CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-6171

    Last Modified: 23 Apr 2026

    includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.

    Published: 19 Feb 2009
    3.5
    Low

    CVE-2008-6170

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.12 and 6.x before 6.6 allows remote authenticated users with create book content or edit node book hierarchy permissions to inject arbitrary web script or HTML via the book page title.

    Published: 19 Feb 2009
    6.8
    Medium

    CVE-2008-6169

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Localization client 5.x before 5.x-1.1 and 6.x before 6.x-1.6 and the Localization server 5.x before 5.x-1.0-alpha5 and 6.x before 6.x-alpha2, modules for Drupal, allows remote attackers to perform unauthorized actions as administrators via unspecified vectors related to the "local translation submission interface."

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6167

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in search.php in miniPortail 2.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lng parameter.

    Published: 19 Feb 2009
    7.8
    High

    CVE-2009-0658

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitrary code via a crafted PDF document, related to a non-JavaScript function call and possibly an embedded JBIG2 image stream, as exploited in the wild in February 2009 by Trojan.Pidief.E.

    Published: 19 Feb 2009
    6.8
    Medium

    CVE-2009-0040

    Last Modified: 23 Apr 2026

    The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables.

    Published: 19 Feb 2009
    9.3
    Critical

    CVE-2009-1062

    Last Modified: 23 Apr 2026

    Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to trigger memory corruption and possibly execute arbitrary code via unknown attack vectors related to JBIG2, a different vulnerability than CVE-2009-0193 and CVE-2009-1061.

    Published: 19 Feb 2009
    9.3
    Critical

    CVE-2009-0193

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a PDF file with a malformed JBIG2 symbol dictionary segment, a different vulnerability than CVE-2009-1061 and CVE-2009-1062.

    Published: 19 Feb 2009
    10
    Critical

    CVE-2009-0928

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecified table.

    Published: 19 Feb 2009
    6.8
    Medium

    CVE-2008-6165

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) pseudo and (2) passe parameters.

    Published: 19 Feb 2009
    7.5
    High

    CVE-2008-6166

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to index.php.

    Published: 19 Feb 2009
    9.3
    Critical

    CVE-2009-1061

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Acrobat Reader 9 before 9.1, 8 before 8.1.4, and 7 before 7.1.1 might allow remote attackers to execute arbitrary code via unknown attack vectors related to JBIG2 and "input validation," a different vulnerability than CVE-2009-0193 and CVE-2009-1062.

    Published: 19 Feb 2009
    6.5
    Medium

    CVE-2009-0645

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) language, (2) Introduction_complete, and (3) use_log parameters, different vectors than CVE-2004-2445.

    Published: 18 Feb 2009
    7.5
    High

    CVE-2009-0646

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) password parameters to pcgi/4site.pl, (3) page parameter to print/print.shtml, (4) s and (5) i parameters to portfolio/index.shtml, (6) h parameter to hotel/index.php, (7) id parameter to news/news1.shtml, and the (8) th parameter to faq/index.shtml.

    Published: 18 Feb 2009
    4.3
    Medium

    CVE-2005-4878

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) acid_qry_main.php in Analysis Console for Intrusion Databases (ACID) 0.9.6b20 and (2) base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.2, and unspecified other console scripts in these products, allow remote attackers to inject arbitrary web script or HTML via the sig[1] parameter and possibly other parameters, a different vulnerability than CVE-2007-6156.

    Published: 18 Feb 2009
    5
    Medium

    CVE-2009-0644

    Last Modified: 23 Apr 2026

    The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it easier for remote attackers to obtain privileged access.

    Published: 18 Feb 2009
    7.5
    High

    CVE-2008-6162

    Last Modified: 23 Apr 2026

    Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNick cookie to admin.

    Published: 18 Feb 2009
    7.5
    High

    CVE-2008-6163

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in www/delivery/ac.php in OpenX 2.6.1 allows remote attackers to execute arbitrary SQL commands via the bannerid parameter.

    Published: 18 Feb 2009
    5
    Medium

    CVE-2009-0640

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by reading the vy_netman.cfg file that contains passwords.

    Published: 18 Feb 2009
    4.3
    Medium

    CVE-2008-6164

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in DreamCost HostAdmin 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 18 Feb 2009
    9.3
    Critical

    CVE-2009-0641

    Last Modified: 23 Apr 2026

    sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which might allow remote attackers to execute arbitrary code by passing a crafted environment variable from a telnet client, as demonstrated by an LD_PRELOAD value that references a malicious library.

    Published: 18 Feb 2009
    5.1
    Medium

    CVE-2009-0643

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary PHP code into news.txt via the post parameter, and then execute the code via a direct request to display.php. NOTE: some of these details are obtained from third party information.

    Published: 18 Feb 2009
    5
    Medium

    CVE-2008-6159

    Last Modified: 23 Apr 2026

    Content Management Made Easy (CMME) 1.19 allows remote attackers to obtain system information via a direct request to info.php, which invokes the phpinfo function.

    Published: 18 Feb 2009
    5
    Medium

    CVE-2008-6160

    Last Modified: 23 Apr 2026

    Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement menu and database APIs, which allows remote attackers to obtain usernames and read hashed emails and comments via unspecified vectors.

    Published: 18 Feb 2009
    4.3
    Medium

    CVE-2008-6161

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WOW Raid Manager (WRM) before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Feb 2009
    7.2
    High

    CVE-2009-0310

    Last Modified: 23 Apr 2026

    Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors related to "incoming data and authentication-strings."

    Published: 18 Feb 2009
    7.5
    High

    CVE-2009-0639

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute arbitrary PHP code via a URL in the Azione parameter.

    Published: 18 Feb 2009
    7.5
    High

    CVE-2008-6157

    Last Modified: 23 Apr 2026

    SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent attackers to obtain sensitive information.

    Published: 17 Feb 2009
    10
    Critical

    CVE-2008-6158

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the admin backend in w3b>cms (aka w3blabor CMS) before 3.2.0 have unknown impact and remote attack vectors.

    Published: 17 Feb 2009
    3.5
    Low

    CVE-2009-0359

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2) user full name.

    Published: 17 Feb 2009
    7.2
    High

    CVE-2009-0606

    Last Modified: 23 Apr 2026

    The link_image function in linker/linker.c in the dynamic linker in Bionic in Open Handset Alliance Android 1.0 on the T-Mobile G1 phone does not properly handle file descriptors 0, 1, and 2 for a setgid program, which allows local users to create arbitrary files owned by certain groups, possibly a related issue to CVE-2002-0820.

    Published: 17 Feb 2009
    7.2
    High

    CVE-2009-0608

    Last Modified: 23 Apr 2026

    Integer overflow in the showLog function in fake_log_device.c in liblog in Open Handset Alliance Android 1.0 allows attackers to trigger a buffer overflow and possibly have unspecified other impact by sending a large number of input lines.

    Published: 17 Feb 2009
    4.3
    Medium

    CVE-2009-0611

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3) clusterserviceproperties action, (4) the adminurl parameter in a global action, or (5) the print-list parameter.

    Published: 17 Feb 2009
    4.3
    Medium

    CVE-2009-0612

    Last Modified: 23 Apr 2026

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 3.x and InterScan Web Security Suite (IWSS) 3.x, when basic authorization is enabled on the standalone proxy, forwards the Proxy-Authorization header from Windows Media Player, which allows remote web servers to obtain credentials by offering a media stream and then capturing this header.

    Published: 17 Feb 2009
    6
    Medium

    CVE-2009-0613

    Last Modified: 23 Apr 2026

    Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended permission settings, and modify the system configuration, via requests to unspecified JSP pages.

    Published: 17 Feb 2009
    5
    Medium

    CVE-2008-4285

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Performance Monitoring Infrastructure (PMI) feature in the Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19, when a component statistic is enabled, allows attackers to cause a denial of service (daemon crash) via vectors related to "a gradual degradation in performance."

    Published: 17 Feb 2009
    2.1
    Low

    CVE-2009-0504

    Last Modified: 23 Apr 2026

    WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.1 does not properly recognize the IDAssertion.isUsed binding property, which allows local users to discover a password by reading a SOAP message.

    Published: 17 Feb 2009
    7.5
    High

    CVE-2009-0363

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.

    Published: 17 Feb 2009
    4.9
    Medium

    CVE-2009-0605

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in the do_page_fault function in arch/x86/mm/fault.c in the Linux kernel before 2.6.28.5 allows local users to cause a denial of service (memory corruption) or possibly gain privileges via unspecified vectors that trigger page faults on a machine that has a registered Kprobes probe.

    Published: 17 Feb 2009
    7.2
    High

    CVE-2009-0607

    Last Modified: 23 Apr 2026

    Multiple integer overflows in malloc_leak.c in Bionic in Open Handset Alliance Android 1.0 have unknown impact and attack vectors, related to the (1) chk_calloc and (2) leak_calloc functions.

    Published: 17 Feb 2009
    7.8
    High

    CVE-2009-0609

    Last Modified: 23 Apr 2026

    Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests.

    Published: 17 Feb 2009
    7.5
    High

    CVE-2009-0610

    Last Modified: 23 Apr 2026

    Multiple static code injection vulnerabilities in post.php in Simple PHP News 1.0 final allow remote attackers to inject arbitrary PHP code into news.txt via the (1) title or (2) date parameter, and then execute the code via a direct request to display.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Feb 2009
    Unknown

    CVE-2009-0671

    Last Modified: 7 Nov 2023

    Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit imap-2007d and other applications, allows remote attackers to execute arbitrary code via format string specifiers in the initial request to the IMAP port (143/tcp). NOTE: Red Hat has disputed the vulnerability, stating "The Red Hat Security Response Team have been unable to confirm the existence of this format string vulnerability in the toolkit, and the sample published exploit is not complete or functional." CVE agrees that the exploit contains syntax errors and uses Unix-only include files while invoking Windows functions

    Published: 17 Feb 2009
    6.8
    Medium

    CVE-2009-0577

    Last Modified: 23 Apr 2026

    Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2008-3640.

    Published: 17 Feb 2009
    7.5
    High

    CVE-2009-0604

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2009-0602

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in img/.

    Published: 16 Feb 2009
    3.5
    Low

    CVE-2009-0603

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the Link module 5.x-2.5 for Drupal 5.10 allows remote authenticated users, with "administer content types" privileges, to inject arbitrary web script or HTML via the description parameter (aka the Help field). NOTE: some of these details are obtained from third party information.

    Published: 16 Feb 2009
    6.5
    Medium

    CVE-2008-6156

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbitrary SQL commands via the campaignId parameter.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6155

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idtl parameter in a buy action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Feb 2009
    7.5
    High

    CVE-2008-6154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.

    Published: 16 Feb 2009