7.5
    High

    CVE-2009-1910

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands via the AlbumId parameter.

    Source:YEnH4ckEr
    Published:4 Jun 2009
    4.3
    Medium

    CVE-2009-1907

    Last Modified: 23 Apr 2014

    Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

    Source:Gerendi Sandor Attila
    Published:4 Jun 2009
    5
    Medium

    CVE-2009-1904

    Last Modified: 23 Apr 2026

    The BigDecimal library in Ruby 1.8.6 before p369 and 1.8.7 before p173 allows context-dependent attackers to cause a denial of service (application crash) via a string argument that represents a large number, as demonstrated by an attempted conversion to the Float data type.

    Published:10 Jun 2009
    5
    Medium

    CVE-2009-1902

    Last Modified: 23 Apr 2026

    The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference.

    Source:Juan Galiana Lara
    Published:3 Jun 2009
    6.9
    Medium

    CVE-2009-1897

    Last Modified: 1 May 2014

    The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894.

    Source:Christian Borntraeger
    Published:9 Apr 2009
    7.2
    High

    CVE-2009-1894

    Last Modified: 23 Apr 2026

    Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BIND_NOW to 1, and then calling execv on the target of the /proc/self/exe symlink.

    Source:anonymous
    Published:16 Jul 2009
    9.3
    Critical

    CVE-2009-1886

    Last Modified: 27 Apr 2014

    Multiple format string vulnerabilities in client/client.c in smbclient in Samba 3.2.0 through 3.2.12 might allow context-dependent attackers to execute arbitrary code via format string specifiers in a filename.

    Source:Jeremy Allison
    Published:23 Jun 2009
    2.6
    Low

    CVE-2009-1879

    Last Modified: 5 May 2014

    Cross-site scripting (XSS) vulnerability in index.template.html in the express-install templates in the SDK in Adobe Flex before 3.4, when the installed Flash version is older than a specified requiredMajorVersion value, allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:Adam Bixby
    Published:21 Aug 2009
    4
    Medium

    CVE-2009-1873

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4 Updater 7 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the logfile parameter.

    Source:DSecRG
    Published:18 Aug 2009
    4.3
    Medium

    CVE-2009-1872

    Last Modified: 4 May 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe ColdFusion Server 8.0.1, 8, and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the startRow parameter to administrator/logviewer/searchlog.cfm, or the query string to (2) wizards/common/_logintowizard.cfm, (3) wizards/common/_authenticatewizarduser.cfm, or (4) administrator/enter.cfm.

    Source:Alexander Polyakov
    Published:18 Aug 2009
    9.3
    Critical

    CVE-2009-1869

    Last Modified: 1 May 2014

    Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an AVM2 file with a large intrf_count value that triggers a dereference of an out-of-bounds pointer.

    Source:Roee Hay
    Published:30 Jul 2009
    9.3
    Critical

    CVE-2009-1868

    Last Modified: 30 Apr 2014

    Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing.

    Source:iDefense
    Published:30 Jul 2009
    7.5
    High

    CVE-2009-1854

    Last Modified: 23 Apr 2026

    Million Dollar Text Links 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the userid cookie to 1.

    Source:HxH
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1853

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.

    Source:cOndemned
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1852

    Last Modified: 30 Dec 2016

    Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.

    Source:ThE g0bL!N
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1850

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpBugTracker 1.0.3 allows remote attackers to execute arbitrary SQL commands via the password parameter.

    Source:ByALBAYX
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1848

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a groupdetail action to index.php.

    Source:Chip d3 bi0s
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1847

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Easy PX 41 CMS 9.0 B1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the fiche parameter.

    Source:ThE g0bL!N
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1846

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in SiteX 0.7.4 Build 418 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the THEME_FOLDER parameter to (1) Corporate/homepage.php, (2) Fusion/homepage.php, (3) Joombo/homepage.php, (4) Streamline/homepage.php, and (5) Structure/homepage.php in themes/.

    Source:ahmadbady
    Published:1 Jun 2009
    4.3
    Medium

    CVE-2009-1845

    Last Modified: 25 Apr 2014

    Cross-site scripting (XSS) vulnerability in ajax/updatecheck.php in Lussumo Vanilla 1.1.5 and 1.1.7 allows remote attackers to inject arbitrary web script or HTML via the RequestName parameter.

    Source:Gerendi Sandor Attila
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1843

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) results_table_web.php, and (f) question.php; and the (2) order_number parameter to (g) answers.php and (h) question.php.

    Source:YEnH4ckEr
    Published:1 Jun 2009
    7.5
    High

    CVE-2009-1842

    Last Modified: 25 Apr 2014

    SQL injection vulnerability in main/tracking/userLog.php in Francisco Burzi PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.

    Source:Gerendi Sandor Attila
    Published:1 Jun 2009
    5.4
    Medium

    CVE-2009-1839

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.

    Source:Jordi Chancel
    Published:11 Jun 2009
    4.3
    Medium

    CVE-2009-1834

    Last Modified: 26 Apr 2014

    Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar via an IDN with invalid Unicode characters that are displayed as whitespace, as demonstrated by the \u115A through \u115E characters.

    Source:Pavel Cvrcek
    Published:11 Jun 2009
    9.3
    Critical

    CVE-2009-1831

    Last Modified: 23 Apr 2026

    The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.

    Source:n00b
    Published:29 May 2009
    10
    Critical

    CVE-2009-1830

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long search query.

    Source:laurent gaffié
    Published:29 May 2009
    5
    Medium

    CVE-2009-1828

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affected.

    Source:Thierry Zoller
    Published:29 May 2009
    5
    Medium

    CVE-2009-1827

    Last Modified: 23 Apr 2026

    The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."

    Source:Thierry Zoller
    Published:29 May 2009
    6.5
    Medium

    CVE-2009-1826

    Last Modified: 23 Apr 2026

    modules/admuser.php in myGesuad 0.9.14 (aka 0.9) does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.

    Source:YEnH4ckEr
    Published:29 May 2009
    4
    Medium

    CVE-2009-1825

    Last Modified: 23 Apr 2026

    modules/admuser.php in myColex 1.4.2 does not require administrative authentication, which allows remote authenticated users to list user accounts via a Find action.

    Source:YEnH4ckEr
    Published:29 May 2009
    7.2
    High

    CVE-2009-1824

    Last Modified: 23 Apr 2026

    The ps_drv.sys kernel driver in ArcaBit ArcaVir 2009 Antivirus Protection 9.4.3201.9 and earlier, ArcaVir 2009 Internet Security 9.4.3202.9 and earlier, ArcaVir 2009 System Protection 9.4.3203.9 and earlier, and ArcaBit 2009 Home Protection 9.4.3204.9 and earlier, allows local users to gain privileges via crafted METHOD_NEITHER IOCTL requests to \Device\ps_drv containing arbitrary kernel addresses, as demonstrated using the (1) 0x2A7B802B and possibly (2) 0x2A7B8004 and (3) 0x2A7B802F IOCTLs.

    Source:NT Internals
    Published:29 May 2009
    7.5
    High

    CVE-2009-1822

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) imgcaptcha.php or (2) mp3captcha.php in assets/captcha/includes/captchaform/, or (3) assets/captcha/includes/captchatalk/swfmovie.php.

    Source:iskorpitx
    Published:29 May 2009
    5
    Medium

    CVE-2009-1821

    Last Modified: 23 Apr 2026

    DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb.

    Source:S4S-T3rr0r!sT
    Published:29 May 2009
    4.3
    Medium

    CVE-2009-1820

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:snakespc
    Published:29 May 2009
    7.5
    High

    CVE-2009-1819

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:snakespc
    Published:29 May 2009
    7.5
    High

    CVE-2009-1818

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin_manager.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via an m_username cookie in an add action.

    Source:Securitylab.ir
    Published:29 May 2009
    9.3
    Critical

    CVE-2009-1817

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in DigiMode Maya 1.0.2 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .m3u or (2) .m3l playlist file.

    Source:SirGod
    Published:29 May 2009
    7.5
    High

    CVE-2009-1816

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in My Game Script 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the username field). NOTE: some of these details are obtained from third party information.

    Source:ThE g0bL!N
    Published:29 May 2009
    9.3
    Critical

    CVE-2009-1815

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist file, as demonstrated by a long .mp3 URL in a .m3u file.

    Source:hack4love
    Published:29 May 2009
    7.5
    High

    CVE-2009-1814

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074.

    Source:Br0ly
    Published:29 May 2009
    7.5
    High

    CVE-2009-1813

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitrary SQL commands via (1) the uNev parameter (aka the username field) or (2) the uJelszo parameter (aka the Password field).

    Source:ThE g0bL!N
    Published:29 May 2009
    6
    Medium

    CVE-2009-1812

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) budget.php, (4) zahlung.php, or (5) adresse.php in modules/, related to classes/class.perform.php.

    Source:YEnH4ckEr
    Published:29 May 2009
    4.3
    Medium

    CVE-2009-1811

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to inject arbitrary web script or HTML via (1) the Page parameter in a List action to modules/ereignis.php, (2) the Kontext parameter in a Search action to modules/kategorie.php, (3) the image parameter to modules/image.php, or (4) the ID parameter in a Detail action to modules/sitzung.php.

    Source:YEnH4ckEr
    Published:29 May 2009
    6
    Medium

    CVE-2009-1810

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) medium.php, (4) person.php, or (5) schlagwort.php in modules/, related to classes/class.perform.php.

    Source:YEnH4ckEr
    Published:29 May 2009
    4.3
    Medium

    CVE-2009-1809

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the year parameter to modules/kalender.php, (2) the Page parameter in a List action to modules/ereignis.php, (3) the Kontext parameter in a Search action to modules/kategorie.php, or (4) the image parameter to modules/image.php.

    Source:YEnH4ckEr
    Published:29 May 2009
    4.9
    Medium

    CVE-2009-1808

    Last Modified: 25 Apr 2014

    Microsoft Windows XP SP3 allows local users to cause a denial of service (system crash) by making an SPI_SETDESKWALLPAPER SystemParametersInfo call with an improperly terminated pvParam argument, followed by an SPI_GETDESKWALLPAPER SystemParametersInfo call.

    Source:Arkon
    Published:28 May 2009
    9.3
    Critical

    CVE-2009-1807

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.

    Source:etirah
    Published:28 May 2009
    7.5
    High

    CVE-2009-1804

    Last Modified: 3 Jan 2017

    Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:snakespc
    Published:28 May 2009
    7.5
    High

    CVE-2009-1800

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Chinagames CGAgent ActiveX control 1.x in CGAgent.dll, as distributed in Chinagames iGame 2009, allows remote attackers to execute arbitrary code via a long argument to the CreateChinagames method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party information.

    Source:etirah
    Published:28 May 2009
    6.8
    Medium

    CVE-2009-1799

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1 alpha, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) gallery_category or (2) gallery_show parameter to example.php.

    Source:YEnH4ckEr
    Published:28 May 2009