CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-0257

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) content of indexed files to the (a) Indexed Search Engine (indexed_search) system extension; (b) unspecified test scripts in the ADOdb system extension; and (c) unspecified vectors in the Workspace module.

    Published: 22 Jan 2009
    10
    Critical

    CVE-2009-0258

    Last Modified: 23 Apr 2026

    The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is not properly handled by the command-line indexer.

    Published: 22 Jan 2009
    7.5
    High

    CVE-2009-0255

    Last Modified: 23 Apr 2026

    The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the encryption key with an insufficiently random seed, which makes it easier for attackers to crack the key.

    Published: 22 Jan 2009
    4.3
    Medium

    CVE-2009-0057

    Last Modified: 23 Apr 2026

    The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."

    Published: 22 Jan 2009
    6.8
    Medium

    CVE-2008-3820

    Last Modified: 23 Apr 2026

    Cisco Security Manager 3.1 and 3.2 before 3.2.2, when Cisco IPS Event Viewer (IEV) is used, exposes TCP ports used by the MySQL daemon and IEV server, which allows remote attackers to obtain "root access" to IEV via unspecified use of TCP sessions to these ports.

    Published: 22 Jan 2009
    9.3
    Critical

    CVE-2009-0254

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Flexible Image Transport System (FITS) file. NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2009
    7.6
    High

    CVE-2009-0008

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted MPEG-2 movie.

    Published: 22 Jan 2009
    9.3
    Critical

    CVE-2009-0246

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Radiance RGBE (aka .hdr) file.

    Published: 22 Jan 2009
    5
    Medium

    CVE-2009-0249

    Last Modified: 23 Apr 2026

    Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb.

    Published: 22 Jan 2009
    5
    Medium

    CVE-2009-0250

    Last Modified: 23 Apr 2026

    Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.

    Published: 22 Jan 2009
    6.5
    Medium

    CVE-2009-0251

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2009
    7.5
    High

    CVE-2009-0252

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2009
    4.3
    Medium

    CVE-2009-0247

    Last Modified: 23 Apr 2026

    The server for 53KF Web IM 2009 Home, Professional, and Enterprise editions relies on client-side protection mechanisms against cross-site scripting (XSS), which allows remote attackers to conduct XSS attacks by using a modified client to send a crafted IM message, related to the msg variable.

    Published: 22 Jan 2009
    4.3
    Medium

    CVE-2009-0248

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.

    Published: 22 Jan 2009
    6
    Medium

    CVE-2008-5941

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.

    Published: 22 Jan 2009
    2.6
    Low

    CVE-2008-5944

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter.

    Published: 22 Jan 2009
    6.8
    Medium

    CVE-2008-5940

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the searchid parameter. NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2009
    6.8
    Medium

    CVE-2008-5947

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/class_yapbbcooker.php in YapBB 1.2.Beta 2 allows remote attackers to execute arbitrary PHP code via a URL in the cfgIncludeDirectory parameter.

    Published: 22 Jan 2009
    7.5
    High

    CVE-2008-5946

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in readmore.php in PHP-Fusion 4.01 allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Published: 22 Jan 2009
    6.8
    Medium

    CVE-2008-5938

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the reflect_base parameter.

    Published: 22 Jan 2009
    7.5
    High

    CVE-2008-5943

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter to (1) admin_modules.php and (2) modules.php.

    Published: 22 Jan 2009
    7.5
    High

    CVE-2008-5945

    Last Modified: 23 Apr 2026

    Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jan 2009
    4.3
    Medium

    CVE-2008-5939

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the username field, possibly related to snippet.ditto.php. NOTE: some sources list the id parameter as being affected, but this is probably incorrect based on the original disclosure.

    Published: 22 Jan 2009
    4.3
    Medium

    CVE-2008-5942

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrls function and (2) "username input." NOTE: vector 2 may be related to CVE-2008-5939.

    Published: 22 Jan 2009
    5
    Medium

    CVE-2008-5936

    Last Modified: 23 Apr 2026

    front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parameter.

    Published: 22 Jan 2009
    4.3
    Medium

    CVE-2009-0245

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-4629.

    Published: 22 Jan 2009
    7.8
    High

    CVE-2008-5937

    Last Modified: 23 Apr 2026

    AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values.

    Published: 22 Jan 2009
    5
    Medium

    CVE-2009-0756

    Last Modified: 23 Apr 2026

    The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.

    Published: 22 Jan 2009
    9.3
    Critical

    CVE-2009-0397

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11, and GStreamer Plug-ins (aka gstreamer-plugins) 0.8.5, might allow remote attackers to execute arbitrary code via crafted Time-to-sample (aka stts) atom data in a malformed QuickTime media .mov file.

    Published: 22 Jan 2009
    9.3
    Critical

    CVE-2009-0387

    Last Modified: 23 Apr 2026

    Array index error in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted Sync Sample (aka stss) atom data in a malformed QuickTime media .mov file, related to "mark keyframes."

    Published: 22 Jan 2009
    9.3
    Critical

    CVE-2009-0386

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the qtdemux_parse_samples function in gst/qtdemux/qtdemux.c in GStreamer Good Plug-ins (aka gst-plugins-good) 0.10.9 through 0.10.11 might allow remote attackers to execute arbitrary code via crafted Composition Time To Sample (ctts) atom data in a malformed QuickTime media .mov file.

    Published: 22 Jan 2009
    7.5
    High

    CVE-2008-2384

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mod_auth_mysql.c in the mod-auth-mysql (aka libapache2-mod-auth-mysql) module for the Apache HTTP Server 2.x, when configured to use a multibyte character set that allows a \ (backslash) as part of the character encoding, allows remote attackers to execute arbitrary SQL commands via unspecified inputs in a login request.

    Published: 22 Jan 2009
    5.5
    Medium

    CVE-2009-0935

    Last Modified: 23 Apr 2026

    The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users to cause a denial of service (OOPS) via a read with an invalid address to an inotify instance, which causes the device's event list mutex to be unlocked twice and prevents proper synchronization of a data structure for the inotify instance.

    Published: 22 Jan 2009
    9.3
    Critical

    CVE-2009-0398

    Last Modified: 23 Apr 2026

    Array index error in the gst_qtp_trak_handler function in gst/qtdemux/qtdemux.c in GStreamer Plug-ins (aka gstreamer-plugins) 0.6.0 allows remote attackers to have an unknown impact via a crafted QuickTime media file.

    Published: 22 Jan 2009
    4.6
    Medium

    CVE-2008-3866

    Last Modified: 23 Apr 2026

    The Trend Micro Personal Firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, relies on client-side password protection implemented in the configuration GUI, which allows local users to bypass intended access restrictions and change firewall settings by using a modified client to send crafted packets.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0001

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0004

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted MP3 audio file.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0005

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted H.263 encoded movie file that triggers memory corruption.

    Published: 21 Jan 2009
    8.8
    High

    CVE-2009-0244

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 21 Jan 2009
    5
    Medium

    CVE-2008-3864

    Last Modified: 23 Apr 2026

    The ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allows remote attackers to cause a denial of service (service crash) via a packet with a large value in an unspecified size field.

    Published: 21 Jan 2009
    10
    Critical

    CVE-2008-3865

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the ApiThread function in the firewall service (aka TmPfw.exe) in Trend Micro Network Security Component (NSC) modules, as used in Trend Micro OfficeScan 8.0 SP1 Patch 1 and Internet Security 2007 and 2008 17.0.1224, allow remote attackers to execute arbitrary code via a packet with a small value in an unspecified size field.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0003

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via an AVI movie file with an invalid nBlockAlign value in the _WAVEFORMATEX structure.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0002

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QTVR movie file with crafted THKD atoms.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0006

    Last Modified: 23 Apr 2026

    Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cinepak encoded movie file with a crafted MDAT atom that triggers a heap-based buffer overflow.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0007

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.

    Published: 21 Jan 2009
    7.2
    High

    CVE-2009-0243

    Last Modified: 23 Apr 2026

    Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted remote attackers to execute arbitrary code by mapping a network drive; and allows user-assisted attackers to execute arbitrary code by clicking on (6) an icon under My Computer\Devices with Removable Storage and (7) an option in an AutoPlay dialog, related to the Autorun.inf file. NOTE: vectors 1 and 3 on Vista are already covered by CVE-2008-0951.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5921

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Jan 2009
    5
    Medium

    CVE-2008-5925

    Last Modified: 23 Apr 2026

    ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for diary.mdb.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5927

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka username field) or (2) checkpass parameter (aka password field) to admin/index.php. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5928

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in redir.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Jan 2009