CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-0810

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Published: 4 Mar 2009
    7.8
    High

    CVE-2008-6395

    Last Modified: 23 Apr 2026

    The web management interface in 3Com Wireless 8760 Dual Radio 11a/b/g PoE Access Point allows remote attackers to cause a denial of service (device crash) via a malformed HTTP POST request.

    Published: 4 Mar 2009
    9.3
    Critical

    CVE-2009-0812

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. NOTE: some of these details are obtained from third party information.

    Published: 4 Mar 2009
    3.5
    Low

    CVE-2009-0809

    Last Modified: 23 Apr 2026

    The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other products, allows remote authenticated users to read the profile card of an object in the document class via a link that is sent from the owner of the document object.

    Published: 4 Mar 2009
    5.4
    Medium

    CVE-2009-0804

    Last Modified: 23 Apr 2026

    Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

    Published: 4 Mar 2009
    5.4
    Medium

    CVE-2009-0802

    Last Modified: 23 Apr 2026

    Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

    Published: 4 Mar 2009
    5.4
    Medium

    CVE-2009-0803

    Last Modified: 23 Apr 2026

    SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

    Published: 4 Mar 2009
    5
    Medium

    CVE-2009-0780

    Last Modified: 23 Apr 2026

    The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of service (application crash) via an Autonomous System (AS) advertisement containing a long AS path.

    Published: 4 Mar 2009
    7.2
    High

    CVE-2009-0779

    Last Modified: 23 Apr 2026

    Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."

    Published: 4 Mar 2009
    9.3
    Critical

    CVE-2009-0772

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption.

    Published: 4 Mar 2009
    9.3
    Critical

    CVE-2009-0774

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773.

    Published: 4 Mar 2009
    10
    Critical

    CVE-2009-0775

    Last Modified: 23 Apr 2026

    Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execute arbitrary code via "cloned XUL DOM elements which were linked as a parent and child," which are not properly handled during garbage collection.

    Published: 4 Mar 2009
    5.8
    Medium

    CVE-2009-0777

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the location bar, which causes an incorrect address to be displayed and makes it easier for remote attackers to spoof URLs and conduct phishing attacks.

    Published: 4 Mar 2009
    10
    Critical

    CVE-2009-0771

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures.

    Published: 4 Mar 2009
    10
    Critical

    CVE-2009-0773

    Last Modified: 23 Apr 2026

    The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang.

    Published: 4 Mar 2009
    7.1
    High

    CVE-2009-0776

    Last Modified: 23 Apr 2026

    nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect.

    Published: 4 Mar 2009
    5
    Medium

    CVE-2009-0760

    Last Modified: 23 Apr 2026

    Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb.

    Published: 3 Mar 2009
    4.3
    Medium

    CVE-2009-0763

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.

    Published: 3 Mar 2009
    7.5
    High

    CVE-2009-0765

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the configfile parameter.

    Published: 3 Mar 2009
    5
    Medium

    CVE-2009-0770

    Last Modified: 23 Apr 2026

    dkim-milter 2.6.0 through 2.8.0 allows remote attackers to cause a denial of service (crash) by signing a message with a key that has been revoked in DNS, which triggers an assertion error.

    Published: 3 Mar 2009
    4.3
    Medium

    CVE-2009-0762

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ScriptsEz Ez PHP Comment allows remote attackers to inject arbitrary web script or HTML via the name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2009
    7.5
    High

    CVE-2009-0766

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2009
    5
    Medium

    CVE-2009-0767

    Last Modified: 23 Apr 2026

    Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data.

    Published: 3 Mar 2009
    4.3
    Medium

    CVE-2009-0761

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter.

    Published: 3 Mar 2009
    4.3
    Medium

    CVE-2009-0764

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm parameter to (1) index.php and (2) kipper.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Mar 2009
    7.5
    High

    CVE-2009-0768

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.

    Published: 3 Mar 2009
    4.3
    Medium

    CVE-2009-0769

    Last Modified: 23 Apr 2026

    QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\rtf\pict\&&} message. NOTE: the vulnerability may be in Sergey Tkachenko TRichView. If so, then this should not be treated as a vulnerability in QIP.

    Published: 3 Mar 2009
    6.5
    Medium

    CVE-2009-0759

    Last Modified: 23 Apr 2026

    Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the znc.conf configuration file and gain privileges via CRLF sequences in the quit message and other vectors.

    Published: 3 Mar 2009
    6.8
    Medium

    CVE-2009-0037

    Last Modified: 23 Apr 2026

    The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.

    Published: 3 Mar 2009
    6.2
    Medium

    CVE-2009-0578

    Last Modified: 23 Apr 2026

    GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.

    Published: 3 Mar 2009
    10
    Critical

    CVE-2009-0752

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vectors, possibly related to the password recovery mechanism.

    Published: 3 Mar 2009
    4.6
    Medium

    CVE-2009-0365

    Last Modified: 23 Apr 2026

    nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.

    Published: 3 Mar 2009
    9.3
    Critical

    CVE-2009-0186

    Last Modified: 23 Apr 2026

    Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow.

    Published: 3 Mar 2009
    2.1
    Low

    CVE-2009-0368

    Last Modified: 23 Apr 2026

    OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.

    Published: 2 Mar 2009
    7.5
    High

    CVE-2009-0750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 2 Mar 2009
    5
    Medium

    CVE-2009-0751

    Last Modified: 23 Apr 2026

    Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.

    Published: 2 Mar 2009
    7.8
    High

    CVE-2009-0749

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a crafted GIF image that causes the realloc function to return a new pointer, which triggers memory corruption when the old pointer is accessed.

    Published: 2 Mar 2009
    8.5
    High

    CVE-2008-6367

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in Member_images/.

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6368

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Chipmunk Guestbook 1.4m allows remote attackers to execute arbitrary SQL commands via the start parameter.

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6369

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitrary SQL commands via the Sort parameter.

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6372

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a Cat action. NOTE: some of these details are obtained from third party information.

    Published: 2 Mar 2009
    5
    Medium

    CVE-2008-6374

    Last Modified: 23 Apr 2026

    CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to db/MailingList.mdb.

    Published: 2 Mar 2009
    5
    Medium

    CVE-2008-6375

    Last Modified: 23 Apr 2026

    JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to userids.mdb.

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6376

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main.asp in Jbook allows remote attackers to execute arbitrary SQL commands via the password (pass parameter).

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6377

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6371

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary SQL commands via the username (Username parameter).

    Published: 2 Mar 2009
    7.5
    High

    CVE-2008-6380

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.

    Published: 2 Mar 2009
    5
    Medium

    CVE-2008-6382

    Last Modified: 23 Apr 2026

    ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to ASPPortal.mdb.

    Published: 2 Mar 2009
    6.8
    Medium

    CVE-2008-6384

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Comment Mail 5.x before 5.x-1.1, a module for Drupal, allow remote attackers to hijack the authentication of administrators.

    Published: 2 Mar 2009
    4.3
    Medium

    CVE-2008-6385

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Published: 2 Mar 2009