CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-5933

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka the input field for the cerca action) or (2) the id_oggetto parameter. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5934

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via the id_sezione parameter.

    Published: 21 Jan 2009
    5
    Medium

    CVE-2008-5932

    Last Modified: 23 Apr 2026

    CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    5
    Medium

    CVE-2008-5935

    Last Modified: 23 Apr 2026

    Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    5
    Medium

    CVE-2008-5931

    Last Modified: 23 Apr 2026

    The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/blog.mdb. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5922

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) main and (2) right parameters.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5923

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5924

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5926

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka user field) or the (2) password parameter (aka pass field). NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    5
    Medium

    CVE-2008-5929

    Last Modified: 23 Apr 2026

    VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the password via a direct request for database/shopping650.mdb. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5930

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute arbitrary SQL commands via the BlogID parameter.

    Published: 21 Jan 2009
    4.6
    Medium

    CVE-2008-5916

    Last Modified: 23 Apr 2026

    gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repository owners to execute arbitrary commands by modifying the diff.external configuration variable and executing a crafted gitweb query.

    Published: 21 Jan 2009
    4.3
    Medium

    CVE-2008-5917

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the XSS filter (framework/Text_Filter/Filter/xss.php) in Horde Application Framework 3.2.2 and 3.3, when Internet Explorer is being used, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to style attributes.

    Published: 21 Jan 2009
    3.5
    Low

    CVE-2009-0240

    Last Modified: 23 Apr 2026

    listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.

    Published: 21 Jan 2009
    4.3
    Medium

    CVE-2008-5918

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 21 Jan 2009
    6.8
    Medium

    CVE-2008-5919

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitrary files via directory traversal sequences in the rev parameter.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5920

    Last Modified: 23 Apr 2026

    The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch.

    Published: 21 Jan 2009
    9.3
    Critical

    CVE-2009-0219

    Last Modified: 23 Apr 2026

    The PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 performs delete operations on uninitialized pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted data stream in a .pdf file.

    Published: 21 Jan 2009
    6.8
    Medium

    CVE-2009-0253

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.

    Published: 21 Jan 2009
    7.5
    High

    CVE-2008-5516

    Last Modified: 23 Apr 2026

    The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_search.

    Published: 20 Jan 2009
    2.1
    Low

    CVE-2008-5914

    Last Modified: 23 Apr 2026

    An unspecified function in the JavaScript implementation in Apple Safari creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 20 Jan 2009
    2.1
    Low

    CVE-2008-5915

    Last Modified: 23 Apr 2026

    An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 20 Jan 2009
    8.8
    High

    CVE-2009-0182

    Last Modified: 23 Apr 2026

    Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.

    Published: 20 Jan 2009
    9.3
    Critical

    CVE-2008-4388

    Last Modified: 23 Apr 2026

    The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows remote attackers to execute arbitrary code via the installAppMgr method and unspecified other methods.

    Published: 20 Jan 2009
    10
    Critical

    CVE-2009-0178

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.

    Published: 20 Jan 2009
    2.1
    Low

    CVE-2008-5912

    Last Modified: 23 Apr 2026

    An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack." NOTE: as of 20090116, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 20 Jan 2009
    7.5
    High

    CVE-2009-0180

    Last Modified: 23 Apr 2026

    Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.

    Published: 20 Jan 2009
    9.3
    Critical

    CVE-2009-0181

    Last Modified: 23 Apr 2026

    Buffer overflow in VUPlayer allows user-assisted attackers to have an unknown impact via a long file, as demonstrated by a file composed entirely of 'A' characters.

    Published: 20 Jan 2009
    5
    Medium

    CVE-2009-0177

    Last Modified: 23 Apr 2026

    vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.

    Published: 20 Jan 2009
    9.3
    Critical

    CVE-2009-0174

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.

    Published: 20 Jan 2009
    10
    Critical

    CVE-2008-5911

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in RealNetworks Helix Server and Helix Mobile Server 11.x before 11.1.8 and 12.x before 12.0.1 allow remote attackers to (1) cause a denial of service via three crafted RTSP SETUP commands, or execute arbitrary code via (2) an NTLM authentication request with malformed base64-encoded data, (3) an RTSP DESCRIBE command, or (4) a DataConvertBuffer request.

    Published: 20 Jan 2009
    9.3
    Critical

    CVE-2009-0175

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.

    Published: 20 Jan 2009
    9.3
    Critical

    CVE-2009-0176

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the PDF distiller in the Attachment Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) 4.1.3 through 4.1.6, BlackBerry Professional Software 4.1.4, and BlackBerry Unite! before 1.0.3 bundle 28 allow user-assisted remote attackers to execute arbitrary code via (1) a crafted stream in a .pdf file, related to "symWidths"; or (2) a crafted data stream in a .pdf file, related to "bitmaps."

    Published: 20 Jan 2009
    4.3
    Medium

    CVE-2009-0413

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in RoundCube Webmail (roundcubemail) 0.2 stable allows remote attackers to inject arbitrary web script or HTML via the background attribute embedded in an HTML e-mail message.

    Published: 20 Jan 2009
    4.3
    Medium

    CVE-2009-0026

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.

    Published: 20 Jan 2009
    5
    Medium

    CVE-2009-3720

    Last Modified: 23 Apr 2026

    The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.

    Published: 17 Jan 2009
    4.9
    Medium

    CVE-2009-0322

    Last Modified: 23 Apr 2026

    drivers/firmware/dell_rbu.c in the Linux kernel before 2.6.27.13, and 2.6.28.x before 2.6.28.2, allows local users to cause a denial of service (system crash) via a read system call that specifies zero bytes from the (1) image_type or (2) packet_size file in /sys/devices/platform/dell_rbu/.

    Published: 17 Jan 2009
    4.9
    Medium

    CVE-2009-0031

    Last Modified: 23 Apr 2026

    Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel memory consumption) via unknown vectors related to a "missing kfree."

    Published: 17 Jan 2009
    4.3
    Medium

    CVE-2008-3821

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.

    Published: 16 Jan 2009
    7.2
    High

    CVE-2008-5908

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the root/boot archive tool in Sun OpenSolaris has unknown impact and local attack vectors, related to a "Temporary file vulnerability," aka Bug ID 6653455.

    Published: 16 Jan 2009
    7.2
    High

    CVE-2008-5909

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in conv_lpd in Sun OpenSolaris has unknown impact and local attack vectors, related to improper handling of temporary files, aka Bug ID 6655641.

    Published: 16 Jan 2009
    7.2
    High

    CVE-2008-5910

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in txzonemgr in Sun OpenSolaris has unknown impact and local attack vectors, related to a "Temporary file vulnerability," aka Bug ID 6653462.

    Published: 16 Jan 2009
    4.3
    Medium

    CVE-2009-0053

    Last Modified: 23 Apr 2026

    PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to a "logic error."

    Published: 16 Jan 2009
    6.8
    Medium

    CVE-2009-0055

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to modify appliance preferences as arbitrary users via unspecified vectors.

    Published: 16 Jan 2009
    4.7
    Medium

    CVE-2009-0167

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to enumeration of "wrong printers," aka a "Temporary file vulnerability."

    Published: 16 Jan 2009
    4.9
    Medium

    CVE-2009-0168

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a failure to "include all cache files," and improper handling of temporary files.

    Published: 16 Jan 2009
    9
    Critical

    CVE-2009-0169

    Last Modified: 23 Apr 2026

    Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and then logging in as amadmin in the root realm.

    Published: 16 Jan 2009
    5
    Medium

    CVE-2009-0172

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.

    Published: 16 Jan 2009
    7.8
    High

    CVE-2008-3818

    Last Modified: 23 Apr 2026

    Cisco ONS 15310-CL, 15310-MA, 15327, 15454, 15454 SDH, and 15600 with software 7.0.2 through 7.0.6, 7.2.2, 8.0.x, 8.5.1, and 8.5.2 allows remote attackers to cause a denial of service (control-card reset) via a crafted TCP session.

    Published: 16 Jan 2009
    7.1
    High

    CVE-2008-4444

    Last Modified: 23 Apr 2026

    Cisco Unified IP Phone (aka SIP phone) 7960G and 7940G with firmware P0S3-08-9-00 and possibly other versions before 8.10 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a Realtime Transport Protocol (RTP) packet with malformed headers.

    Published: 16 Jan 2009