CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-6015

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in search.php in EsFaq 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) keywords and (2) cat parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jan 2009
    4.7
    Medium

    CVE-2009-1046

    Last Modified: 23 Apr 2026

    The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 30 Jan 2009
    9.3
    Critical

    CVE-2009-0341

    Last Modified: 23 Apr 2026

    The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.

    Published: 29 Jan 2009
    7.2
    High

    CVE-2009-0343

    Last Modified: 23 Apr 2026

    Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.

    Published: 29 Jan 2009
    10
    Critical

    CVE-2009-0344

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6633175, a different vulnerability than CVE-2007-5717.

    Published: 29 Jan 2009
    10
    Critical

    CVE-2009-0345

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 allows remote attackers to obtain privileged ELOM login access or execute arbitrary Service Processor (SP) commands via unknown vectors, aka Bug ID 6648082, a different vulnerability than CVE-2007-5717.

    Published: 29 Jan 2009
    4.9
    Medium

    CVE-2009-0346

    Last Modified: 23 Apr 2026

    The IP-in-IP packet processing implementation in the IPsec and IP stacks in the kernel in Sun Solaris 9 and 10, and OpenSolaris snv_01 though snv_85, allows local users to cause a denial of service (panic) via a self-encapsulated packet that lacks IPsec protection.

    Published: 29 Jan 2009
    5.8
    Medium

    CVE-2009-0347

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.

    Published: 29 Jan 2009
    5
    Medium

    CVE-2009-0348

    Last Modified: 23 Apr 2026

    The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

    Published: 29 Jan 2009
    9.3
    Critical

    CVE-2009-0349

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code via a long string in a licensing key (aka .key) file.

    Published: 29 Jan 2009
    7.2
    High

    CVE-2009-0342

    Last Modified: 23 Apr 2026

    Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall.

    Published: 29 Jan 2009
    9.3
    Critical

    CVE-2009-0350

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip. NOTE: some of these details are obtained from third party information.

    Published: 29 Jan 2009
    9
    Critical

    CVE-2009-0351

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0324

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.

    Published: 29 Jan 2009
    4.3
    Medium

    CVE-2009-0325

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0326

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0327

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.

    Published: 29 Jan 2009
    5
    Medium

    CVE-2009-0328

    Last Modified: 23 Apr 2026

    ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0333

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0334

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the day parameter in an archive action.

    Published: 29 Jan 2009
    4.3
    Medium

    CVE-2009-0335

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.

    Published: 29 Jan 2009
    6.8
    Medium

    CVE-2009-0340

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to execute arbitrary SQL commands via the itemID parameter in a view action.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0329

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Jan 2009
    6.8
    Medium

    CVE-2009-0330

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.

    Published: 29 Jan 2009
    7.8
    High

    CVE-2009-0331

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. NOTE: the vulnerability may be in my little homepage Comment script. If so, then this should not be treated as a vulnerability in ESPG.

    Published: 29 Jan 2009
    7.5
    High

    CVE-2009-0332

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AV Book Library before 1.1 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/edit.php, (2) admin/add.php, (3) lib/book_search.php, and possibly other components.

    Published: 29 Jan 2009
    5
    Medium

    CVE-2009-0336

    Last Modified: 23 Apr 2026

    Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb. NOTE: some of these details are obtained from third party information.

    Published: 29 Jan 2009
    4.3
    Medium

    CVE-2009-0338

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.

    Published: 29 Jan 2009
    6.8
    Medium

    CVE-2009-0642

    Last Modified: 23 Apr 2026

    ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote attackers to successfully present an invalid X.509 certificate, possibly involving a revoked certificate.

    Published: 29 Jan 2009
    6
    Medium

    CVE-2008-5082

    Last Modified: 23 Apr 2026

    The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate System 1.0 returns successfully even when token enrollment did not use the hardware key, which allows remote authenticated users with enrollment privileges to bypass intended authentication policies by performing enrollment with a software key.

    Published: 29 Jan 2009
    3.7
    Low

    CVE-2009-0415

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in trickle 1.07 allows local users to execute arbitrary code via a Trojan horse trickle-overload.so in the current working directory, which is referenced in the LD_PRELOAD path.

    Published: 29 Jan 2009
    10
    Critical

    CVE-2008-6005

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute value inputs.

    Published: 28 Jan 2009
    10
    Critical

    CVE-2009-0323

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.

    Published: 28 Jan 2009
    4.3
    Medium

    CVE-2008-3358

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Web Dynpro (WD) in the SAP NetWeaver portal, when Internet Explorer 7.0.5730 is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URI, which causes the XSS payload to be reflected in a text/plain document.

    Published: 28 Jan 2009
    6.9
    Medium

    CVE-2009-0319

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the autofs module in the kernel in Sun Solaris 8 through 10, and OpenSolaris before snv_108, allows local users to cause a denial of service (autofs mount outage) or possibly gain privileges via vectors related to "xdr processing problems."

    Published: 28 Jan 2009
    4.3
    Medium

    CVE-2009-0321

    Last Modified: 23 Apr 2026

    Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.

    Published: 28 Jan 2009
    4
    Medium

    CVE-2009-0320

    Last Modified: 23 Apr 2026

    Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."

    Published: 28 Jan 2009
    7.5
    High

    CVE-2008-5988

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in scripts/recruit_details.php in Jadu CMS for Government allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Jan 2009
    6.8
    Medium

    CVE-2008-5989

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter.

    Published: 28 Jan 2009
    6.8
    Medium

    CVE-2008-5990

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in connect/init.inc in emergecolab 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sitecode parameter to connect/index.php.

    Published: 28 Jan 2009
    7.5
    High

    CVE-2008-5991

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the doc parameter.

    Published: 28 Jan 2009
    4.3
    Medium

    CVE-2008-5995

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the freeCap CAPTCHA (sr_freecap) extension before 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Jan 2009
    3.5
    Low

    CVE-2008-5996

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Simplenews module 5.x before 5.x-1.5 and 6.x before 6.x-1.0-beta4, a module for Drupal, allows remote authenticated users, with "administer taxonomy" permissions, to inject arbitrary web script or HTML via a Newsletter category field.

    Published: 28 Jan 2009
    7.8
    High

    CVE-2008-5997

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in admin/fileKontrola/browser.asp in Omnicom Content Platform (OCP) 2.0 allows remote attackers to list arbitrary directories via a full pathname in the root parameter.

    Published: 28 Jan 2009
    6
    Medium

    CVE-2008-5998

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the ajax_checklist_save function in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allow remote authenticated users, with "update ajax checklists" permissions, to execute arbitrary SQL commands via a save operation, related to the (1) nid, (2) qid, and (3) state parameters.

    Published: 28 Jan 2009
    3.5
    Low

    CVE-2008-5999

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Ajax Checklist module 5.x before 5.x-1.1 for Drupal allows remote authenticated users, with create and edit permissions for posts, to inject arbitrary web script or HTML via unspecified vectors involving the ajax_checklist filter.

    Published: 28 Jan 2009
    7.1
    High

    CVE-2008-6002

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote attackers to read arbitrary files via a full pathname in the filelocation parameter.

    Published: 28 Jan 2009
    7.5
    High

    CVE-2008-6003

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute arbitrary SQL commands via the seller_id parameter.

    Published: 28 Jan 2009