5
    Medium

    CVE-2009-2533

    Last Modified: 23 Apr 2026

    rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of service (daemon exit) via multiple RTSP SET_PARAMETER requests with empty DataConvertBuffer headers.

    Source:Core Security
    Published:20 Jul 2009
    10
    Critical

    CVE-2009-2532

    Last Modified: 9 Dec 2016

    Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SMBv2 packet to the Server service, aka "SMBv2 Command Value Vulnerability."

    Source:ohnozzy
    Published:14 Oct 2009
    7.8
    High

    CVE-2009-2526

    Last Modified: 9 Dec 2016

    Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka "SMBv2 Infinite Loop Vulnerability."

    Source:ohnozzy
    Published:14 Oct 2009
    5
    Medium

    CVE-2009-2521

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."

    Source:kingcope
    Published:4 Sept 2009
    9.3
    Critical

    CVE-2009-2514

    Last Modified: 23 Apr 2026

    win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."

    Source:H D Moore
    Published:11 Nov 2009
    7.5
    High

    CVE-2009-2511

    Last Modified: 9 May 2014

    Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows man-in-the-middle attackers to spoof arbitrary SSL servers and other entities via an X.509 certificate that has a malformed ASN.1 Object Identifier (OID) and was issued by a legitimate Certification Authority, aka "Integer Overflow in X.509 Object Identifiers Vulnerability."

    Source:Dan Kaminsky
    Published:14 Oct 2009
    9.3
    Critical

    CVE-2009-2485

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a .ht3 file.

    Source:Metasploit
    Published:16 Jul 2009
    9.3
    Critical

    CVE-2009-2484

    Last Modified: 23 Nov 2016

    Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.9, when running on Microsoft Windows, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long smb URI in a playlist file.

    Source:Trancer
    Published:16 Jul 2009
    7.8
    High

    CVE-2009-2479

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.

    Source:Andrew Haynes
    Published:14 Jul 2009
    5
    Medium

    CVE-2009-2478

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."

    Source:David Kennedy (ReL1K)
    Published:14 Jul 2009
    9.3
    Critical

    CVE-2009-2477

    Last Modified: 19 Dec 2016

    js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

    Source:Hacker Fantastic
    Published:14 Jul 2009
    4.3
    Medium

    CVE-2009-2473

    Last Modified: 23 Apr 2026

    neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Source:Peter Valchev
    Published:18 Aug 2009
    10
    Critical

    CVE-2009-2464

    Last Modified: 1 May 2014

    The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.

    Source:Christophe Charron
    Published:21 Jul 2009
    7.5
    High

    CVE-2009-2451

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in MIM:InfiniX 1.2.003 and possibly earlier versions allow remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters in a calendar action, or (3) a search term in the search form.

    Source:YEnH4ckEr
    Published:14 Jul 2009
    7.2
    High

    CVE-2009-2450

    Last Modified: 23 Apr 2026

    The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Personal Firewall 3.5 before 3.5.0.14, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\OAmon containing arbitrary kernel addresses, as demonstrated using the 0x830020C3 IOCTL.

    Source:NT Internals
    Published:13 Jul 2009
    8.5
    High

    CVE-2009-2446

    Last Modified: 29 Apr 2014

    Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0.0 through 5.0.83 allow remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in a database name in a (1) COM_CREATE_DB or (2) COM_DROP_DB request. NOTE: some of these details are obtained from third party information.

    Source:kingcope
    Published:9 Jul 2009
    5
    Medium

    CVE-2009-2443

    Last Modified: 14 Dec 2016

    Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Source:NoGe
    Published:13 Jul 2009
    4.3
    Medium

    CVE-2009-2442

    Last Modified: 29 Sept 2014

    Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a resultats-recherche action.

    Source:599eme Man
    Published:13 Jul 2009
    4.3
    Medium

    CVE-2009-2441

    Last Modified: 28 Sept 2014

    Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject arbitrary web script or HTML via the entry parameter.

    Source:Moudi
    Published:13 Jul 2009
    4.3
    Medium

    CVE-2009-2440

    Last Modified: 28 Sept 2014

    Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Moudi
    Published:13 Jul 2009
    7.5
    High

    CVE-2009-2439

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is not associated with alibaba.com or the Alibaba Group.

    Source:599eme Man
    Published:13 Jul 2009
    4.3
    Medium

    CVE-2009-2438

    Last Modified: 28 Apr 2014

    Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the text parameter in a list action. NOTE: this might overlap CVE-2008-1399.

    Source:599eme Man
    Published:13 Jul 2009
    4.3
    Medium

    CVE-2009-2437

    Last Modified: 28 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action.

    Source:599eme Man
    Published:13 Jul 2009
    7.5
    High

    CVE-2009-2436

    Last Modified: 2 Jan 2012

    SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Source:ITTIHACK
    Published:13 Jul 2009
    4.3
    Medium

    CVE-2009-2433

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.

    Source:Sberry
    Published:10 Jul 2009
    7.5
    High

    CVE-2009-2428

    Last Modified: 29 Sept 2014

    Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL commands via the (1) userid parameter to suchauftraege_user.php and the (2) descr parameter to vote.php; and other unspecified vectors.

    Source:Moudi
    Published:10 Jul 2009
    7.5
    High

    CVE-2009-2427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands via the emp_id parameter.

    Source:Moudi
    Published:10 Jul 2009
    4.3
    Medium

    CVE-2009-2424

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary web script or HTML via the mode parameter.

    Source:Moudi
    Published:10 Jul 2009
    7.5
    High

    CVE-2009-2423

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter in a list action.

    Source:Moudi
    Published:10 Jul 2009
    4.3
    Medium

    CVE-2009-2419

    Last Modified: 28 Apr 2014

    Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted HTML document that references a zero-length .js file and the JavaScript reload function. NOTE: some of these details are obtained from third party information.

    Source:SkyOut
    Published:9 Jul 2009
    9.3
    Critical

    CVE-2009-2403

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.

    Source:hack4love
    Published:9 Jul 2009
    7.5
    High

    CVE-2009-2402

    Last Modified: 20 Oct 2017

    SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a thread action, a different vector than CVE-2008-0355.

    Source:JosS
    Published:9 Jul 2009
    4.3
    Medium

    CVE-2009-2401

    Last Modified: 20 Oct 2017

    Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script or HTML via a forum post.

    Source:JosS
    Published:9 Jul 2009
    7.5
    High

    CVE-2009-2400

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:Chip d3 bi0s
    Published:9 Jul 2009
    6.8
    Medium

    CVE-2009-2399

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

    Source:Septemb0x
    Published:9 Jul 2009
    5
    Medium

    CVE-2009-2398

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.

    Source:ahmadbady
    Published:9 Jul 2009
    5
    Medium

    CVE-2009-2397

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter.

    Source:ThE g0bL!N
    Published:9 Jul 2009
    9.3
    Critical

    CVE-2009-2396

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.

    Source:Septemb0x
    Published:9 Jul 2009
    7.5
    High

    CVE-2009-2395

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter in an itemlist action to index.php.

    Source:Chip d3 bi0s
    Published:9 Jul 2009
    7.5
    High

    CVE-2009-2394

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

    Source:SecurityRules
    Published:9 Jul 2009
    6.5
    Medium

    CVE-2009-2393

    Last Modified: 23 Apr 2026

    admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to have an unknown impact via unspecified vectors.

    Source:HxH
    Published:9 Jul 2009
    7.5
    High

    CVE-2009-2392

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Source:HxH
    Published:9 Jul 2009
    4.3
    Medium

    CVE-2009-2391

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.

    Source:HxH
    Published:9 Jul 2009
    7.5
    High

    CVE-2009-2390

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter to index.php.

    Source:boom3rang
    Published:9 Jul 2009
    6.8
    Medium

    CVE-2009-2389

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.

    Source:jmp-esp
    Published:9 Jul 2009
    6.8
    Medium

    CVE-2009-2388

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the txtPassword parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Moudi
    Published:9 Jul 2009
    9.3
    Critical

    CVE-2009-2386

    Last Modified: 1 May 2014

    Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.

    Source:Diego Juarez
    Published:10 Jul 2009
    7.5
    High

    CVE-2009-2385

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the awardsMembers function in Sources/Profile.php in the Member Awards component 1.0.2 for Simple Machines Forum (SMF) allows remote attackers to execute arbitrary SQL commands via the id parameter in a profile action to index.php. NOTE: some of these details are obtained from third party information.

    Source:eLwaux
    Published:8 Jul 2009
    9.3
    Critical

    CVE-2009-2384

    Last Modified: 23 Apr 2026

    Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.

    Source:ThE g0bL!N
    Published:8 Jul 2009
    7.5
    High

    CVE-2009-2383

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BTE_RW_webajax.php in the Related Sites plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the guid parameter.

    Source:eLwaux
    Published:8 Jul 2009