4.3
    Medium

    CVE-2009-4032

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.

    Source:Moritz Naumann
    Published:21 Nov 2009
    4
    Medium

    CVE-2009-4019

    Last Modified: 17 May 2014

    mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.

    Source:Shane Bester
    Published:4 Nov 2009
    7.5
    High

    CVE-2009-4018

    Last Modified: 23 Apr 2026

    The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.

    Source:Hamid Ebadi
    Published:23 Jul 2009
    5
    Medium

    CVE-2009-4017

    Last Modified: 23 Apr 2026

    PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.

    Source:Eren
    Published:20 Nov 2009
    10
    Critical

    CVE-2009-4006

    Last Modified: 27 Sept 2016

    Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.

    Source:Metasploit
    Published:20 Nov 2009
    10
    Critical

    CVE-2009-3999

    Last Modified: 21 Oct 2011

    Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.

    Source:Metasploit
    Published:20 Jan 2010
    9.3
    Critical

    CVE-2009-3976

    Last Modified: 10 Mar 2011

    Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).

    Source:Metasploit
    Published:18 Nov 2009
    6.8
    Medium

    CVE-2009-3975

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL commands via the gallery_id parameter in a gallery_view action.

    Source:Mr.tro0oqy
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3973

    Last Modified: 3 Jan 2017

    SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a browse action, a different vector than CVE-2008-5629.

    Source:The_5p3ctrum
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3972

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in an sdetay action to index.php.

    Source:v3n0m
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3971

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the season parameter in a ladder action to index.php.

    Source:Chip d3 bi0s
    Published:18 Nov 2009
    6.5
    Medium

    CVE-2009-3970

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.

    Source:Mr.tro0oqy
    Published:18 Nov 2009
    9.3
    Critical

    CVE-2009-3969

    Last Modified: 17 Sept 2010

    Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.

    Source:hack4love
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3968

    Last Modified: 9 Nov 2016

    Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php, (2) cate_id parameter to category.php, (3) id parameter to news.php, and (4) productid parameter to itechd.php. NOTE: the sellers_othersitem.php, classifieds.php, and shop.php vectors are already covered by CVE-2008-3238.

    Source:Mr.SQL
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3967

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:rgod
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3966

    Last Modified: 23 Apr 2026

    Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.

    Source:Mr.tro0oqy
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3965

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL commands via the det parameter.

    Source:Bgh7
    Published:18 Nov 2009
    7.5
    High

    CVE-2009-3964

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the testimID parameter in a display action to index.php.

    Source:Chip d3 bi0s
    Published:18 Nov 2009
    7.8
    High

    CVE-2009-3962

    Last Modified: 23 Apr 2026

    The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.29.52 allows remote attackers to cause a denial of service (reboot) via a %0d%0a sequence in the page parameter to the xslt program on TCP port 50001, a related issue to CVE-2006-4523.

    Source:preth00nker
    Published:17 Nov 2009
    6.5
    Medium

    CVE-2009-3960

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

    Source:Roberto Suggi Liverani
    Published:15 Feb 2010
    10
    Critical

    CVE-2009-3958

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers to execute arbitrary code via unspecified initialization parameters.

    Source:superli
    Published:12 Jan 2010
    8.8
    High

    CVE-2009-3953

    Last Modified: 10 Mar 2011

    The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

    Source:Metasploit
    Published:12 Jan 2010
    7.5
    High

    CVE-2009-3949

    Last Modified: 23 Apr 2026

    cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows remote attackers to create administrative accounts via the name, password, and conf_password parameters.

    Source:Qabandi
    Published:16 Nov 2009
    4.3
    Medium

    CVE-2009-3948

    Last Modified: 1 Apr 2017

    JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and application crash) via a long string at the end of a .wav file.

    Source:prodigy
    Published:16 Nov 2009
    9.3
    Critical

    CVE-2009-3947

    Last Modified: 23 Apr 2026

    Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (process crash or device reboot) or possibly execute arbitrary code via a long USER command, as demonstrated by a command ending with many space characters.

    Source:otokoyama
    Published:16 Nov 2009
    7.5
    High

    CVE-2009-3913

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL commands via the select parameter.

    Source:Bernardo Trigo
    Published:9 Nov 2009
    5
    Medium

    CVE-2009-3912

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the album parameter.

    Source:blake
    Published:9 Nov 2009
    4.3
    Medium

    CVE-2009-3911

    Last Modified: 12 May 2014

    Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the sample parameter.

    Source:blake
    Published:9 Nov 2009
    7.5
    High

    CVE-2009-3904

    Last Modified: 23 Apr 2026

    classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to bypass restrictions and gain administrative access via a HTTP request that contains an empty (1) sessID (ccAdmin cookie), (2) X_CLUSTER_CLIENT_IP header, or (3) User-Agent header.

    Source:Bogdan Calin
    Published:6 Nov 2009
    5
    Medium

    CVE-2009-3902

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL.

    Source:Dr_IDE
    Published:6 Nov 2009
    4.3
    Medium

    CVE-2009-3901

    Last Modified: 20 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors.

    Source:BugsNotHugs
    Published:6 Nov 2009
    4.9
    Medium

    CVE-2009-3898

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0.8.x before 0.8.17, allows remote authenticated users to create or overwrite arbitrary files via a .. (dot dot) in the Destination HTTP header for the WebDAV (1) COPY or (2) MOVE method.

    Source:kingcope
    Published:24 Nov 2009
    6
    Medium

    CVE-2009-3890

    Last Modified: 4 May 2017

    Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress before 2.8.6, when a certain configuration of the mod_mime module in the Apache HTTP Server is enabled, allows remote authenticated users to execute arbitrary code by posting an attachment with a multiple-extension filename, and then accessing this attachment via a direct request to a wp-content/uploads/ pathname, as demonstrated by a .php.jpg filename.

    Source:Dawid Golunski
    Published:17 Nov 2009
    4.9
    Medium

    CVE-2009-3888

    Last Modified: 23 Apr 2026

    The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory.

    Source:David Howells
    Published:16 Nov 2009
    9.3
    Critical

    CVE-2009-3869

    Last Modified: 7 Mar 2011

    Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.

    Source:Metasploit
    Published:3 Nov 2009
    9.3
    Critical

    CVE-2009-3867

    Last Modified: 18 Dec 2016

    Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.

    Source:Tometzky
    Published:3 Nov 2009
    5
    Medium

    CVE-2009-3863

    Last Modified: 23 Apr 2026

    Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.

    Source:Francis Provencher
    Published:4 Nov 2009
    6.9
    Medium

    CVE-2009-3861

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd).

    Source:Metasploit
    Published:4 Nov 2009
    5.8
    Medium

    CVE-2009-3860

    Last Modified: 29 Apr 2014

    Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateFolder and (2) Copy methods. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.

    Source:Khashayar Fereidani
    Published:4 Nov 2009
    9.3
    Critical

    CVE-2009-3859

    Last Modified: 23 Apr 2026

    Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry.

    Source:LiquidWorm
    Published:4 Nov 2009
    4.3
    Medium

    CVE-2009-3858

    Last Modified: 22 Sept 2014

    Cross-site scripting (XSS) vulnerability in GejoSoft allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI in photos/tags.

    Source:Moudi
    Published:4 Nov 2009
    4.3
    Medium

    CVE-2009-3857

    Last Modified: 23 Apr 2026

    Buffer overflow in Softonic International SciTE 1.72 allows user-assisted remote attackers to cause a denial of service (application crash) via a Ruby (.rb) file containing a long string, which triggers the crash when a scroll bar is used.

    Source:prodigy
    Published:4 Nov 2009
    4.3
    Medium

    CVE-2009-3856

    Last Modified: 19 Aug 2014

    Cross-site scripting (XSS) vulnerability in the default URI in news/ in Twilight CMS before 4.1 allows remote attackers to inject arbitrary web script or HTML via the calendar parameter. NOTE: some of these details are obtained from third party information.

    Source:Vladimir Vorontsov
    Published:4 Nov 2009
    9.3
    Critical

    CVE-2009-3853

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7, 5.4 before 5.4.3, 5.5 before 5.5.2.2, and 6.1 before 6.1.0.2, and TSM Express 5.3.3.0 through 5.3.6.6, allows remote attackers to execute arbitrary code via crafted data in a TCP packet.

    Source:Metasploit
    Published:4 Nov 2009
    9.3
    Critical

    CVE-2009-3850

    Last Modified: 23 Apr 2026

    Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.

    Source:Core Security
    Published:6 Nov 2009
    10
    Critical

    CVE-2009-3849

    Last Modified: 6 Mar 2011

    Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long Template parameter to nnmRptConfig.exe, related to the strcat function; or (2) a long Oid parameter to snmp.exe.

    Source:Metasploit
    Published:10 Dec 2009
    10
    Critical

    CVE-2009-3844

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted MSG_PROTOCOL packet.

    Source:Metasploit
    Published:8 Dec 2009
    10
    Critical

    CVE-2009-3843

    Last Modified: 27 Oct 2016

    HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.manager.HTMLManagerServlet class to make requests to manager/html/upload.

    Source:Metasploit
    Published:24 Nov 2009
    5
    Medium

    CVE-2009-3840

    Last Modified: 23 Apr 2026

    The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service (daemon crash) via an invalid Error Code field in a packet.

    Source:Core Security
    Published:19 Nov 2009
    9.3
    Critical

    CVE-2009-3838

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.

    Source:Francis Provencher
    Published:2 Nov 2009