CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-6004

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in AJ Auction Pro Platinum 2 allows remote attackers to inject arbitrary web script or HTML via the product parameter.

    Published: 28 Jan 2009
    7.5
    High

    CVE-2008-6001

    Last Modified: 23 Apr 2026

    index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an initial sysop: string, an arbitrary password field, and a final :sysop:0 string.

    Published: 28 Jan 2009
    7.5
    High

    CVE-2008-5992

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL commands via the KayitNo parameter to (1) diger.php and (2) sayfalar.php.

    Published: 28 Jan 2009
    7.2
    High

    CVE-2008-6000

    Last Modified: 23 Apr 2026

    The GDTdiIcpt.sys driver in G DATA AntiVirus 2008, InternetSecurity 2008, and TotalCare 2008 populates kernel registers with IOCTL 0x8317001c input values, which allows local users to cause a denial of service (system crash) or gain privileges via a crafted IOCTL request, as demonstrated by execution of the KeSetEvent function with modified register contents.

    Published: 28 Jan 2009
    7.5
    High

    CVE-2008-5993

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in image.php in Barcode Generator 1D (barcodegen) 2.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the code parameter.

    Published: 28 Jan 2009
    4.3
    Medium

    CVE-2008-5994

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Jan 2009
    6.9
    Medium

    CVE-2008-5985

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Python interface in Epiphany 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 28 Jan 2009
    6.9
    Medium

    CVE-2009-0313

    Last Modified: 23 Apr 2026

    winetricks before 20081223 allows local users to overwrite arbitrary files via a symlink attack on the x_showmenu.txt temporary file.

    Published: 28 Jan 2009
    4.3
    Medium

    CVE-2009-0312

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.

    Published: 28 Jan 2009
    10
    Critical

    CVE-2009-0042

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA products allow remote attackers to bypass virus detection via a malformed archive file.

    Published: 28 Jan 2009
    4.3
    Medium

    CVE-2009-0374

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue.

    Published: 28 Jan 2009
    2.1
    Low

    CVE-2009-0675

    Last Modified: 23 Apr 2026

    The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests only when the CAP_NET_ADMIN capability is absent, instead of when this capability is present, which allows local users to reset the driver statistics, related to an "inverted logic" issue.

    Published: 28 Jan 2009
    9
    Critical

    CVE-2007-2795

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.

    Published: 27 Jan 2009
    10
    Critical

    CVE-2008-5982

    Last Modified: 23 Apr 2026

    Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.

    Published: 27 Jan 2009
    10
    Critical

    CVE-2009-0311

    Last Modified: 23 Apr 2026

    The Backbone service (ftbackbone.exe) in EMC AutoStart before 5.3 SP2 allows remote attackers to execute arbitrary code via a packet with a crafted value that is dereferenced as a function pointer.

    Published: 27 Jan 2009
    6.9
    Medium

    CVE-2009-0032

    Last Modified: 23 Apr 2026

    CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0291

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0292

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0293

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0297

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.

    Published: 27 Jan 2009
    9.3
    Critical

    CVE-2009-0298

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0299

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 27 Jan 2009
    6.8
    Medium

    CVE-2009-0301

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.

    Published: 27 Jan 2009
    4.6
    Medium

    CVE-2009-0302

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2009-0303

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Web Help Desk before 9.1.18 allows remote attackers to inject arbitrary web script or HTML via vectors related to "encoded JavaScript" and Helpdesk.woa.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0296

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 27 Jan 2009
    Unknown

    CVE-2009-0300

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2636. Reason: This candidate is a duplicate of CVE-2006-2636. Notes: All CVE users should reference CVE-2006-2636 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Jan 2009
    6.8
    Medium

    CVE-2009-0294

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3) comments.php, and (4) news.php; (5) News.php, (6) SendFriend.php, (7) Archive.php, and (8) Comments.php in base/; and possibly other components, different vectors than CVE-2007-1288.

    Published: 27 Jan 2009
    6.8
    Medium

    CVE-2009-0295

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Jan 2009
    7.8
    High

    CVE-2009-0304

    Last Modified: 23 Apr 2026

    The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.

    Published: 27 Jan 2009
    5
    Medium

    CVE-2009-0288

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory traversal sequences in a GET request.

    Published: 27 Jan 2009
    6.8
    Medium

    CVE-2009-0290

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.

    Published: 27 Jan 2009
    5
    Medium

    CVE-2009-0289

    Last Modified: 23 Apr 2026

    k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request.

    Published: 27 Jan 2009
    9.3
    Critical

    CVE-2009-0282

    Last Modified: 23 Apr 2026

    Integer overflow in Ralink Technology USB wireless adapter (RT73) 3.08 for Windows, and other wireless card drivers including rt2400, rt2500, rt2570, and rt61, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Probe Request packet with a long SSID, possibly related to an integer signedness error.

    Published: 27 Jan 2009
    2.6
    Low

    CVE-2009-0286

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0287

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lib/patUser.php in KEEP Toolkit before 2.5.1 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2009-0285

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0284

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2009-0283

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0281

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0280

    Last Modified: 23 Apr 2026

    Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2009-0279

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Jan 2009
    7.8
    High

    CVE-2009-0277

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in OpenSolaris snv_100 through snv_102 on the Sun UltraSPARC T2 and T2+ sun4v platforms allows local users to cause a denial of service (panic) via unknown vectors.

    Published: 27 Jan 2009
    5
    Medium

    CVE-2009-0278

    Last Modified: 23 Apr 2026

    Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.

    Published: 27 Jan 2009
    6.5
    Medium

    CVE-2008-5970

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2008-5971

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5972

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Active Business Directory 2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5973

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.aspx in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5974

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) password and (2) username fields.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5975

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links.asp in Active Price Comparison 4.0 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Jan 2009