CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-0569

    Last Modified: 23 Apr 2026

    Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request.

    Published: 13 Feb 2009
    6.5
    Medium

    CVE-2008-6125

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 13 Feb 2009
    7.5
    High

    CVE-2008-6124

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the hotpot_delete_selected_attempts function in report.php in the HotPot module in Moodle 1.6 before 1.6.7, 1.7 before 1.7.5, 1.8 before 1.8.6, and 1.9 before 1.9.2 allows remote attackers to execute arbitrary SQL commands via a crafted selected attempt.

    Published: 13 Feb 2009
    6.8
    Medium

    CVE-2009-0009

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Pixlet codec in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted movie file that triggers memory corruption.

    Published: 13 Feb 2009
    7.2
    High

    CVE-2009-0011

    Last Modified: 23 Apr 2026

    Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file operation" on a temporary file.

    Published: 13 Feb 2009
    10
    Critical

    CVE-2009-0012

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.

    Published: 13 Feb 2009
    4.9
    Medium

    CVE-2009-0015

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."

    Published: 13 Feb 2009
    7.2
    High

    CVE-2009-0017

    Last Modified: 23 Apr 2026

    csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.

    Published: 13 Feb 2009
    7.8
    High

    CVE-2009-0018

    Last Modified: 23 Apr 2026

    The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.

    Published: 13 Feb 2009
    7.8
    High

    CVE-2009-0020

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.

    Published: 13 Feb 2009
    10
    Critical

    CVE-2009-0137

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issues."

    Published: 13 Feb 2009
    10
    Critical

    CVE-2009-0138

    Last Modified: 23 Apr 2026

    servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.

    Published: 13 Feb 2009
    5.5
    Medium

    CVE-2009-0141

    Last Modified: 23 Apr 2026

    XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.

    Published: 13 Feb 2009
    7.5
    High

    CVE-2009-0019

    Last Modified: 23 Apr 2026

    Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.

    Published: 13 Feb 2009
    9.3
    Critical

    CVE-2009-0139

    Last Modified: 23 Apr 2026

    Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.

    Published: 13 Feb 2009
    2.1
    Low

    CVE-2009-0013

    Last Modified: 23 Apr 2026

    dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.

    Published: 13 Feb 2009
    2.1
    Low

    CVE-2009-0014

    Last Modified: 23 Apr 2026

    Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.

    Published: 13 Feb 2009
    9.3
    Critical

    CVE-2009-0140

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.

    Published: 13 Feb 2009
    4.3
    Medium

    CVE-2009-0548

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Additional Report Settings interface in ESET Remote Administrator before 3.0.105 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2009
    9.3
    Critical

    CVE-2009-0546

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file.

    Published: 12 Feb 2009
    1.9
    Low

    CVE-2009-0142

    Last Modified: 23 Apr 2026

    Race condition in AFP Server in Apple Mac OS X 10.5.6 allows local users to cause a denial of service (infinite loop) via unspecified vectors related to "file enumeration logic."

    Published: 12 Feb 2009
    10
    Critical

    CVE-2009-0545

    Last Modified: 23 Apr 2026

    cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.

    Published: 12 Feb 2009
    6.8
    Medium

    CVE-2009-0543

    Last Modified: 23 Apr 2026

    ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms via invalid, encoded multibyte characters, which are not properly handled in (1) mod_sql_mysql and (2) mod_sql_postgres.

    Published: 12 Feb 2009
    6.8
    Medium

    CVE-2009-0530

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SnippetMaster 2.2.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _SESSION[SCRIPT_PATH] parameter to includes/vars.inc.php and the (2) g_pcltar_lib_dir parameter to includes/tar_lib/pcltar.lib.php.

    Published: 11 Feb 2009
    4.3
    Medium

    CVE-2009-0525

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the sajax_get_common_js function in php/Sajax.php in Sajax 0.12 allows remote attackers to inject arbitrary web script or HTML via the URL parameter, which is not properly handled when using browsers that do not URL-encode requests, such as Internet Explorer 6. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Feb 2009
    4.3
    Medium

    CVE-2009-0529

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in SnippetMaster Webpage Editor 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2009-0535

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the export_to parameter.

    Published: 11 Feb 2009
    4.3
    Medium

    CVE-2009-0532

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in password.php in Scripts For Sites (SFS) EZ Baby allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Feb 2009
    4.3
    Medium

    CVE-2009-0533

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in password.php in Scripts for Sites EZ Reminder allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving the u2 parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2009-0534

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter.

    Published: 11 Feb 2009
    4.9
    Medium

    CVE-2009-0536

    Last Modified: 23 Apr 2026

    at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2009-0531

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2009-0528

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 11 Feb 2009
    6.8
    Medium

    CVE-2009-0527

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the sitepath parameter.

    Published: 11 Feb 2009
    4.3
    Medium

    CVE-2009-0526

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) url and (2) acuparam parameters, and (3) the URI.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6111

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.php in NetArt Media Vlog System 1.1 allows remote attackers to execute arbitrary SQL commands via the note parameter.

    Published: 11 Feb 2009
    4.3
    Medium

    CVE-2008-6113

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SemanticScuttle before 0.90 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the (1) username and (2) profile page.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6114

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attackers to execute arbitrary SQL commands via the product parameter.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6115

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Prozilla Hosting Index allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action, a different vector than CVE-2008-2083.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6120

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile_comments.php in SocialEngine (SE) 2.7 and earlier allows remote attackers to execute arbitrary SQL commands via the comment_secure parameter.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6117

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in homepage.php in PG Job Site Pro allows remote attackers to execute arbitrary SQL commands via the poll_view_id parameter in a results action.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6119

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attackers to inject arbitrary PHP code into admin/userandpass.php via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Feb 2009
    7.8
    High

    CVE-2008-6122

    Last Modified: 23 Apr 2026

    The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a request that contains a question mark ("?").

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the EXtrovert Software Thyme (com_thyme) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event parameter to index.php.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6121

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the PHPSESSID cookie.

    Published: 11 Feb 2009
    5
    Medium

    CVE-2008-6112

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter in a detail action to (1) main.php and (2) template.php in ringtones/.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2008-6118

    Last Modified: 23 Apr 2026

    win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1.

    Published: 11 Feb 2009
    10
    Critical

    CVE-2008-6110

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SemanticScuttle before 0.90 has unknown impact and attack vectors related to improper validation of parameters to profile.php.

    Published: 11 Feb 2009
    10
    Critical

    CVE-2009-0517

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information.

    Published: 11 Feb 2009
    7.5
    High

    CVE-2009-0514

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in WebFrame 0.76 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) currentmod and (2) LANG parameters to mod/index.php.

    Published: 11 Feb 2009