CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2009-0450

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.

    Published: 5 Feb 2009
    5
    Medium

    CVE-2009-0453

    Last Modified: 23 Apr 2026

    Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0454

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DMXReady Online Notebook Manager 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field. NOTE: some third parties report inability to verify this issue.

    Published: 5 Feb 2009
    6.8
    Medium

    CVE-2009-0452

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.

    Published: 5 Feb 2009
    9.3
    Critical

    CVE-2009-0443

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an M3U file containing a long string in a URL.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0451

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Admin name field to the default URI under admin/.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0444

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in GRBoard 1.8, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) theme parameter to (a) 179_squarebox_pds_list/view.php, (b) 179_squarebox_minishop_expand/view.php, (c) 179_squarebox_gallery_list_pds/view.php, (d) 179_squarebox_gallery_list/view.php, (e) 179_squarebox_gallery/view.php, (f) 179_squarebox_board_swfupload/view.php, (g) 179_squarebox_board_expand/view.php, (h) 179_squarebox_board_basic_with_grcode/view.php, (i) 179_squarebox_board_basic/view.php, (j) 179_simplebar_pds_list/view.php, (k) 179_simplebar_notice/view.php, (l) 179_simplebar_gallery_list_pds/view.php, (m) 179_simplebar_gallery/view.php, and (n) 179_simplebar_basic/view.php in theme/; the (2) path parameter to (o) latest/sirini_gallery_latest/list.php; and the (3) grboard parameter to (p) include.php and (q) form_mail.php.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0445

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL commands via the exhibition_id parameter in a gallery.viewPhotos action.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0446

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Feb 2009
    Unknown

    CVE-2008-6067

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5838. Reason: This candidate is a duplicate of CVE-2008-5838. Notes: All CVE users should reference CVE-2008-5838 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2009
    7.5
    High

    CVE-2008-6066

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) modules.php, (2) ManagerResource.class.php, (3) ManagerRightsResource.class.php, (4) RegForm.class.php, (5) RegResource.class.php, and (6) RegRightsResource.class.php in classes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Feb 2009
    5.1
    Medium

    CVE-2008-6065

    Last Modified: 23 Apr 2026

    Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file through UTL_FILE operations, a related issue to CVE-2006-7141.

    Published: 5 Feb 2009
    4.3
    Medium

    CVE-2008-6060

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter.

    Published: 5 Feb 2009
    4.3
    Medium

    CVE-2008-6061

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary additional SWF content via a URL in the csPreloader parameter.

    Published: 5 Feb 2009
    4.3
    Medium

    CVE-2008-6062

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter. NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637.

    Published: 5 Feb 2009
    4.3
    Medium

    CVE-2008-6063

    Last Modified: 23 Apr 2026

    Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2008-6064

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the cat parameter to agenda/index.php, and unspecified other vectors.

    Published: 5 Feb 2009
    5
    Medium

    CVE-2009-1272

    Last Modified: 23 Apr 2026

    The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.

    Published: 5 Feb 2009
    5
    Medium

    CVE-2008-6058

    Last Modified: 23 Apr 2026

    Syslserve 1.058 and earlier, and probably 1.059, allows remote attackers to cause a denial of service (hang) via a crafted UDP Syslog packet.

    Published: 5 Feb 2009
    7.8
    High

    CVE-2009-0061

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Wireless LAN Controller (WLC) TSEC driver in the Cisco 4400 WLC, Cisco Catalyst 6500 and 7600 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.1 allows remote attackers to cause a denial of service (device crash or hang) via unknown IP packets.

    Published: 5 Feb 2009
    9
    Critical

    CVE-2009-0062

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.2.173.0 allows remote authenticated users to gain privileges via unknown vectors, as demonstrated by escalation from the (1) Lobby Admin and (2) Local Management User privilege levels.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the clanek parameter.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0426

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0423

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the preview parameter.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0431

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Default.asp in LinksPro Standard Edition allows remote attackers to execute arbitrary SQL commands via the OrderDirection parameter.

    Published: 5 Feb 2009
    4.3
    Medium

    CVE-2009-0430

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Active Bids allow remote attackers to inject arbitrary web script or HTML via the (1) search parameter to search.asp and the (2) URL parameter to tellafriend.asp.

    Published: 5 Feb 2009
    7.8
    High

    CVE-2008-4419

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the HP JetDirect web administration interface in the HP-ChaiSOE 1.0 embedded web server on the LaserJet 9040mfp, LaserJet 9050mfp, and Color LaserJet 9500mfp before firmware 08.110.9; LaserJet 4345mfp and 9200C Digital Sender before firmware 09.120.9; Color LaserJet 4730mfp before firmware 46.200.9; LaserJet 2410, LaserJet 2420, and LaserJet 2430 before firmware 20080819 SPCL112A; LaserJet 4250 and LaserJet 4350 before firmware 20080819 SPCL015A; and LaserJet 9040 and LaserJet 9050 before firmware 20080819 SPCL110A allows remote attackers to read arbitrary files via directory traversal sequences in the URI.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0428

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0420

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the RD-Autos (com_rdautos) 1.5.5 Stable component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0422

    Last Modified: 23 Apr 2026

    Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SERVER[ConfigFile] parameter to admin/index.php.

    Published: 5 Feb 2009
    4.3
    Medium

    CVE-2009-0424

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sign1.php in AN Guestbook (ANG) before 0.7.7 allows remote attackers to inject arbitrary web script or HTML via the country parameter, which is not properly handled in (1) administrator/manage.php or (2) administrator/trash.php. NOTE: some of these details are obtained from third party information.

    Published: 5 Feb 2009
    6.1
    Medium

    CVE-2009-0058

    Last Modified: 23 Apr 2026

    The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service (web authentication outage or device reload) via unspecified network traffic, as demonstrated by a vulnerability scanner.

    Published: 5 Feb 2009
    7.8
    High

    CVE-2009-0059

    Last Modified: 23 Apr 2026

    The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.2.x before 5.2.157.0 allow remote attackers to cause a denial of service (device reload) via a web authentication (aka WebAuth) session that includes a malformed POST request to login.html.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0421

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Eventing (com_eventing) 1.6.x component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Published: 5 Feb 2009
    7.5
    High

    CVE-2009-0429

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Active Bids allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to search.asp, (2) SortDir parameter to auctionsended.asp, and the (3) catid parameter to wishlist.php.

    Published: 5 Feb 2009
    10
    Critical

    CVE-2009-0388

    Last Modified: 23 Apr 2026

    Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code via a large length value in a message, related to the (a) ClientConnection::CheckBufferSize and (b) ClientConnection::CheckFileZipBufferSize functions in ClientConnection.cpp.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2009-0419

    Last Modified: 23 Apr 2026

    Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-4033.

    Published: 4 Feb 2009
    9.3
    Critical

    CVE-2009-0418

    Last Modified: 23 Apr 2026

    The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.

    Published: 4 Feb 2009
    7.5
    High

    CVE-2008-6046

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ADbNewsSender before 1.5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors in (1) opt_in_out.php.inc, (2) confirmation.php.inc, and (3) renewal.php.inc in mailinglist/.

    Published: 4 Feb 2009
    4.3
    Medium

    CVE-2008-6047

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ADbNewsSender before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) subscribing and (2) unsubscribing.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2008-6051

    Last Modified: 23 Apr 2026

    MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to obtain usernames and passwords via a direct request.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2008-6052

    Last Modified: 23 Apr 2026

    PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2008-6053

    Last Modified: 23 Apr 2026

    PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2008-6054

    Last Modified: 23 Apr 2026

    PreProjects Pre Courier and Cargo Business stores dbcourior.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

    Published: 4 Feb 2009
    5
    Medium

    CVE-2008-6055

    Last Modified: 23 Apr 2026

    PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

    Published: 4 Feb 2009
    7.5
    High

    CVE-2008-6050

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the item parameter to index.php.

    Published: 4 Feb 2009
    Unknown

    CVE-2008-6049

    Last Modified: 7 Nov 2023

    SQL injection vulnerability in index.php in TinyMCE 2.0.1 allows remote attackers to execute arbitrary SQL commands via the menuID parameter. NOTE: CVE and multiple reliable third parties dispute this issue, since TinyMCE does not contain index.php or any PHP code. This may be an issue in a product that has integrated TinyMCE

    Published: 4 Feb 2009
    5
    Medium

    CVE-2008-6057

    Last Modified: 23 Apr 2026

    Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to obtain passwords via a direct request.

    Published: 4 Feb 2009
    4.3
    Medium

    CVE-2008-6056

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to emailrecipe.aspx, (2) id parameter to recipedetail.aspx, and the (3) catid parameter to validatefieldlength.aspx.

    Published: 4 Feb 2009