CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-6103

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in A4Desk Event Calendar, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the v parameter.

    Published: 10 Feb 2009
    5
    Medium

    CVE-2009-0498

    Last Modified: 23 Apr 2026

    Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request to guestbook.mdb.

    Published: 10 Feb 2009
    5
    Medium

    CVE-2009-0497

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in log.jsp in Ignite Realtime Openfire 3.6.2 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the log parameter.

    Published: 10 Feb 2009
    4.3
    Medium

    CVE-2009-0496

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) log parameter to (a) logviewer.jsp and (b) log.jsp; (2) search parameter to (c) group-summary.jsp; (3) username parameter to (d) user-properties.jsp; (4) logDir, (5) maxTotalSize, (6) maxFileSize, (7) maxDays, and (8) logTimeout parameters to (e) audit-policy.jsp; (9) propName parameter to (f) server-properties.jsp; and the (10) roomconfig_roomname and (11) roomconfig_roomdesc parameters to (g) muc-room-edit-form.jsp. NOTE: this can be leveraged for arbitrary code execution by using XSS to upload a malicious plugin.

    Published: 10 Feb 2009
    7.5
    High

    CVE-2009-0494

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Portfol (com_portfol) 1.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the vcatid parameter in a viewcategory action to index.php.

    Published: 10 Feb 2009
    9.3
    Critical

    CVE-2009-0491

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary code via a M3U file containing a long URL.

    Published: 10 Feb 2009
    7.5
    High

    CVE-2009-0495

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/define.php in REALTOR 747 4.11 allows remote attackers to execute arbitrary PHP code via a URL in the INC_DIR parameter.

    Published: 10 Feb 2009
    7.5
    High

    CVE-2009-0493

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL commands via the Username.

    Published: 10 Feb 2009
    10
    Critical

    CVE-2009-0492

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."

    Published: 10 Feb 2009
    7.5
    High

    CVE-2009-0542

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL commands via a "%" (percent) character in the username, which introduces a "'" (single quote) character during variable substitution by mod_sql.

    Published: 10 Feb 2009
    6.5
    Medium

    CVE-2009-0588

    Last Modified: 23 Apr 2026

    agent/request/op.cgi in the Registration Authority (RA) component in Red Hat Certificate System (RHCS) 7.3 and Dogtag Certificate System allows remote authenticated users to approve certificate requests queued for arbitrary agent groups via a modified request ID field.

    Published: 10 Feb 2009
    2.1
    Low

    CVE-2009-0489

    Last Modified: 23 Apr 2026

    The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemon, possibly including credentials.

    Published: 9 Feb 2009
    4.3
    Medium

    CVE-2009-0488

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Phorum before 5.2.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Feb 2009
    4.3
    Medium

    CVE-2009-0487

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mahara before 1.0.9 allows remote attackers to inject arbitrary web script or HTML via a crafted forum post.

    Published: 9 Feb 2009
    6.8
    Medium

    CVE-2008-6091

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tagname parameter.

    Published: 9 Feb 2009
    7.5
    High

    CVE-2008-6092

    Last Modified: 23 Apr 2026

    phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.

    Published: 9 Feb 2009
    4.3
    Medium

    CVE-2008-6096

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login page.

    Published: 9 Feb 2009
    4.3
    Medium

    CVE-2008-6094

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.do in Celoxis Technologies Celoxis allows remote attackers to inject arbitrary web script or HTML via the ni.smessage parameter.

    Published: 9 Feb 2009
    6.8
    Medium

    CVE-2008-6093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) file_id parameter in a detailansicht action and the (2) kategorie parameter in a kategorien action.

    Published: 9 Feb 2009
    4.3
    Medium

    CVE-2008-6095

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in surveillanceView.htm in OpenNMS 1.5.94 allows remote attackers to inject arbitrary web script or HTML via the viewName parameter.

    Published: 9 Feb 2009
    4.3
    Medium

    CVE-2008-6097

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WikyBlog before 1.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to index.php/Special/Main/keywordSearch, (2) revNum parameter to index.php/Edit/Main/Home, (3) to parameter to index.php/Special/Main/WhatLinksHere, (4) user parameter to index.php/Special/Main/UserEdits, and (5) the PATH_INFO to index.php.

    Published: 9 Feb 2009
    4.9
    Medium

    CVE-2009-0480

    Last Modified: 23 Apr 2026

    The IP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_82, uses an improper arena when allocating minor numbers for sockets, which allows local users to cause a denial of service (32-bit application failure and login outage) by opening a large number of sockets.

    Published: 9 Feb 2009
    7.5
    High

    CVE-2009-0479

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/admin_login.php in Online Grades 3.2.4 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Feb 2009
    7.5
    High

    CVE-2009-0486

    Last Modified: 23 Apr 2026

    Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.

    Published: 9 Feb 2009
    5.8
    Medium

    CVE-2009-0484

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete shared or saved searches via a link or IMG tag to buglist.cgi.

    Published: 9 Feb 2009
    5.8
    Medium

    CVE-2009-0482

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote attackers to perform bug updating activities as other users via a link or IMG tag to process_bug.cgi.

    Published: 9 Feb 2009
    3.5
    Low

    CVE-2009-0481

    Last Modified: 23 Apr 2026

    Bugzilla 2.x before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote authenticated users to conduct cross-site scripting (XSS) and related attacks by uploading HTML and JavaScript attachments that are rendered by web browsers.

    Published: 9 Feb 2009
    6.8
    Medium

    CVE-2009-5022

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in tif_ojpeg.c in the OJPEG decoder in LibTIFF before 3.9.5 allows remote attackers to execute arbitrary code via a crafted TIFF file.

    Published: 9 Feb 2009
    5.5
    Medium

    CVE-2009-0035

    Last Modified: 21 Nov 2024

    alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.

    Published: 9 Feb 2009
    5.8
    Medium

    CVE-2009-0483

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete keywords and user preferences via a link or IMG tag to (1) editkeywords.cgi or (2) userprefs.cgi.

    Published: 9 Feb 2009
    5.8
    Medium

    CVE-2009-0485

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.

    Published: 9 Feb 2009
    7.8
    High

    CVE-2009-0211

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32018.

    Published: 8 Feb 2009
    7.8
    High

    CVE-2009-0212

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32020.

    Published: 8 Feb 2009
    7.8
    High

    CVE-2009-0213

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NETIO application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to cause a denial of service (system crash) via unknown vectors, aka PD32021.

    Published: 8 Feb 2009
    10
    Critical

    CVE-2009-0210

    Last Modified: 23 Apr 2026

    Buffer overflow in the MLF application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service (system crash) via unspecified vectors, aka PD28578.

    Published: 8 Feb 2009
    9
    Critical

    CVE-2009-0214

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebFGServer application in AREVA e-terrahabitat 5.7 and earlier allows remote authenticated users to gain privileges via unknown vectors, aka PD32022.

    Published: 8 Feb 2009
    9.3
    Critical

    CVE-2009-0476

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as originally reported for Euphonics Audio Player 1.0. NOTE: some of these details are obtained from third party information.

    Published: 8 Feb 2009
    9.3
    Critical

    CVE-2009-0376

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a modified field that controls an unspecified structure length and triggers heap corruption, related to use of RealPlayer through a Windows Explorer plugin.

    Published: 8 Feb 2009
    4.9
    Medium

    CVE-2009-0206

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NFS in HP ONCplus B.11.31.05 and earlier for HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

    Published: 8 Feb 2009
    9.3
    Critical

    CVE-2009-0375

    Last Modified: 23 Apr 2026

    Buffer overflow in a DLL file in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a crafted Internet Video Recording (IVR) file with a filename length field containing a large integer, which triggers overwrite of an arbitrary memory location with a 0x00 byte value, related to use of RealPlayer through a Windows Explorer plugin.

    Published: 8 Feb 2009
    7.2
    High

    CVE-2009-0477

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via vectors related to the contract filesystem.

    Published: 8 Feb 2009
    7.8
    High

    CVE-2008-4560

    Last Modified: 23 Apr 2026

    HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain sensitive information via (1) a crafted request to the nnmRptConfig.exe CGI program, which reveals the pathname of log directories; or (2) a crafted parameter in a request to the ovlaunch.exe CGI program, which reveals configuration details. NOTE: this issue may be partially covered by CVE-2009-0205.

    Published: 8 Feb 2009
    10
    Critical

    CVE-2008-4562

    Last Modified: 23 Apr 2026

    Buffer overflow in the ovlaunch CGI program in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 on Windows allows remote attackers to execute arbitrary code via a crafted Host parameter. NOTE: this issue may be partially covered by CVE-2009-0205.

    Published: 8 Feb 2009
    10
    Critical

    CVE-2008-4559

    Last Modified: 23 Apr 2026

    HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. NOTE: this issue may be partially covered by CVE-2009-0205.

    Published: 8 Feb 2009
    4.6
    Medium

    CVE-2009-0579

    Last Modified: 23 Apr 2026

    Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified.

    Published: 7 Feb 2009
    10
    Critical

    CVE-2009-0544

    Last Modified: 23 Apr 2026

    Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.

    Published: 7 Feb 2009
    5
    Medium

    CVE-2009-0474

    Last Modified: 23 Apr 2026

    The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to obtain "internal web page information" and "internal information about the module" via unspecified vectors. NOTE: this may overlap CVE-2002-1603.

    Published: 6 Feb 2009
    7.5
    High

    CVE-2008-6088

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tordetails action to index.php.

    Published: 6 Feb 2009
    6.8
    Medium

    CVE-2009-0473

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 6 Feb 2009
    5
    Medium

    CVE-2002-2430

    Last Modified: 23 Apr 2026

    GoAhead WebServer before 2.1.1 allows remote attackers to cause a denial of service (CPU consumption) by performing a socket disconnect to terminate a request before it has been fully processed by the server.

    Published: 6 Feb 2009