9.3
    Critical

    CVE-2009-3577

    Last Modified: 9 May 2014

    Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."

    Source:Sebastian Tello
    Published:24 Nov 2009
    9.3
    Critical

    CVE-2009-3576

    Last Modified: 23 Apr 2026

    Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene package containing a Scene Table of Contents (aka .scntoc) file with a Script_Content element, as demonstrated by code that loads the WScript.Shell ActiveX control.

    Source:Core Security
    Published:24 Nov 2009
    9.3
    Critical

    CVE-2009-3574

    Last Modified: 23 Apr 2026

    Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long File1 argument in a .pls playlist file, possibly a buffer overflow.

    Source:zAx
    Published:6 Oct 2009
    9.3
    Critical

    CVE-2009-3573

    Last Modified: 10 Oct 2016

    Multiple insecure method vulnerabilities in the PDIControl.PDI.1 ActiveX control (PDIControl.dll) 2.2.3160.0 in EMC Captiva PixTools Distributed Imaging 2.2 allow remote attackers to create or overwrite arbitrary files via the (1) SetLogFileName and (2) WriteToLog methods.

    Source:Giuseppe Fuggiano
    Published:6 Oct 2009
    4.3
    Medium

    CVE-2009-3566

    Last Modified: 14 May 2014

    McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie header for the session identifier, which allows remote attackers to hijack a session by leveraging a cross-site scripting (XSS) vulnerability.

    Source:Daniel King
    Published:13 Nov 2009
    4.3
    Medium

    CVE-2009-3565

    Last Modified: 14 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in intruvert/jsp/module/Login.jsp in McAfee IntruShield Network Security Manager (NSM) before 5.1.11.6 allow remote attackers to inject arbitrary web script or HTML via the (1) iaction or (2) node parameter.

    Source:Daniel King
    Published:13 Nov 2009
    2.6
    Low

    CVE-2009-3562

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Xerver HTTP Server 4.32 allows remote attackers to inject arbitrary web script or HTML via the currentPath parameter in a chooseDirectory action.

    Source:Stack
    Published:5 Oct 2009
    5
    Medium

    CVE-2009-3561

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Xerver HTTP Server 4.32 allows remote attackers to read arbitrary files via a full pathname with a drive letter in the currentPath parameter in a chooseDirectory action.

    Source:Stack
    Published:5 Oct 2009
    9.8
    Critical

    CVE-2009-3555

    Last Modified: 27 May 2026

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.

    Source:Dan Kaminsky
    Published:5 Nov 2009
    7.5
    High

    CVE-2009-3548

    Last Modified: 27 Oct 2016

    The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.

    Source:Metasploit
    Published:12 Nov 2009
    7
    High

    CVE-2009-3547

    Last Modified: 10 May 2019

    Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname.

    Source:Matthew Bergin
    Published:14 Oct 2009
    4
    Medium

    CVE-2009-3545

    Last Modified: 23 Apr 2026

    DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.

    Source:PLATEN
    Published:5 Oct 2009
    5
    Medium

    CVE-2009-3544

    Last Modified: 23 Apr 2026

    Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.

    Source:Dr_IDE
    Published:5 Oct 2009
    7.5
    High

    CVE-2009-3543

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).

    Source:Khashayar Fereidani
    Published:2 Oct 2009
    7.5
    High

    CVE-2009-3542

    Last Modified: 24 Oct 2016

    Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Source:Eolas_Gadai
    Published:2 Oct 2009
    7.5
    High

    CVE-2009-3541

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter.

    Source:Khashayar Fereidani
    Published:2 Oct 2009
    4.3
    Medium

    CVE-2009-3539

    Last Modified: 23 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.

    Source:Moudi
    Published:2 Oct 2009
    9.3
    Critical

    CVE-2009-3536

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in EpicDJSoftware EpicVJ 1.2.8.0 and 1.3.1.2 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a (1) .m3u or (2) .mpl playlist file.

    Source:hack4love
    Published:2 Oct 2009
    4.3
    Medium

    CVE-2009-3535

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in image.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the researcher also suggests an analogous PHP remote file inclusion vulnerability, but this may be incorrect.

    Source:MizoZ
    Published:2 Oct 2009
    6.8
    Medium

    CVE-2009-3534

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Source:MoDaMeR
    Published:2 Oct 2009
    7.5
    High

    CVE-2009-3531

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Mr.tro0oqy
    Published:2 Oct 2009
    4.3
    Medium

    CVE-2009-3530

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in storefront.php in RadScripts RadBids Gold 4 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

    Source:Moudi
    Published:2 Oct 2009
    6.8
    Medium

    CVE-2009-3529

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RadScripts RadBids Gold 4 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action, a different vector than CVE-2005-1074.

    Source:Moudi
    Published:2 Oct 2009
    6.5
    Medium

    CVE-2009-3528

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.

    Source:Monster-Dz
    Published:2 Oct 2009
    6.9
    Medium

    CVE-2009-3527

    Last Modified: 23 Apr 2026

    Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (crash) or gain privileges via vectors related to kqueues, which triggers a use after free, leading to a NULL pointer dereference or memory corruption.

    Source:Przemyslaw Frasunek
    Published:6 Oct 2009
    7.2
    High

    CVE-2009-3525

    Last Modified: 9 May 2014

    The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest's kernel boot parameters without providing the expected password.

    Source:Jan Lieskovsky
    Published:25 Aug 2009
    6.9
    Medium

    CVE-2009-3523

    Last Modified: 23 Apr 2026

    aavmKer4.sys in avast! Home and Professional for Windows before 4.8.1356 does not properly validate input to IOCTLs (1) 0xb2d6000c and (2) 0xb2d60034, which allows local users to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption, a different vulnerability than CVE-2008-1625.

    Source:ryujin
    Published:1 Oct 2009
    7.2
    High

    CVE-2009-3522

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other versions before 4.8.1356, allows local users to cause a denial of service (system crash) and possibly gain privileges via a crafted IOCTL request to IOCTL 0xb2c80018.

    Source:Giuseppe
    Published:1 Oct 2009
    9.3
    Critical

    CVE-2009-3518

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname.

    Source:bruiser
    Published:1 Oct 2009
    6.5
    Medium

    CVE-2009-3515

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dnet_admin/index.php in d.net CMS allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the type parameter.

    Source:SirGod
    Published:1 Oct 2009
    6.5
    Medium

    CVE-2009-3514

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in d.net CMS allow remote attackers to execute arbitrary SQL commands via (1) the page parameter to index.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (2) edit_id and (3) _p parameter in a news action to dnet_admin/index.php.

    Source:SirGod
    Published:1 Oct 2009
    4.3
    Medium

    CVE-2009-3513

    Last Modified: 23 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php.

    Source:Moudi
    Published:1 Oct 2009
    4.3
    Medium

    CVE-2009-3512

    Last Modified: 23 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.

    Source:Moudi
    Published:1 Oct 2009
    7.5
    High

    CVE-2009-3511

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php.

    Source:SirGod
    Published:1 Oct 2009
    7.5
    High

    CVE-2009-3510

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.

    Source:NoGe
    Published:1 Oct 2009
    4.3
    Medium

    CVE-2009-3509

    Last Modified: 23 Sept 2014

    Cross-site scripting (XSS) vulnerability in admin/admin_index.php in CJ Dynamic Poll PRO 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Moudi
    Published:1 Oct 2009
    6
    Medium

    CVE-2009-3508

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and the (2) url parameter to install/install.php; and allow remote authenticated administrators to read arbitrary files via a .. (dot dot) in the (3) _htmlfile parameter to admin.php.

    Source:SirGod
    Published:1 Oct 2009
    7.5
    High

    CVE-2009-3507

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules.php in CMSphp 0.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod_file parameter.

    Source:SirGod
    Published:1 Oct 2009
    4.3
    Medium

    CVE-2009-3506

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.

    Source:SirGod
    Published:1 Oct 2009
    7.5
    High

    CVE-2009-3504

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Easy Laster
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3503

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters.

    Source:OoN Boy
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3502

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.

    Source:OoN Boy
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3500

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BPowerHouse BPGames 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to main.php and (2) game_id parameter to game.php.

    Source:OoN Boy
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3499

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in employee.aspx in BPowerHouse BPLawyerCaseDocuments 1.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:OoN Boy
    Published:30 Sept 2009
    4.3
    Medium

    CVE-2009-3496

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to inject arbitrary web script or HTML via the mag_id parameter.

    Source:OoN_Boy
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3495

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_mag.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the mag_id parameter, a different vector than CVE-2008-4465.

    Source:OoN_Boy
    Published:30 Sept 2009
    6.8
    Medium

    CVE-2009-3494

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a delete_category action, (2) the name parameter in an update_category action, and other vectors.

    Source:Salvatore Fresta
    Published:30 Sept 2009
    4.3
    Medium

    CVE-2009-3493

    Last Modified: 28 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) scrivi.php and (2) index.php.

    Source:Moudi
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3492

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pathToIndex parameter to (1) Calendar.php, (2) Comment.php, (3) Rss.php and (4) Trackback.php in lib/Loggix/Module/; and (5) modules/downloads/lib/LM_Downloads.php.

    Source:cr4wl3r
    Published:30 Sept 2009
    7.5
    High

    CVE-2009-3491

    Last Modified: 8 May 2014

    SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php.

    Source:kaMtiEz
    Published:30 Sept 2009