CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-0047

    Last Modified: 23 Apr 2026

    Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    5
    Medium

    CVE-2009-0051

    Last Modified: 23 Apr 2026

    ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    5
    Medium

    CVE-2009-0049

    Last Modified: 23 Apr 2026

    Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    5
    Medium

    CVE-2009-0048

    Last Modified: 23 Apr 2026

    OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    4.3
    Medium

    CVE-2009-0050

    Last Modified: 23 Apr 2026

    Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    4.9
    Medium

    CVE-2009-0747

    Last Modified: 23 Apr 2026

    The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.

    Published: 7 Jan 2009
    5.8
    Medium

    CVE-2008-5077

    Last Modified: 23 Apr 2026

    OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

    Published: 7 Jan 2009
    6.8
    Medium

    CVE-2009-0025

    Last Modified: 23 Apr 2026

    BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    5
    Medium

    CVE-2009-0021

    Last Modified: 23 Apr 2026

    NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077.

    Published: 7 Jan 2009
    10
    Critical

    CVE-2008-5848

    Last Modified: 23 Apr 2026

    The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5849

    Last Modified: 23 Apr 2026

    Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an intranet address, as demonstrated by a TCP packet to the firewall management server on port 18264.

    Published: 6 Jan 2009
    Unknown

    CVE-2008-5850

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate was originally recorded for a "SPLAT Remote Root Exploit" that was claimed to exist for Check Point SmartCenter. The claim has no actionable details and was disclosed by a person of unknown reliability who did not coordinate with the vendor. No people of known reliability have confirmed the original claim. The vendor has not indicated that they are aware of any vulnerability. Since the claim has no actionable details or independent verification, it is outside the scope of CVE according to current inclusion criteria

    Published: 6 Jan 2009
    4.3
    Medium

    CVE-2008-5854

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in login.php in myPHPscripts Login Session 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) ls_user and (2) ls_email parameters (aka the User form) in an ls_register action. NOTE: some of these details are obtained from third party information.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5855

    Last Modified: 23 Apr 2026

    myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover usernames, e-mail addresses, and password hashes via a direct request for users.txt.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5856

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter.

    Published: 6 Jan 2009
    6.5
    Medium

    CVE-2008-5857

    Last Modified: 23 Apr 2026

    The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.

    Published: 6 Jan 2009
    4.3
    Medium

    CVE-2008-5858

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in KnowledgeTree before 3.5.4a allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-4281.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5861

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in source.php in FreeLyrics 1.0 allows remote attackers to read arbitrary files via directory traversal sequences in the p parameter. NOTE: some of these details are obtained from third party information.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5862

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the URI.

    Published: 6 Jan 2009
    7.5
    High

    CVE-2008-5863

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the y parameter in a get_user action.

    Published: 6 Jan 2009
    7.5
    High

    CVE-2008-5864

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showhoteldetails action to index.php.

    Published: 6 Jan 2009
    7.5
    High

    CVE-2008-5865

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the r_type parameter in a showhoteldetails action to index.php.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5852

    Last Modified: 23 Apr 2026

    Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for guestbook.mdb.

    Published: 6 Jan 2009
    5.1
    Medium

    CVE-2008-5859

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the show_page parameter.

    Published: 6 Jan 2009
    5.1
    Medium

    CVE-2008-5860

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to create or read arbitrary files via directory traversal sequences in the edit_file parameter.

    Published: 6 Jan 2009
    7.5
    High

    CVE-2008-5851

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary SQL commands via the seasonID parameter.

    Published: 6 Jan 2009
    5
    Medium

    CVE-2008-5853

    Last Modified: 23 Apr 2026

    Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) obtain database credentials via a direct request for config.inc or (2) read database backups via a request for a backup/ URI.

    Published: 6 Jan 2009
    4.9
    Medium

    CVE-2009-0748

    Last Modified: 23 Apr 2026

    The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate the superblock configuration, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) by attempting to mount a crafted ext4 filesystem.

    Published: 6 Jan 2009
    4.3
    Medium

    CVE-2008-5842

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via vectors associated with (1) a demo application shipped with WebTransactions and possibly (2) an unspecified "dynamic application."

    Published: 5 Jan 2009
    4.6
    Medium

    CVE-2008-5843

    Last Modified: 23 Apr 2026

    Multiple untrusted search path vulnerabilities in pdfjam allow local users to gain privileges via a Trojan horse program in (1) the current working directory or (2) /var/tmp, related to the (a) pdf90, (b) pdfjoin, and (c) pdfnup scripts.

    Published: 5 Jan 2009
    4.3
    Medium

    CVE-2008-5845

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Six Apart Movable Type (MT) before 4.23 allow remote attackers to inject arbitrary web script or HTML via a (1) MTEntryAuthorUsername, (2) MTAuthorDisplayName, (3) MTEntryAuthorDisplayName, or (4) MTCommenterName field in a Profile View template; a (5) listing screen or (6) edit screen in the CMS app; (7) a TrackBack title, related to the HTML sanitization library; or (8) a user archive name (aka archive title) on a published Community Blog template.

    Published: 5 Jan 2009
    2.6
    Low

    CVE-2008-5847

    Last Modified: 23 Apr 2026

    Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.

    Published: 5 Jan 2009
    4
    Medium

    CVE-2008-5846

    Last Modified: 23 Apr 2026

    Six Apart Movable Type (MT) before 4.23 allows remote authenticated users with create permission for posts to bypass intended access restrictions and publish posts via a "system-wide entry listing screen."

    Published: 5 Jan 2009
    9.3
    Critical

    CVE-2008-5839

    Last Modified: 23 Apr 2026

    Buffer overflow in Foxmail 6.5 allows remote attackers to execute arbitrary code via a long mailto URI in the HREF attribute of an A element.

    Published: 5 Jan 2009
    7.5
    High

    CVE-2008-5840

    Last Modified: 23 Apr 2026

    PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.

    Published: 5 Jan 2009
    7.5
    High

    CVE-2008-5841

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.

    Published: 5 Jan 2009
    7.5
    High

    CVE-2008-5838

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 5 Jan 2009
    6.3
    Medium

    CVE-2009-0022

    Last Modified: 23 Apr 2026

    Samba 3.2.0 through 3.2.6, when registry shares are enabled, allows remote authenticated users to access the root filesystem via a crafted connection request that specifies a blank share name.

    Published: 5 Jan 2009
    4.3
    Medium

    CVE-2009-2285

    Last Modified: 23 Apr 2026

    Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial of service (crash) via a crafted TIFF image, a different vulnerability than CVE-2008-2327.

    Published: 3 Jan 2009
    5
    Medium

    CVE-2008-5828

    Last Modified: 23 Apr 2026

    Microsoft Windows Live Messenger Client 8.5.1 and earlier, when MSN Protocol Version 15 (MSNP15) is used over a NAT session, allows remote attackers to discover intranet IP addresses and port numbers by reading the (1) IPv4InternalAddrsAndPorts, (2) IPv4Internal-Addrs, and (3) IPv4Internal-Port header fields.

    Published: 2 Jan 2009
    7.5
    High

    CVE-2008-5827

    Last Modified: 23 Apr 2026

    The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remote attackers to execute arbitrary code via a crafted URI record in an NDEF tag.

    Published: 2 Jan 2009
    2.6
    Low

    CVE-2008-5825

    Last Modified: 23 Apr 2026

    The SmartPoster implementation on the Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware does not properly display the URI record when the Title record contains a certain combination of space, CR (aka \r), and . (dot) characters, which allows remote attackers to trick a user into loading an arbitrary URI via a crafted NDEF tag, as demonstrated by (1) an http: URI for a malicious web site, (2) a tel: URI for a premium-rate telephone number, and (3) an sms: URI that triggers purchase of a ringtone.

    Published: 2 Jan 2009
    7.5
    High

    CVE-2008-2381

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.

    Published: 2 Jan 2009
    5
    Medium

    CVE-2008-5822

    Last Modified: 23 Apr 2026

    Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption and browser hang) via a long CLASS attribute in an HR element in an HTML document.

    Published: 2 Jan 2009
    4.3
    Medium

    CVE-2008-5823

    Last Modified: 23 Apr 2026

    An ActiveX control in prtstb06.dll in Microsoft Money 2006, when used with WScript in Windows Script Host (WSH) on Windows Vista, allows remote attackers to cause a denial of service (access violation and application crash) via a zero value for the Startup property.

    Published: 2 Jan 2009
    7.8
    High

    CVE-2008-5826

    Last Modified: 23 Apr 2026

    The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware allows remote attackers to cause a denial of service (device crash) via (1) a large value in the payload length field in an NDEF record, or a certain length for a (2) tel: or (3) sms: NDEF URI.

    Published: 2 Jan 2009
    5
    Medium

    CVE-2008-5821

    Last Modified: 23 Apr 2026

    Memory leak in WebKit.dll in WebKit, as used by Apple Safari 3.2 on Windows Vista SP1, allows remote attackers to cause a denial of service (memory consumption and browser crash) via a long ALINK attribute in a BODY element in an HTML document.

    Published: 2 Jan 2009
    7.5
    High

    CVE-2008-5820

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Published: 2 Jan 2009
    7.5
    High

    CVE-2008-5811

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gid parameter in a table action to index.php.

    Published: 2 Jan 2009
    6.8
    Medium

    CVE-2008-5819

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in eDNews_archive.php in eDreamers eDNews 2, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lg parameter. NOTE: some of these details are obtained from third party information.

    Published: 2 Jan 2009