9.3
    Critical

    CVE-2009-3338

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EffectMatrix (E.M.) Magic Morph 1.95b allows remote attackers to execute arbitrary code via a long string in a .mor file.

    Source:fl0 fl0w
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3336

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL commands via the auction_id parameter.

    Source:NoGe
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3335

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TurtuShout component 0.11 for Joomla! allows remote attackers to execute arbitrary SQL commands via the Name field.

    Source:jdc
    Published:24 Sept 2009
    7.5
    High

    CVE-2009-3334

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Lhacky! Extensions Cave Joomla! Integrated Newsletters Component (aka JINC or com_jinc) component 0.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a messages action to index.php.

    Source:Chip d3 bi0s
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3333

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Don Tukulesto
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3332

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JBudgetsMagic (com_jbudgetsmagic) component 0.3.2 through 0.4.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the bid parameter in a mybudget action to index.php.

    Source:kaMtiEz
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3331

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the wwwRoot parameter to (1) header.php, (2) submit.php, (3) submitted.php, and (4) autosubmitter/index.php.

    Source:HxH
    Published:23 Sept 2009
    6.8
    Medium

    CVE-2009-3330

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in cP Creator 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the tickets parameter in a support ticket action.

    Source:Sina Yazdanmehr
    Published:23 Sept 2009
    4.3
    Medium

    CVE-2009-3328

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sign.php in WX-Guestbook 1.1.208 allows remote attackers to inject arbitrary web script or HTML via the sName parameter (aka the name field). NOTE: some of these details are obtained from third party information.

    Source:learn3r
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3327

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in WX-Guestbook 1.1.208 allow remote attackers to execute arbitrary SQL commands via the (1) QUERY parameter to search.php and (2) USERNAME parameter to login.php. NOTE: some of these details are obtained from third party information.

    Source:learn3r
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3326

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMScontrol Content Management System 7.x allows remote attackers to execute arbitrary SQL commands via the id_menu parameter.

    Source:ph1l1ster
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3325

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Focusplus Developments Survey Manager (com_surveymanager) component 1.5.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the stype parameter in an editsurvey action to index.php.

    Source:kaMtiEz
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3324

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/prodler.class.php in ProdLer 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sPath parameter.

    Source:cr4wl3r
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3323

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BAnner ROtation System mini (BAROSmini) 0.32.595 allow remote attackers to execute arbitrary PHP code via a URL in the baros_path parameter to (1) include/common_functions.php, and the main_path parameter to (2) lib_users.php, (3) lib_stats.php, and (4) lib_slots.php in include/lib/.

    Source:EA Ngel
    Published:23 Sept 2009
    7.8
    High

    CVE-2009-3322

    Last Modified: 23 Apr 2026

    The Siemens Gigaset SE361 WLAN router allows remote attackers to cause a denial of service (device reboot) via a flood of crafted TCP packets to port 1723.

    Source:crashbrz
    Published:23 Sept 2009
    6.8
    Medium

    CVE-2009-3321

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SaphpLesson 4.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the CLIENT_IP HTTP header.

    Source:Jafer Al Zidjali
    Published:23 Sept 2009
    4.3
    Medium

    CVE-2009-3320

    Last Modified: 28 Aug 2014

    Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Moudi
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3318

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote attackers to access arbitrary directories and have unspecified other impact via a .. (dot dot) in the target parameter to index.php.

    Source:DreamTurk
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3317

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to execute arbitrary PHP code via a URL in the path parameter, a different vector than CVE-2008-0648.

    Source:EA Ngel
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3316

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a propertycpanel action to index.php.

    Source:Chip d3 bi0s
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3315

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.

    Source:learn3r hacker
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3314

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL commands via the platform parameter.

    Source:snakespc
    Published:23 Sept 2009
    6.5
    Medium

    CVE-2009-3313

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the comp parameter to (1) index.php and (2) editComments.php, and (3) allow remote authenticated administrators to execute arbitrary SQL commands via the id parameter in a comment action to edit.php.

    Source:learn3r hacker
    Published:23 Sept 2009
    6.8
    Medium

    CVE-2009-3312

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a crafted URL in the include_class parameter.

    Source:cr4wl3r
    Published:23 Sept 2009
    4.3
    Medium

    CVE-2009-3311

    Last Modified: 28 Aug 2014

    Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Moudi
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3310

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the album_id parameter in an AlbumSongs action.

    Source:snakespc
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3309

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a ViewDetails action, a different vector than CVE-2008-6320.

    Source:learn3r hacker
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3308

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.

    Source:(In)Security Romania
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3307

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code via a URL in the FSPHP_LIB parameter to (1) FSphp.php, (2) navigation.php, and (3) pathwrite.php in lib/.

    Source:NoGe
    Published:23 Sept 2009
    7.5
    High

    CVE-2009-3306

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter.

    Source:EA Ngel
    Published:23 Sept 2009
    5
    Medium

    CVE-2009-3305

    Last Modified: 23 Apr 2026

    Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.

    Source:Jeremy Brown
    Published:24 Dec 2009
    7.2
    High

    CVE-2009-3281

    Last Modified: 23 Apr 2026

    The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.

    Source:mu-b
    Published:16 Oct 2009
    5
    Medium

    CVE-2009-3272

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences.

    Source:Jeremy Brown
    Published:21 Sept 2009
    4.3
    Medium

    CVE-2009-3271

    Last Modified: 23 Apr 2026

    Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel: URL in the SRC attribute of an IFRAME element.

    Source:cloud
    Published:21 Sept 2009
    5
    Medium

    CVE-2009-3270

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Source:Dr_IDE
    Published:18 Sept 2009
    4.3
    Medium

    CVE-2009-3260

    Last Modified: 28 Aug 2014

    Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the header of the topic in a comment.

    Source:Inj3ct0r
    Published:18 Sept 2009
    4.3
    Medium

    CVE-2009-3256

    Last Modified: 28 Aug 2014

    Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTML via the URI, as demonstrated by a SCRIPT element in an arbitrary parameter such as the asd parameter.

    Source:Inj3ct0r
    Published:18 Sept 2009
    9.3
    Critical

    CVE-2009-3254

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.

    Source:hack4love
    Published:18 Sept 2009
    9.3
    Critical

    CVE-2009-3253

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.

    Source:hack4love
    Published:18 Sept 2009
    7.5
    High

    CVE-2009-3252

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL commands via the (1) year and (2) id parameters.

    Source:Affix
    Published:18 Sept 2009
    9
    Critical

    CVE-2009-3250

    Last Modified: 4 Oct 2017

    The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.

    Source:USH
    Published:18 Sept 2009
    7.5
    High

    CVE-2009-3249

    Last Modified: 4 Oct 2017

    Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the module parameter to graph.php; or the (2) module or (3) file parameter to include/Ajax/CommonAjax.php, reachable through modules/Campaigns/CampaignsAjax.php, modules/SalesOrder/SalesOrderAjax.php, modules/System/SystemAjax.php, modules/Products/ProductsAjax.php, modules/uploads/uploadsAjax.php, modules/Dashboard/DashboardAjax.php, modules/Potentials/PotentialsAjax.php, modules/Notes/NotesAjax.php, modules/Faq/FaqAjax.php, modules/Quotes/QuotesAjax.php, modules/Utilities/UtilitiesAjax.php, modules/Calendar/ActivityAjax.php, modules/Calendar/CalendarAjax.php, modules/PurchaseOrder/PurchaseOrderAjax.php, modules/HelpDesk/HelpDeskAjax.php, modules/Invoice/InvoiceAjax.php, modules/Accounts/AccountsAjax.php, modules/Reports/ReportsAjax.php, modules/Contacts/ContactsAjax.php, and modules/Portal/PortalAjax.php; and allow remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the step parameter in an Import action to the (4) Accounts, (5) Contacts, (6) HelpDesk, (7) Leads, (8) Potentials, (9) Products, or (10) Vendors module, reachable through index.php and related to modules/Import/index.php and multiple Import.php files.

    Source:TecR0c
    Published:18 Sept 2009
    6.8
    Medium

    CVE-2009-3248

    Last Modified: 4 Oct 2017

    Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.

    Source:USH
    Published:18 Sept 2009
    4.3
    Medium

    CVE-2009-3247

    Last Modified: 4 Oct 2017

    Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php. NOTE: the query_string vector is already covered by CVE-2008-3101.3.

    Source:USH
    Published:18 Sept 2009
    7.5
    High

    CVE-2009-3246

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL commands via the id parameter in an spnews action to the default URI. NOTE: some of these details are obtained from third party information.

    Source:HxH
    Published:18 Sept 2009
    9.3
    Critical

    CVE-2009-3244

    Last Modified: 27 Oct 2016

    Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long PlayerVersion property value.

    Source:Francis Provencher
    Published:18 Sept 2009
    5
    Medium

    CVE-2009-3243

    Last Modified: 8 May 2014

    Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote attackers to cause a denial of service (application crash) via unknown vectors related to TLS 1.2 conversations.

    Source:Buildbot Builder
    Published:18 Sept 2009
    5
    Medium

    CVE-2009-3242

    Last Modified: 8 May 2014

    Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors related to "an uninitialized dissector handle," which triggers an assertion failure.

    Source:Buildbot Builder
    Published:13 Aug 2009
    7.8
    High

    CVE-2009-3241

    Last Modified: 8 May 2014

    Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via malformed OPCUA Service CallRequest packets.

    Source:Buildbot Builder
    Published:6 Sept 2009
    4.9
    Medium

    CVE-2009-3234

    Last Modified: 8 May 2014

    Buffer overflow in the perf_copy_attr function in kernel/perf_counter.c in the Linux kernel 2.6.31-rc1 allows local users to cause a denial of service (crash) and execute arbitrary code via a "big size data" to the perf_counter_open system call.

    Source:Xiao Guangrong
    Published:17 Sept 2009