CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-0129

    Last Modified: 23 Apr 2026

    libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 11 Jan 2009
    5
    Medium

    CVE-2009-0127

    Last Modified: 23 Apr 2026

    M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: a Linux vendor disputes the relevance of this report to the M2Crypto product because "these functions are not used anywhere in m2crypto.

    Published: 11 Jan 2009
    4.9
    Medium

    CVE-2009-0746

    Last Modified: 23 Apr 2026

    The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.

    Published: 11 Jan 2009
    1.9
    Low

    CVE-2009-1215

    Last Modified: 23 Apr 2026

    Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the /tmp/screen-exchange temporary file.

    Published: 11 Jan 2009
    5
    Medium

    CVE-2009-0126

    Last Modified: 23 Apr 2026

    The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 11 Jan 2009
    5
    Medium

    CVE-2009-0124

    Last Modified: 23 Apr 2026

    The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 11 Jan 2009
    5
    Medium

    CVE-2009-0125

    Last Modified: 23 Apr 2026

    NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 does not properly check the return value from the OpenSSL DSA_do_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. NOTE: the upstream vendor has disputed this issue, stating "while we do misuse this function (this is a bug), it has absolutely no security ramification.

    Published: 11 Jan 2009
    7.2
    High

    CVE-2009-0029

    Last Modified: 23 Apr 2026

    The ABI in the Linux kernel 2.6.28 and earlier on s390, powerpc, sparc64, and mips 64-bit platforms requires that a 32-bit argument in a 64-bit register was properly sign extended when sent from a user-mode application, but cannot verify this, which allows local users to cause a denial of service (crash) or possibly gain privileges via a crafted system call.

    Published: 10 Jan 2009
    7.5
    High

    CVE-2008-5882

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.asp in Citrix Application Gateway - Broadcast Server (BCS) before 6.1, as used by Avaya AG250 - Broadcast Server before 2.0 and possibly other products, allows remote attackers to execute arbitrary SQL commands via the txtUID parameter.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0103

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0104

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.

    Published: 9 Jan 2009
    4.3
    Medium

    CVE-2009-0107

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0110

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0111

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 9 Jan 2009
    6.8
    Medium

    CVE-2009-0112

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create or modify accounts as administrators via the username, password, and name parameters.

    Published: 9 Jan 2009
    5
    Medium

    CVE-2009-0113

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0108

    Last Modified: 23 Apr 2026

    PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0109

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2009-0106

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 9 Jan 2009
    4.3
    Medium

    CVE-2009-0105

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2008-5881

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) gateway_module parameter to plugin/gateway/gnokii/init.php and the (2) themes_module parameter to plugin/themes/default/init.php.

    Published: 9 Jan 2009
    7.5
    High

    CVE-2008-5262

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the iGetHdrHeader function in src-IL/src/il_hdr.c in DevIL 1.7.4 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE file.

    Published: 9 Jan 2009
    5.8
    Medium

    CVE-2009-5138

    Last Modified: 12 Apr 2025

    GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which allows remote attackers to bypass intended restrictions by leveraging a X.509 V1 certificate from a trusted CA to issue new certificates, a different vulnerability than CVE-2014-1959.

    Published: 9 Jan 2009
    9.3
    Critical

    CVE-2008-5876

    Last Modified: 23 Apr 2026

    Buffer overflow in Irrlicht before 1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors in the B3D loader.

    Published: 8 Jan 2009
    5.1
    Medium

    CVE-2008-5878

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the (1) boxname parameter to theme/superchrome/box.php and the (2) theme parameter to phpclanwebsite/footer.php.

    Published: 8 Jan 2009
    9.3
    Critical

    CVE-2009-0070

    Last Modified: 23 Apr 2026

    Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.

    Published: 8 Jan 2009
    7.5
    High

    CVE-2008-5880

    Last Modified: 23 Apr 2026

    admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".

    Published: 8 Jan 2009
    5
    Medium

    CVE-2008-3819

    Last Modified: 23 Apr 2026

    dnsserver in Cisco Application Control Engine Global Site Selector (GSS) before 3.0(1) allows remote attackers to cause a denial of service (daemon crash) via a series of crafted DNS requests, aka Bug ID CSCsj70093.

    Published: 8 Jan 2009
    10
    Critical

    CVE-2008-0067

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) long string parameters to the OpenView5.exe CGI program; (2) a long string parameter to the OpenView5.exe CGI program, related to ov.dll; or a long string parameter to the (3) getcvdata.exe, (4) ovlaunch.exe, or (5) Toolbar.exe CGI program.

    Published: 8 Jan 2009
    9.3
    Critical

    CVE-2008-4827

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the AddTab method in the (1) Tab and (2) CTab ActiveX controls in c1sizer.ocx and the (3) TabOne ActiveX control in sizerone.ocx in ComponentOne SizerOne 8.0.20081.140, as used in ComponentOne Studio for ActiveX 2008, TSC2 Help Desk 4.1.8, SAP GUI 6.40 Patch 29 and 7.10, and possibly other products, allow remote attackers to execute arbitrary code by adding many tabs, or adding tabs with long tab captions.

    Published: 8 Jan 2009
    2.6
    Low

    CVE-2009-0071

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.

    Published: 8 Jan 2009
    7.5
    High

    CVE-2008-5874

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php in the (1) com_allhotels or (2) com_5starhotels module. NOTE: some of these details are obtained from third party information.

    Published: 8 Jan 2009
    7.5
    High

    CVE-2008-5875

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

    Published: 8 Jan 2009
    6.8
    Medium

    CVE-2008-5877

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php, (2) form_id parameter to pcw/processforms.php, (3) pcwlogin and (4) pcw_pass parameters to pcw/setlogin.php, (5) searchvalue parameter to pcw/downloads.php, and the (6) searchvalue and (7) whichfield parameter to pcw/downloads.php, a different vector than CVE-2006-0444.

    Published: 8 Jan 2009
    4.3
    Medium

    CVE-2008-5879

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows remote attackers to inject arbitrary web script or HTML via the page parameter and other unspecified vectors.

    Published: 8 Jan 2009
    10
    Critical

    CVE-2009-0043

    Last Modified: 23 Apr 2026

    The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 8 Jan 2009
    4.3
    Medium

    CVE-2009-0072

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application crash) via an onload=screen[""] attribute value in a BODY element.

    Published: 8 Jan 2009
    9.3
    Critical

    CVE-2008-5868

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via a long ProxyLogin value in a configuration (.cfg) file.

    Published: 8 Jan 2009
    4.3
    Medium

    CVE-2008-5869

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 allows remote authenticated users to inject arbitrary web script or HTML via the system.sysName.0 SNMP OID.

    Published: 8 Jan 2009
    4.3
    Medium

    CVE-2008-5870

    Last Modified: 23 Apr 2026

    FastStone Image Viewer 3.6 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with large width and height values, possibly a related issue to CVE-2007-1942.

    Published: 8 Jan 2009
    6.4
    Medium

    CVE-2008-5871

    Last Modified: 23 Apr 2026

    Nortel Multimedia Communication Server (MSC) 5100 3.0.13 does not verify credentials during call placement, which allows remote attackers to spoof and redirect VoIP calls, possibly related to the snoop command.

    Published: 8 Jan 2009
    7.8
    High

    CVE-2008-5872

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the UNIStim File Transfer Protocol (UFTP) processing in IP Client Manager (IPCM) in Nortel Multimedia Communication Server (MSC) 5100 3.0.13 allow remote attackers to cause a denial of service (device outage) via a UFTP message that has a negative block size or other crafted Connection Details values.

    Published: 8 Jan 2009
    7.5
    High

    CVE-2008-5873

    Last Modified: 23 Apr 2026

    Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username.

    Published: 8 Jan 2009
    5
    Medium

    CVE-2009-0041

    Last Modified: 23 Apr 2026

    IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

    Published: 8 Jan 2009
    4.9
    Medium

    CVE-2009-0069

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun Solaris 10 and OpenSolaris before snv_102 allows local users to cause a denial of service (recursive mutex_enter and panic) via unspecified vectors.

    Published: 7 Jan 2009
    10
    Critical

    CVE-2008-5866

    Last Modified: 23 Apr 2026

    The Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 has public as its default SNMP read/write community, which makes it easier for remote attackers to obtain sensitive information or modify SNMP variables.

    Published: 7 Jan 2009
    5
    Medium

    CVE-2008-5867

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Yerba SACphp 6.3 allows remote attackers to read arbitrary files, and possibly have other impact, via directory traversal sequences in the mod field contained in the base64-encoded SID parameter to an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Jan 2009
    6.8
    Medium

    CVE-2009-0068

    Last Modified: 23 Apr 2026

    Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

    Published: 7 Jan 2009
    7.6
    High

    CVE-2009-0066

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot. NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 7 Jan 2009
    5
    Medium

    CVE-2009-0046

    Last Modified: 23 Apr 2026

    Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009