5
    Medium

    CVE-2009-3151

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter.

    Source:GoLd_M
    Published:10 Sept 2009
    7.5
    High

    CVE-2009-3150

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands via the Browse parameter in a vote action.

    Source:SarBoT511
    Published:10 Sept 2009
    4.3
    Medium

    CVE-2009-3149

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the js parameter. NOTE: some of these details are obtained from third party information.

    Source:eLwaux
    Published:10 Sept 2009
    7.5
    High

    CVE-2009-3148

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to assignments.php.

    Source:SirGod
    Published:10 Sept 2009
    7.8
    High

    CVE-2009-3129

    Last Modified: 21 Aug 2010

    Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."

    Source:anonymous
    Published:11 Nov 2009
    5
    Medium

    CVE-2009-3124

    Last Modified: 3 Oct 2014

    Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter.

    Source:Securitylab.ir
    Published:9 Sept 2009
    5
    Medium

    CVE-2009-3123

    Last Modified: 3 Oct 2014

    Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter.

    Source:Inj3ct0r
    Published:9 Sept 2009
    7.5
    High

    CVE-2009-3119

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.

    Source:Inj3ct0r
    Published:9 Sept 2009
    7.5
    High

    CVE-2009-3117

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:Mr.SQL
    Published:9 Sept 2009
    7.5
    High

    CVE-2009-3116

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action.

    Source:Mr.SQL
    Published:9 Sept 2009
    5
    Medium

    CVE-2009-3115

    Last Modified: 23 Apr 2026

    SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information.

    Source:Gaurav Baruah
    Published:9 Sept 2009
    5
    Medium

    CVE-2009-3111

    Last Modified: 23 Apr 2026

    The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) via zero-length Tunnel-Password attributes, as demonstrated by a certain module in VulnDisco Pack Professional 7.6 through 8.11. NOTE: this is a regression error related to CVE-2003-0967.

    Source:Matthew Gillespie
    Published:7 Sept 2009
    10
    Critical

    CVE-2009-3103

    Last Modified: 23 Apr 2026

    Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via an & (ampersand) character in a Process ID High header field in a NEGOTIATE PROTOCOL REQUEST packet, which triggers an attempted dereference of an out-of-bounds memory location, aka "SMBv2 Negotiation Vulnerability." NOTE: some of these details are obtained from third party information.

    Source:Jelmer de Hen
    Published:8 Sept 2009
    10
    Critical

    CVE-2009-3099

    Last Modified: 6 May 2014

    Unspecified vulnerability in HP OpenView Operations Manager 8.1 on Windows Server 2003 SP2 allows remote attackers to have an unknown impact, related to a "Remote exploit," as demonstrated by a certain module in VulnDisco Pack Professional 8.11, a different vulnerability than CVE-2007-3872. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Source:Intevydis
    Published:8 Sept 2009
    7.5
    High

    CVE-2009-3082

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wcategory.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Mr.SQL
    Published:4 Sept 2009
    7.5
    High

    CVE-2009-3081

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the month parameter in a calendar action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Mr.SQL
    Published:4 Sept 2009
    9.3
    Critical

    CVE-2009-3076

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier for remote attackers to trick a user into installing or removing an arbitrary PKCS11 module.

    Source:Dan Kaminsky
    Published:9 Sept 2009
    9.3
    Critical

    CVE-2009-3068

    Last Modified: 6 May 2014

    Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute arbitrary code by uploading a Java Archive (.jsp) file during a PUBLISH action, then accessing it via a direct request to the file in the robohelp/robo/reserved/web directory under its sessionid subdirectory, as demonstrated by the vd_adobe module in VulnDisco Pack Professional 8.7 through 8.11.

    Source:Intevydis
    Published:4 Sept 2009
    4.3
    Medium

    CVE-2009-3066

    Last Modified: 30 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php.

    Source:Moudi
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3065

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the highlighter parameter.

    Source:RoMaNcYxHaCkEr
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3064

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _GET[filename] parameter.

    Source:CoBRa_21
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3063

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a gamepanel action to index.php.

    Source:v3n0m
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3062

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in message_box.php in OSI Codes PHP Live! 3.3 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.

    Source:v3n0m
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3061

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lesson.php in Alqatari Q R Script 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Source:Red-D3v1L
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3059

    Last Modified: 28 Aug 2014

    Multiple SQL injection vulnerabilities in Joker Board (aka JBoard) 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) core/select.php or (2) the city parameter to top_add.inc.php, reachable through sboard.php.

    Source:Inj3ct0r
    Published:3 Sept 2009
    9.3
    Critical

    CVE-2009-3058

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in akPlayer 1.9.0 allows remote attackers to execute arbitrary code via a long string in a .plt playlist file.

    Source:TiGeR-Dz
    Published:3 Sept 2009
    4.3
    Medium

    CVE-2009-3057

    Last Modified: 30 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in AOM Software Beex 3 allow remote attackers to inject arbitrary web script or HTML via the navaction parameter to (1) news.php and (2) partneralle.php.

    Source:Moudi
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3056

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[AdminPath] parameter.

    Source:CoBRa_21
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3055

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in engine/api/api.class.php in DataLife Engine (DLE) 8.2 allows remote attackers to execute arbitrary PHP code via a URL in the dle_config_api parameter.

    Source:Kurd-Team
    Published:3 Sept 2009
    7.5
    High

    CVE-2009-3054

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Artetics.com Art Portal (com_artportal) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the portalid parameter to index.php.

    Source:599eme Man
    Published:3 Sept 2009
    6.8
    Medium

    CVE-2009-3053

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter to the avatars page, reachable through index.php.

    Source:ByALBAYX
    Published:3 Sept 2009
    6.5
    Medium

    CVE-2009-3052

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB 3 allows remote authenticated users to execute arbitrary SQL commands via the prime_quick_style parameter to ucp.php.

    Source:-SmoG-
    Published:3 Sept 2009
    4.9
    Medium

    CVE-2009-3043

    Last Modified: 6 Sept 2016

    The tty_ldisc_hangup function in drivers/char/tty_ldisc.c in the Linux kernel 2.6.31-rc before 2.6.31-rc8 allows local users to cause a denial of service (system crash, sometimes preceded by a NULL pointer dereference) or possibly gain privileges via certain pseudo-terminal I/O activity, as demonstrated by KernelTtyTest.c.

    Source:Eric W. Biederman
    Published:2 Sept 2009
    7.5
    High

    CVE-2009-3042

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attackers to execute arbitrary SQL commands via the systemid parameter, a different vector than CVE-2009-3040.

    Source:Guilherme Marinheiro
    Published:11 Aug 2009
    7.5
    High

    CVE-2009-3041

    Last Modified: 23 Apr 2026

    SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which allows remote attackers to conduct unauthorized activities related to installation and backups, as exploited in the wild in August 2009.

    Source:Kernel_Panik
    Published:1 Sept 2009
    7.5
    High

    CVE-2009-3040

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attackers to execute arbitrary SQL commands via the (1) N, (2) DL, (3) O and (4) V parameters to download.php and the (5) SYSTEMID parameter to group_show.php.

    Source:Nico Leidecker
    Published:30 May 2009
    4.3
    Medium

    CVE-2009-3038

    Last Modified: 23 Apr 2026

    A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBerry Desktop Manager 5.0.0.11 allows remote attackers to cause a denial of service (Internet Explorer crash) by referencing the control's CLSID in the classid attribute of an OBJECT element.

    Source:Francis Provencher
    Published:1 Sept 2009
    4.3
    Medium

    CVE-2009-3036

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published:23 Feb 2010
    9.3
    Critical

    CVE-2009-3033

    Last Modified: 10 Mar 2011

    Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.

    Source:Metasploit
    Published:25 Nov 2009
    9.3
    Critical

    CVE-2009-3031

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.

    Source:Nikolas Sotiriu
    Published:3 Nov 2009
    6.8
    Medium

    CVE-2009-3028

    Last Modified: 10 Mar 2011

    The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method.

    Source:Metasploit
    Published:7 Mar 2011
    9
    Critical

    CVE-2009-3023

    Last Modified: 27 Oct 2016

    Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authenticated users to execute arbitrary code via a crafted NLST (NAME LIST) command that uses wildcards, leading to memory corruption, aka "IIS FTP Service RCE and DoS Vulnerability."

    Source:muts
    Published:31 Aug 2009
    7.1
    High

    CVE-2009-3020

    Last Modified: 23 Apr 2026

    win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.

    Source:webDEViL
    Published:31 Aug 2009
    5
    Medium

    CVE-2009-3019

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls createElement to create an instance of the LI element, and then calls setAttribute to set the value attribute.

    Source:Irfan Asrar
    Published:31 Aug 2009
    4.9
    Medium

    CVE-2009-3002

    Last Modified: 23 Apr 2026

    The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows local users to read the contents of some kernel memory locations by calling getsockname on (1) an AF_APPLETALK socket, related to the atalk_getname function in net/appletalk/ddp.c; (2) an AF_IRDA socket, related to the irda_getname function in net/irda/af_irda.c; (3) an AF_ECONET socket, related to the econet_getname function in net/econet/af_econet.c; (4) an AF_NETROM socket, related to the nr_getname function in net/netrom/af_netrom.c; (5) an AF_ROSE socket, related to the rose_getname function in net/rose/af_rose.c; or (6) a raw CAN socket, related to the raw_getname function in net/can/raw.c.

    Source:Clément Lecigne
    Published:23 Aug 2009
    4.9
    Medium

    CVE-2009-3001

    Last Modified: 4 Sept 2016

    The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.

    Source:Jon Oberheide
    Published:23 Aug 2009
    9.3
    Critical

    CVE-2009-2994

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.

    Source:Felipe Andres Manzano
    Published:13 Oct 2009
    9.3
    Critical

    CVE-2009-2990

    Last Modified: 22 Nov 2017

    Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow attackers to execute arbitrary code via unspecified vectors.

    Source:Felipe Andres Manzano
    Published:13 Oct 2009
    9.3
    Critical

    CVE-2009-2983

    Last Modified: 13 Oct 2017

    Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

    Source:Skylined
    Published:13 Oct 2009
    4.3
    Medium

    CVE-2009-2966

    Last Modified: 23 Apr 2026

    avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of service (CPU consumption and network connectivity loss) via an HTTP URL request that contains a large number of dot "." characters.

    Source:Prakhar Prasad
    Published:25 Aug 2009