009
    7.2
    High

    CVE-2009-0083

    Last Modified: 23 Apr 2026

    The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 does not properly handle invalid pointers, which allows local users to gain privileges via an application that triggers use of a crafted pointer, aka "Windows Kernel Invalid Pointer Vulnerability."

    Published: 10 Mar 2009
    9.3
    Critical

    CVE-2009-0191

    Last Modified: 23 Apr 2026

    Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 3.0.2009.1301, does not properly handle a JBIG2 symbol dictionary segment with zero new symbols, which allows remote attackers to execute arbitrary code via a crafted PDF file that triggers a dereference of an uninitialized memory location.

    Published: 10 Mar 2009
    4.7
    Medium

    CVE-2009-0870

    Last Modified: 23 Apr 2026

    The NFSv4 Server module in the kernel in Sun Solaris 10, and OpenSolaris before snv_111, allow local users to cause a denial of service (infinite loop and system hang) by accessing an hsfs filesystem that is shared through NFSv4, related to the rfs4_op_readdir function.

    Published: 10 Mar 2009
    7.1
    High

    CVE-2009-0085

    Last Modified: 23 Apr 2026

    The Secure Channel (aka SChannel) authentication component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, when certificate authentication is used, does not properly validate the client's key exchange data in Transport Layer Security (TLS) handshake messages, which allows remote attackers to spoof authentication by crafting a TLS packet based on knowledge of the certificate but not the private key, aka "SChannel Spoofing Vulnerability."

    Published: 10 Mar 2009
    7.8
    High

    CVE-2009-0082

    Last Modified: 23 Apr 2026

    The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate handles, which allows local users to gain privileges via a crafted application that triggers unspecified "actions," aka "Windows Kernel Handle Validation Vulnerability."

    Published: 10 Mar 2009
    10
    Critical

    CVE-2009-0836

    Last Modified: 23 Apr 2026

    Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspecified other impact via a crafted file, as demonstrated by the "Open/Execute a file" action.

    Published: 10 Mar 2009
    10
    Critical

    CVE-2009-0837

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "Open/Execute a file" action.

    Published: 10 Mar 2009
    10
    Critical

    CVE-2009-0869

    Last Modified: 23 Apr 2026

    Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 on Windows allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 10 Mar 2009
    4.3
    Medium

    CVE-2009-0861

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpDenora before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via an IRC channel name. NOTE: some of these details are obtained from third party information.

    Published: 10 Mar 2009
    4.3
    Medium

    CVE-2009-0862

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the hook_cntrlr_error_output function in modules/page/hooks/listeners.php in the admincp component in TangoCMS 2.2.x (aka Eagle) before 2.2.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 10 Mar 2009
    7.5
    High

    CVE-2009-0863

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 10 Mar 2009
    7.5
    High

    CVE-2009-0864

    Last Modified: 23 Apr 2026

    S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie.

    Published: 10 Mar 2009