CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-5969

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2008-5979

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to inject arbitrary web script or HTML via the Email parameter.

    Published: 27 Jan 2009
    5
    Medium

    CVE-2008-5980

    Last Modified: 23 Apr 2026

    Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for o12mail.mdb.

    Published: 27 Jan 2009
    5
    Medium

    CVE-2008-5981

    Last Modified: 23 Apr 2026

    PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) poll.mdb or (2) poll97.mdb.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5977

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the adname parameter in a Submit action.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2008-5976

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in siteadmin/forgot.php in PHP JOBWEBSITE PRO allow remote attackers to inject arbitrary web script or HTML via (1) the adname parameter in a Submit action or (2) the UserName field.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5978

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.

    Published: 27 Jan 2009
    6.4
    Medium

    CVE-2009-0932

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in framework/Image/Image.php in Horde before 3.2.4 and 3.3.3 and Horde Groupware before 1.1.5 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Horde_Image driver name.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2009-0931

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the tag cloud search script (horde/services/portal/cloud_search.php) in Horde before 3.2.4 and 3.3.3, and Horde Groupware before 1.1.5, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Jan 2009
    4.3
    Medium

    CVE-2009-0930

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 4.2.2 and 4.3.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) smime.php, (2) pgp.php, and (3) message.php.

    Published: 27 Jan 2009
    5
    Medium

    CVE-2009-0755

    Last Modified: 23 Apr 2026

    The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.

    Published: 27 Jan 2009
    4.4
    Medium

    CVE-2009-0036

    Last Modified: 23 Apr 2026

    Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.

    Published: 27 Jan 2009
    7.5
    High

    CVE-2008-5968

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cookie_language parameter in a phpicalendar_* cookie, a different vector than CVE-2006-1292.

    Published: 26 Jan 2009
    5
    Medium

    CVE-2008-5965

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to check for the existence of arbitrary files via a .. (dot dot) in the page parameter.

    Published: 26 Jan 2009
    7.5
    High

    CVE-2008-5966

    Last Modified: 23 Apr 2026

    globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename in the file parameter and file contents in the data parameter.

    Published: 26 Jan 2009
    7.5
    High

    CVE-2008-5967

    Last Modified: 23 Apr 2026

    admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote attackers to upload a calendar (aka .ics) file with arbitrary content to the calendars/ directory outside the web root.

    Published: 26 Jan 2009
    6.5
    Medium

    CVE-2009-0275

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jan 2009
    10
    Critical

    CVE-2009-0270

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in PXEService.exe in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to execute arbitrary code via a large PXE protocol request in a UDP packet.

    Published: 26 Jan 2009
    5
    Medium

    CVE-2009-0271

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the TFTP service in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors.

    Published: 26 Jan 2009
    7.5
    High

    CVE-2009-0265

    Last Modified: 23 Apr 2026

    Internet Systems Consortium (ISC) BIND 9.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077 and CVE-2009-0025.

    Published: 26 Jan 2009
    9.3
    Critical

    CVE-2008-5260

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the CamImage.CamImage.1 ActiveX control in AxisCamControl.ocx in AXIS Camera Control 2.40.0.0 allows remote attackers to execute arbitrary code via a long image_pan_tilt property value.

    Published: 26 Jan 2009
    10
    Critical

    CVE-2009-0264

    Last Modified: 23 Apr 2026

    Buffer overflow in the Registry Setting Tool in Fujitsu SystemcastWizard Lite 2.0A, 2.0, 1.9, and earlier has unknown impact and attack vectors.

    Published: 26 Jan 2009
    9.3
    Critical

    CVE-2009-0266

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jan 2009
    5
    Medium

    CVE-2009-0267

    Last Modified: 23 Apr 2026

    libike in Sun Solaris 9 and 10, and OpenSolaris before snv_100, does not properly check packets, which allows remote attackers to cause a denial of service (in.iked daemon crash) via an unspecified IKE packet, a different vulnerability than CVE-2007-2989.

    Published: 26 Jan 2009
    4.9
    Medium

    CVE-2009-0268

    Last Modified: 23 Apr 2026

    Race condition in the pseudo-terminal (aka pty) driver module in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows local users to cause a denial of service (panic) via unspecified vectors related to lack of "properly sequenced code" in ptc and ptsl.

    Published: 26 Jan 2009
    4.3
    Medium

    CVE-2010-0651

    Last Modified: 11 Apr 2025

    WebKit before r52784, as used in Google Chrome before 4.0.249.78 and Apple Safari before 4.0.5, permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

    Published: 26 Jan 2009
    4.3
    Medium

    CVE-2010-0051

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of stylesheets, which allows remote attackers to obtain sensitive information via a crafted HTML document. NOTE: this might overlap CVE-2010-0651.

    Published: 26 Jan 2009
    7.5
    High

    CVE-2008-5948

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5949

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php; (2) handle/proxy.php; (3) header.php, (4) include.php, and (5) workspace.php in includes/; and (6) plugins/RSS/files/rss.php.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5950

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in media/media_level.asp in ASP Template Creature allows remote attackers to execute arbitrary SQL commands via the mcatid parameter.

    Published: 23 Jan 2009
    5
    Medium

    CVE-2008-5951

    Last Modified: 23 Apr 2026

    ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for workDB/templatemonster.mdb.

    Published: 23 Jan 2009
    6
    Medium

    CVE-2008-5952

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the tid parameter in a vtech action to the default URI.

    Published: 23 Jan 2009
    5
    Medium

    CVE-2008-5956

    Last Modified: 23 Apr 2026

    Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request to connect.inc.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5957

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the directory parameter to index.php.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5958

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5959

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in start.asp in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) useremail parameter (aka username field) or (2) password parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5960

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to execute arbitrary SQL commands via the cID parameter in a document action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Jan 2009
    6.8
    Medium

    CVE-2008-5962

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the objectname parameter.

    Published: 23 Jan 2009
    10
    Critical

    CVE-2008-5963

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter.

    Published: 23 Jan 2009
    6.8
    Medium

    CVE-2008-5964

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 23 Jan 2009
    4.3
    Medium

    CVE-2009-0260

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).

    Published: 23 Jan 2009
    10
    Critical

    CVE-2009-0263

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file.

    Published: 23 Jan 2009
    9.3
    Critical

    CVE-2009-0262

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.

    Published: 23 Jan 2009
    4.3
    Medium

    CVE-2008-5961

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Tribiq CMS Community 5.0.10B and 5.0.11E allows remote attackers to inject arbitrary web script or HTML via the cID parameter in a document action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5953

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to the default URI.

    Published: 23 Jan 2009
    6.8
    Medium

    CVE-2008-5954

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a login action to an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2008-5955

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show.php in Wbstreet (aka PHPSTREET Webboard) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Jan 2009
    9.3
    Critical

    CVE-2009-0261

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.

    Published: 23 Jan 2009
    7.8
    High

    CVE-2009-0034

    Last Modified: 23 Apr 2026

    parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions for a user who belongs to that group, which allows local users to leverage an applicable sudoers file and gain root privileges via a sudo command.

    Published: 23 Jan 2009
    7.5
    High

    CVE-2009-0256

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to hijack web sessions via unspecified vectors related to (1) frontend and (2) backend authentication.

    Published: 22 Jan 2009