9.3
    Critical

    CVE-2009-3837

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message.

    Source:Francis Provencher
    Published:2 Nov 2009
    7.5
    High

    CVE-2009-3835

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.

    Source:Don Tukulesto
    Published:2 Nov 2009
    4.3
    Medium

    CVE-2009-3833

    Last Modified: 12 May 2014

    Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Source:blake
    Published:2 Nov 2009
    5
    Medium

    CVE-2009-3830

    Last Modified: 23 Apr 2026

    The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.

    Source:Daniel Martin
    Published:30 Oct 2009
    5
    Medium

    CVE-2009-3828

    Last Modified: 23 Apr 2026

    The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.

    Source:Andrea Fabrizi
    Published:30 Oct 2009
    7.5
    High

    CVE-2009-3825

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in GenCMS 2006 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) p parameter to show.php and the (2) Template parameter to admin/pages/SiteNew.php.

    Source:eLwaux
    Published:28 Oct 2009
    7.5
    High

    CVE-2009-3824

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content_path parameter.

    Source:Khashayar Fereidani
    Published:28 Oct 2009
    4.3
    Medium

    CVE-2009-3823

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in myhtml.php in Mobilelib GOLD 3.0, when magic_quotes_gpc is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the GLOBALS[page] parameter.

    Source:Qabandi
    Published:28 Oct 2009
    7.5
    High

    CVE-2009-3822

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php.

    Source:kaMtiEz
    Published:28 Oct 2009
    7.5
    High

    CVE-2009-3817

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in doc/releasenote.php in the BookLibrary (com_booklibrary) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter, a different vector than CVE-2009-2637. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:kaMtiEz
    Published:28 Oct 2009
    9.3
    Critical

    CVE-2009-3812

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in OtsAV DJ trial version 1.85.64.0, Radio trial version 1.85.64.0, TV trial version 1.85.64.0, and Free version 1.77.001 allows remote attackers to execute arbitrary code via a long playlist in an Ots File List (.ofl) file.

    Source:hack4love
    Published:27 Oct 2009
    9.3
    Critical

    CVE-2009-3811

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information.

    Source:LiquidWorm
    Published:27 Oct 2009
    9.3
    Critical

    CVE-2009-3810

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.

    Source:D3V!L FUCK3R
    Published:27 Oct 2009
    4.3
    Medium

    CVE-2009-3809

    Last Modified: 23 Apr 2026

    Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long string in a .sgp playlist file.

    Source:prodigy
    Published:27 Oct 2009
    9.3
    Critical

    CVE-2009-3808

    Last Modified: 23 Apr 2026

    MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an .mp3 playlist file.

    Source:prodigy
    Published:27 Oct 2009
    9.3
    Critical

    CVE-2009-3807

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.

    Source:hack4love
    Published:27 Oct 2009
    7.5
    High

    CVE-2009-3806

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.

    Source:Securitylab Security Research
    Published:27 Oct 2009
    4.3
    Medium

    CVE-2009-3805

    Last Modified: 23 Apr 2026

    gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a long certificate signature.

    Source:Dr_IDE
    Published:27 Oct 2009
    6.5
    Medium

    CVE-2009-3804

    Last Modified: 12 May 2014

    Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.

    Source:Nine:Situations:Group::bookoo
    Published:27 Oct 2009
    4.3
    Medium

    CVE-2009-3803

    Last Modified: 29 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the status_message parameter to (1) /news, (2) /comment, (3) /forum, (4) /blog, and (5) /tags; the status_message parameter to (6) forum.php, (7) discussion.php, (8) guestbook.php, (9) blog.php, (10) news.php, (11) srv_updates.php, (12) srv_backups.php, (13) srv_twist_prevention.php, (14) srv_tags.php, (15) srv_tags_reindex.php, (16) google_sitemap.php, (17) sitemap_history.php, (18) srv_options.php, (19) locales.php and (20) plugins_wizard.php in _admin/; a crafted IMG BBcode tag in the message body of a (21) forum, (22) guestbook, or (23) comment; (24) the content of an avatar file, which is not properly handled by Internet Explorer; and (25) the loginname parameter (aka username) in _admin/index.php.

    Source:Vladimir Vorontsov
    Published:27 Oct 2009
    5
    Medium

    CVE-2009-3802

    Last Modified: 19 Oct 2017

    Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.

    Source:Vladimir Vorontsov
    Published:27 Oct 2009
    4.3
    Medium

    CVE-2009-3789

    Last Modified: 11 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.

    Source:Amol Naik
    Published:26 Oct 2009
    5
    Medium

    CVE-2009-3787

    Last Modified: 23 Apr 2026

    files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files via the file parameter with "logs/" in between two . (dot) characters, which is filtered into a "../" sequence.

    Source:Janek Vind
    Published:26 Oct 2009
    7.5
    High

    CVE-2009-3760

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.

    Source:Secure Network
    Published:22 Oct 2009
    8.8
    High

    CVE-2009-3759

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information.

    Source:Secure Network
    Published:22 Oct 2009
    7.5
    High

    CVE-2009-3758

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Source:Secure Network
    Published:22 Oct 2009
    4.3
    Medium

    CVE-2009-3757

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php. NOTE: some of these details are obtained from third party information.

    Source:Secure Network
    Published:22 Oct 2009
    5
    Medium

    CVE-2009-3756

    Last Modified: 23 Apr 2026

    phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message.

    Source:eLwaux
    Published:22 Oct 2009
    4.3
    Medium

    CVE-2009-3755

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php; and the PATH_INFO to (3) modules_view.php, (4) tabledefs_options.php, and (5) adminsettings.php in phpbms\modules\base\.

    Source:eLwaux
    Published:22 Oct 2009
    7.5
    High

    CVE-2009-3754

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action to advancedsearch.php.

    Source:eLwaux
    Published:22 Oct 2009
    7.5
    High

    CVE-2009-3753

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.

    Source:LMaster
    Published:22 Oct 2009
    7.5
    High

    CVE-2009-3752

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the genres_parent parameter.

    Source:LMaster
    Published:22 Oct 2009
    4.3
    Medium

    CVE-2009-3751

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script or HTML via the genres_parent parameter.

    Source:LMaster
    Published:22 Oct 2009
    7.5
    High

    CVE-2009-3750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the idm parameter.

    Source:darkjoker
    Published:22 Oct 2009
    5
    Medium

    CVE-2009-3749

    Last Modified: 23 Apr 2026

    The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allows remote attackers to cause a denial of service (crash) by sending a HTTP GET request to TCP port 8181 and closing the socket before the service can send a response.

    Source:Nikolas Sotiriu
    Published:22 Oct 2009
    4.3
    Medium

    CVE-2009-3748

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7.1 before Hotfix 4 allow remote attackers to inject arbitrary web script or HTML via the (1) FileName, (2) IsolatedMessageID, (3) ServerName, (4) Dictionary, (5) Scoring, and (6) MessagePart parameters to web/msgList/viewmsg/actions/msgAnalyse.asp; the (7) Queue, (8) FileName, (9) IsolatedMessageID, and (10) ServerName parameters to actions/msgForwardToRiskFilter.asp and viewHeaders.asp in web/msgList/viewmsg/; and (11) the subject in an e-mail message that is held in a Queue.

    Source:Nikolas Sotiriu
    Published:22 Oct 2009
    4.3
    Medium

    CVE-2009-3747

    Last Modified: 30 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter. NOTE: this was originally reported for tbmnet.php, but that program does not exist in the TBmnetCMS 1.0 distribution.

    Source:drunken danish rednecks
    Published:22 Oct 2009
    5
    Medium

    CVE-2009-3744

    Last Modified: 23 Apr 2026

    rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted packet to TCP port 7144.

    Source:bellick
    Published:22 Oct 2009
    5
    Medium

    CVE-2009-3733

    Last Modified: 12 May 2014

    Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.

    Source:Justin Morehouse
    Published:2 Nov 2009
    10
    Critical

    CVE-2009-3732

    Last Modified: 11 Apr 2025

    Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Alexey Sintsov
    Published:12 Apr 2010
    4.3
    Medium

    CVE-2009-3730

    Last Modified: 11 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM Rational RequisitePro 7.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the operation parameter to ReqWebHelp/advanced/workingSet.jsp, or the (2) searchWord, (3) maxHits, (4) scopedSearch, or (5) scope parameter to ReqWebHelp/basic/searchView.jsp.

    Source:IBM
    Published:20 Oct 2009
    7.8
    High

    CVE-2009-3726

    Last Modified: 23 Apr 2026

    The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.

    Source:Simon Vallet
    Published:22 Oct 2008
    4.3
    Medium

    CVE-2009-3719

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in comment.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to inject arbitrary web script or HTML via a comment.

    Source:$qL_DoCt0r
    Published:16 Oct 2009
    7.5
    High

    CVE-2009-3718

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/authenticate.asp in Battle Blog 1.25 and 1.30 build 2 allows remote attackers to execute arbitrary SQL commands via the UserName parameter.

    Source:$qL_DoCt0r
    Published:16 Oct 2009
    9.3
    Critical

    CVE-2009-3717

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:16 Oct 2009
    6.5
    Medium

    CVE-2009-3716

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in smilies/.

    Source:SirGod
    Published:16 Oct 2009
    6.8
    Medium

    CVE-2009-3715

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:SirGod
    Published:16 Oct 2009
    4.3
    Medium

    CVE-2009-3714

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin_login.php in MCshoutbox 1.1 allows remote attackers to inject arbitrary web script or HTML via the loginerror parameter.

    Source:SirGod
    Published:16 Oct 2009
    7.5
    High

    CVE-2009-3713

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fichero.php in MorcegoCMS 1.7.6 and earlier allows remote attackers to execute arbitrary SQL commands via the query string.

    Source:darkjoker
    Published:16 Oct 2009
    7.5
    High

    CVE-2009-3712

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.

    Source:MizoZ
    Published:16 Oct 2009