6.8
    Medium

    CVE-2009-1483

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable from index2.php, allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in profiles/.

    Source:JosS
    Published:29 Apr 2009
    7.5
    High

    CVE-2009-1480

    Last Modified: 14 Dec 2016

    SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via the fileget parameter in a view action and other unspecified vectors.

    Source:Salvatore Fresta
    Published:29 Apr 2009
    7.5
    High

    CVE-2009-1479

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter.

    Source:Axel Neumann
    Published:22 Oct 2009
    4.9
    Medium

    CVE-2009-1478

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, allow local users to cause a denial of service (panic) via unknown vectors.

    Source:mu-b
    Published:29 Apr 2009
    4.3
    Medium

    CVE-2009-1469

    Last Modified: 23 Apr 2014

    CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server before 9.4.2 makes it easier for remote attackers to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header in the subject element of an XML document, as demonstrated by triggering an e-mail message from the server that contains a user's correct credentials, and requests that the user compose a reply that includes this message.

    Source:RedTeam Pentesting GmbH
    Published:5 May 2009
    6.5
    Medium

    CVE-2009-1468

    Last Modified: 22 Apr 2014

    Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) sql and (2) order_by elements in an XML search query.

    Source:RedTeam Pentesting
    Published:5 May 2009
    4.3
    Medium

    CVE-2009-1467

    Last Modified: 22 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.

    Source:RedTeam Pentesting GmbH
    Published:5 May 2009
    4.3
    Medium

    CVE-2009-1458

    Last Modified: 18 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in razorCMS before 0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the slab parameter in an edit action, (2) the catname parameter in a showcats action, and (3) the cat parameter in a reordercat action.

    Source:Jeremi Gosney
    Published:28 Apr 2009
    6.5
    Medium

    CVE-2009-1456

    Last Modified: 18 Apr 2014

    Directory traversal vulnerability in admin.php in Malleo 1.2.3 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the module parameter.

    Source:Drosophila
    Published:28 Apr 2009
    6.8
    Medium

    CVE-2009-1453

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information.

    Source:Salvatore Fresta
    Published:28 Apr 2009
    7.5
    High

    CVE-2009-1452

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execute arbitrary PHP code via a URL in the (1) _page_css and (2) _page_javascript parameters. NOTE: the _page_content vector is already is covered by CVE-2009-1450.

    Source:JosS
    Published:28 Apr 2009
    4.3
    Medium

    CVE-2009-1451

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:ahmadbady
    Published:28 Apr 2009
    7.5
    High

    CVE-2009-1450

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP code via a URL in the _page_content parameter.

    Source:ahmadbady
    Published:28 Apr 2009
    9.3
    Critical

    CVE-2009-1449

    Last Modified: 9 Jan 2011

    Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attackers to execute arbitrary code via a skin file (skin.ini) with a large PlaylistSkin parameter. NOTE: this may overlap CVE-2008-5735.

    Source:Stack
    Published:27 Apr 2009
    6.8
    Medium

    CVE-2009-1447

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/.

    Source:ahmadbady
    Published:27 Apr 2009
    6.5
    Medium

    CVE-2009-1446

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in gallery/pictures/. NOTE: some of these details are obtained from third party information.

    Source:Securitylab.ir
    Published:27 Apr 2009
    7.5
    High

    CVE-2009-1445

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary files via directory traversal sequences in the lang parameter to libraries/helpdocs/help.php and (2) include and execute arbitrary local files via directory traversal sequences in the error parameter to index.php.

    Source:ahmadbady
    Published:27 Apr 2009
    7.5
    High

    CVE-2009-1444

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbitrary PHP code via a URL in the lib_path parameter.

    Source:ahmadbady
    Published:27 Apr 2009
    10
    Critical

    CVE-2009-1443

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and attack vectors.

    Source:Nicolas DEROUET
    Published:27 Apr 2009
    9.3
    Critical

    CVE-2009-1437

    Last Modified: 9 Jan 2011

    Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows remote attackers to execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: this may overlap CVE-2008-3408.

    Source:GoLd_M
    Published:27 Apr 2009
    4.9
    Medium

    CVE-2009-1436

    Last Modified: 21 Apr 2014

    The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berkeley DB 1.85 database structures, which allows local users to obtain sensitive information by reading a database file.

    Source:Jaakko Heinonen
    Published:27 Apr 2009
    2.1
    Low

    CVE-2009-1435

    Last Modified: 19 Apr 2014

    NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of service (application crash) via directories with long pathnames. NOTE: some of these details are obtained from third party information.

    Source:Juan Pablo Lopez Yacubian
    Published:27 Apr 2009
    9.3
    Critical

    CVE-2009-1430

    Last Modified: 6 Mar 2011

    Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allow remote attackers to execute arbitrary code via (1) a crafted packet or (2) data that ostensibly arrives from the MsgSys.exe process.

    Source:Metasploit
    Published:29 Apr 2009
    10
    Critical

    CVE-2009-1429

    Last Modified: 23 Apr 2026

    The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Center (SSS); Symantec AntiVirus Server; Symantec AntiVirus Central Quarantine Server; Symantec AntiVirus (SAV) Corporate Edition 9 before 9.0 MR7, 10.0 and 10.1 before 10.1 MR8, and 10.2 before 10.2 MR2; Symantec Client Security (SCS) 2 before 2.0 MR7 and 3 before 3.1 MR8; and Symantec Endpoint Protection (SEP) before 11.0 MR3, allows remote attackers to execute arbitrary commands via a crafted packet whose contents are interpreted as a command to be launched in a new process by the CreateProcessA function.

    Source:kingcope
    Published:29 Apr 2009
    10
    Critical

    CVE-2009-1422

    Last Modified: 29 Apr 2014

    Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows remote attackers to gain privileges via unknown vectors, aka PR_41209.

    Source:anonymous
    Published:14 Jul 2009
    7.5
    High

    CVE-2009-1416

    Last Modified: 22 Apr 2014

    lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.

    Source:Miroslav Kratochvil
    Published:30 Apr 2009
    4.3
    Medium

    CVE-2009-1415

    Last Modified: 22 Apr 2014

    lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.

    Source:Miroslav Kratochvil
    Published:30 Apr 2009
    7.5
    High

    CVE-2009-1411

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the c parameter to plug.php.

    Source:OoN_Boy
    Published:24 Apr 2009
    7.5
    High

    CVE-2009-1410

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Player
    Published:24 Apr 2009
    5.1
    Medium

    CVE-2009-1409

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the hide parameter, a different vector than CVE-2005-4224 and CVE-2008-5320.

    Source:StAkeR
    Published:24 Apr 2009
    4.3
    Medium

    CVE-2009-1408

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HTML allows remote attackers to inject arbitrary web script or HTML via Javascript events such as onmouseover in nested BBcode tags, as demonstrated using (1) email, (2) img, and (3) url tags.

    Source:YEnH4ckEr
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2009-1407

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter.

    Source:Kacper
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2009-1406

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the include parameter.

    Source:SirGod
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2009-1405

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the set_lng parameter.

    Source:SirGod
    Published:24 Apr 2009
    6.8
    Medium

    CVE-2009-1404

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user (Username) parameter.

    Source:SirGod
    Published:24 Apr 2009
    7.5
    High

    CVE-2009-1403

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL commands via the products_id parameter.

    Source:Player
    Published:24 Apr 2009
    9.3
    Critical

    CVE-2009-1394

    Last Modified: 7 Mar 2011

    Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.

    Source:Metasploit
    Published:26 Jun 2009
    6.8
    Medium

    CVE-2009-1391

    Last Modified: 27 Apr 2014

    Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer overflow, as exploited in the wild by Trojan.Downloader-71014 in June 2009.

    Source:Leo Bergolth
    Published:16 Jun 2009
    5
    Medium

    CVE-2009-1386

    Last Modified: 23 Apr 2026

    ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occurs before ClientHello.

    Source:Jon Oberheide
    Published:2 Jun 2009
    5
    Medium

    CVE-2009-1379

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS packet, as demonstrated by a packet from a server that uses a crafted server certificate.

    Source:Jon Oberheide
    Published:11 May 2009
    9.3
    Critical

    CVE-2009-1376

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the msn_slplink_process_msg functions in the MSN protocol handler in (1) libpurple/protocols/msn/slplink.c and (2) libpurple/protocols/msnp9/slplink.c in Pidgin (formerly Gaim) before 2.5.6 on 32-bit platforms allow remote attackers to execute arbitrary code via a malformed SLP message with a crafted offset value, leading to buffer overflows. NOTE: this issue exists because of an incomplete fix for CVE-2008-2927.

    Source:Pierre Nogues
    Published:2 May 2009
    9.3
    Critical

    CVE-2009-1370

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a .cue file.

    Source:fl0 fl0w
    Published:22 Apr 2009
    5
    Medium

    CVE-2009-1369

    Last Modified: 15 Dec 2016

    moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message.

    Source:SirGod
    Published:22 Apr 2009
    7.5
    High

    CVE-2009-1368

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the same issue as CVE-2008-6126.2, which may have been fixed in 1.10.3.

    Source:SirGod
    Published:22 Apr 2009
    4.3
    Medium

    CVE-2009-1367

    Last Modified: 15 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web script or HTML via the query parameter in search action, a different issue than CVE-2008-6127.2a.

    Source:SirGod
    Published:22 Apr 2009
    6.8
    Medium

    CVE-2009-1362

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary SQL commands via the login_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Valentin
    Published:22 Apr 2009
    10
    Critical

    CVE-2009-1361

    Last Modified: 23 Apr 2026

    dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:SirGod
    Published:22 Apr 2009
    6.8
    Medium

    CVE-2009-1357

    Last Modified: 19 Apr 2014

    CRLF injection vulnerability in da/DA/Login in Sun Java System Delegated Administrator 6.2 through 6.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the HELP_PAGE parameter.

    Source:SCS team
    Published:23 Apr 2009
    9.3
    Critical

    CVE-2009-1356

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 filename in a playlist (.xpl) file.

    Source:fl0 fl0w
    Published:21 Apr 2009
    4
    Medium

    CVE-2009-1354

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:e.wiZz!
    Published:21 Apr 2009