CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-0867

    Last Modified: 23 Apr 2026

    The HRM-S service in Fujitsu Enhanced Support Facility 3.0 and 3.0.1 allows remote attackers to obtain (1) hardware and (2) software information via unspecified requests in a client connection.

    Published: 10 Mar 2009
    6.8
    Medium

    CVE-2009-0868

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the WebLink template in Fujitsu Jasmine2000 Enterprise Edition allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 10 Mar 2009
    8.8
    High

    CVE-2009-0865

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control 8.1.2 and 8.2.0 in LIVEX_~1.OCX allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in the argument, possibly involving the PlayX and SnapShotX methods.

    Published: 10 Mar 2009
    5
    Medium

    CVE-2009-0866

    Last Modified: 23 Apr 2026

    pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for extra/genbackup.php.

    Published: 10 Mar 2009
    4.3
    Medium

    CVE-2009-0860

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web user interface in the login application in NetMRI 3.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to error pages.

    Published: 10 Mar 2009
    3.5
    Low

    CVE-2009-0871

    Last Modified: 23 Apr 2026

    The SIP channel driver in Asterisk Open Source 1.4.22, 1.4.23, and 1.4.23.1; 1.6.0 before 1.6.0.6; 1.6.1 before 1.6.1.0-rc2; and Asterisk Business Edition C.2.3, with the pedantic option enabled, allows remote authenticated users to cause a denial of service (crash) via a SIP INVITE request without any headers, which triggers a NULL pointer dereference in the (1) sip_uri_headers_cmp and (2) sip_uri_params_cmp functions.

    Published: 10 Mar 2009
    7.5
    High

    CVE-2009-0825

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2009-0857

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in /prm/reports in the Performance Reporting Module (PRM) for Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: this can be leveraged for access to the SunMC Web Console.

    Published: 9 Mar 2009
    4.9
    Medium

    CVE-2009-0537

    Last Modified: 23 Apr 2026

    Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2009-0856

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in sample applications in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, and 6.1 before 6.1.0.23 on z/OS, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Mar 2009
    5.8
    Medium

    CVE-2009-0858

    Last Modified: 23 Apr 2026

    The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in the required manner, which allows remote attackers, with control over a third-party subdomain served by tinydns and axfrdns, to trigger DNS responses containing arbitrary records via crafted zone data for this subdomain.

    Published: 9 Mar 2009
    4.7
    Medium

    CVE-2009-0859

    Last Modified: 23 Apr 2026

    The shm_get_stat function in ipc/shm.c in the shm subsystem in the Linux kernel before 2.6.28.5, when CONFIG_SHMEM is disabled, misinterprets the data type of an inode, which allows local users to cause a denial of service (system hang) via an SHM_INFO shmctl call, as demonstrated by running the ipcs program.

    Published: 9 Mar 2009
    6.8
    Medium

    CVE-2009-0853

    Last Modified: 23 Apr 2026

    login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via special characters in the Username parameter, as demonstrated by an admin'# parameter value.

    Published: 9 Mar 2009
    6.8
    Medium

    CVE-2009-0851

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewforum.php and (2) viewtopic.php.

    Published: 9 Mar 2009
    7.5
    High

    CVE-2009-0849

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute arbitrary code on Linux platforms via a long username field during backup domain authentication, related to libnnlindtb.so; or (2) cause a denial of service (daemon crash) on Windows platforms via a long username field during backup domain authentication, related to nnwindtb.dll. NOTE: some of these details are obtained from third party information.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2009-0850

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BitDefender Internet Security 2009 allows user-assisted remote attackers to inject arbitrary web script or HTML via the filename of a virus-infected file, as demonstrated by a filename inside a (1) rar or (2) zip archive file.

    Published: 9 Mar 2009
    5
    Medium

    CVE-2009-0852

    Last Modified: 23 Apr 2026

    showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.

    Published: 9 Mar 2009
    10
    Critical

    CVE-2008-6444

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in CSTransfer.dll in Baidu Hi IM might allow remote attackers to execute arbitrary code via a crafted packet, probably related to an improper length value.

    Published: 9 Mar 2009
    7.5
    High

    CVE-2008-6445

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the ability to upload arbitrary PHP code. NOTE: some of these details are obtained from third party information.

    Published: 9 Mar 2009
    7.5
    High

    CVE-2008-6446

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrary PHP code into the guestbook via the message parameter.

    Published: 9 Mar 2009
    9.3
    Critical

    CVE-2008-6447

    Last Modified: 23 Apr 2026

    Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.

    Published: 9 Mar 2009
    5.8
    Medium

    CVE-2008-6442

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Mar 2009
    4
    Medium

    CVE-2008-6449

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2008-6448

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in install.cgi in SKYARC System MTCMS WYSIWYG Editor allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Mar 2009
    9.3
    Critical

    CVE-2008-6441

    Last Modified: 23 Apr 2026

    Format string vulnerability in the Epic Games Unreal engine client, as used in multiple games, allows remote servers to execute arbitrary code via (1) the CLASS parameter in a DLMGR command, (2) a malformed package (PKG), and possibly (3) the LEVEL parameter in a WELCOME command.

    Published: 9 Mar 2009
    7.5
    High

    CVE-2008-6443

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum_duzen.php in phpKF allows remote attackers to execute arbitrary SQL commands via the fno parameter.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2008-6450

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Under Construction, Baby (UCB) PC2M 0.9.22.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2009-0855

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 on z/OS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Mar 2009
    7.5
    High

    CVE-2010-3444

    Last Modified: 11 Apr 2025

    Buffer overflow in the log2vis_utf8 function in pyfribidi.c in GNU FriBidi 0.19.1, 0.19.2, and possibly other versions, as used in PyFriBidi 0.10.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Arabic UTF-8 string that causes original 2-byte UTF-8 sequences to be transformed into 3-byte sequences.

    Published: 9 Mar 2009
    4.3
    Medium

    CVE-2008-6416

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GreenSQL-Console before 0.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "internal pages."

    Published: 6 Mar 2009
    5
    Medium

    CVE-2008-6417

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in GreenSQL-Console before 0.3.5 allows attackers to obtain the "installation directory" via unknown vectors.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6418

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in scrape.php in TorrentTrader before 2008-05-13 allows remote attackers to execute arbitrary SQL commands via the info_hash parameter.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.

    Published: 6 Mar 2009
    6.8
    Medium

    CVE-2008-6427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6428

    Last Modified: 23 Apr 2026

    The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6429

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view_request action to index2.php.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Published: 6 Mar 2009
    8.8
    High

    CVE-2008-6424

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in FFFTP 1.96b allows remote FTP servers to create or overwrite arbitrary files via a response to an FTP LIST command with a filename that contains a .. (dot dot).

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6436

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Web Server in Xerox WorkCentre 7132, 7228, 7235, and 7245 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6438

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the uid parameter, a different vector than CVE-2008-2455. NOTE: it was later reported that 2.1.4 is also affected.

    Published: 6 Mar 2009
    4.9
    Medium

    CVE-2009-0838

    Last Modified: 23 Apr 2026

    The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.

    Published: 6 Mar 2009
    5
    Medium

    CVE-2008-6420

    Last Modified: 23 Apr 2026

    Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.php, (2) webadmin/download.php, and (3) webadmin/download_file.php.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6421

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6431

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BMForum 5.6 allow remote attackers to inject arbitrary web script or HTML via the (1) outpused parameter to index.php, the (2) footer_copyright and (3) verandproname parameters to newtem/footer/bsd01footer.php, and the (4) topads and (5) myplugin parameters to newtem/header/bsd01header.php.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6433

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.

    Published: 6 Mar 2009
    4.3
    Medium

    CVE-2008-6437

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPFreeForum 1.0 RC2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to error.php, and the (2) nickname and (3) randomid parameters to part/menu.php.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6422

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) weapon.php and (2) map.php.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6419

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) sgc_id parameter to display_blog.php, (2) scm_mem_id parameter to social_my_profile_download.php, and the (3) catid parameter to social_forum_subcategories.php.

    Published: 6 Mar 2009
    7.5
    High

    CVE-2008-6434

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.cfm in Blue River Interactive Group Sava CMS before 5.0.122 allows remote attackers to execute arbitrary SQL commands via the LinkServID parameter.

    Published: 6 Mar 2009
    5
    Medium

    CVE-2008-6440

    Last Modified: 23 Apr 2026

    Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.

    Published: 6 Mar 2009