5
    Medium

    CVE-2009-1353

    Last Modified: 23 Apr 2026

    Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause a denial of service (daemon crash) via a long URI, related to http.c.

    Source:e.wiZz!
    Published:21 Apr 2009
    9.3
    Critical

    CVE-2009-1352

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an HTML file with a link to a long URL, as demonstrated by a .rar URL.

    Source:SuB-ZeRo
    Published:21 Apr 2009
    9.3
    Critical

    CVE-2009-1351

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:21 Apr 2009
    10
    Critical

    CVE-2009-1350

    Last Modified: 8 Mar 2011

    Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of an arbitrary pointer.

    Source:Metasploit
    Published:21 Apr 2009
    4.3
    Medium

    CVE-2009-1349

    Last Modified: 18 Apr 2014

    Cross-site scripting (XSS) vulnerability in C2Net Stronghold 2.3 allows remote attackers to inject arbitrary web script or HTML via the URI.

    Source:Xia Shing Zee
    Published:21 Apr 2009
    6.8
    Medium

    CVE-2009-1347

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login_name parameter (aka the username field) or (2) the login_pw parameter (aka the password field).

    Source:Valentin
    Published:20 Apr 2009
    7.5
    High

    CVE-2009-1346

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in publico/ficha.php in NetHoteles 3.0 allows remote attackers to execute arbitrary SQL commands via the id_establecimiento parameter.

    Source:snakespc
    Published:20 Apr 2009
    7.5
    High

    CVE-2009-1345

    Last Modified: 21 Nov 2016

    SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL commands via the id_document parameter.

    Source:NoGe
    Published:20 Apr 2009
    4.4
    Medium

    CVE-2009-1337

    Last Modified: 23 Apr 2026

    The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_signal field and then uses an exec system call to launch a setuid application.

    Source:gat3way
    Published:25 Feb 2009
    4.3
    Medium

    CVE-2009-1335

    Last Modified: 16 Apr 2014

    Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.

    Source:Nam Nguyen
    Published:17 Apr 2009
    4.3
    Medium

    CVE-2009-1334

    Last Modified: 16 Apr 2014

    Cross-site scripting (XSS) vulnerability in login/FilepathLogin.html in IBM Tivoli Continuous Data Protection (CDP) for Files 3.1.4.0 allows remote attackers to inject arbitrary web script or HTML via the reason parameter.

    Source:Abdul-Aziz Hariri
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1331

    Last Modified: 23 Apr 2026

    Integer overflow in Microsoft Windows Media Player (WMP) 11.0.5721.5260 allows remote attackers to cause a denial of service (application crash) via a crafted .mid file, as demonstrated by crash.mid.

    Source:HuoFu
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1330

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1329

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1328

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1327

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1326

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1325

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1324

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file.

    Source:Cyber-Zone
    Published:17 Apr 2009
    7.5
    High

    CVE-2009-1323

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Osirys
    Published:17 Apr 2009
    5
    Medium

    CVE-2009-1322

    Last Modified: 23 Apr 2026

    ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.

    Source:AlpHaNiX
    Published:17 Apr 2009
    4.3
    Medium

    CVE-2009-1321

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.asp in ASP Product Catalog 1.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter.

    Source:AlpHaNiX
    Published:17 Apr 2009
    7.5
    High

    CVE-2009-1319

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the lang parameter to index.php.

    Source:SirGod
    Published:17 Apr 2009
    6.5
    Medium

    CVE-2009-1318

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions before 3.4.0 allows remote attackers to include arbitrary files via directory traversal sequences in the t parameter.

    Source:zxvf
    Published:17 Apr 2009
    6.8
    Medium

    CVE-2009-1317

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) userSID cookie parameter to droplets/functions/base.php and the (2) username parameter to admin/index.php.

    Source:halkfild
    Published:17 Apr 2009
    7.5
    High

    CVE-2009-1316

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.

    Source:DSecRG
    Published:17 Apr 2009
    4.3
    Medium

    CVE-2009-1315

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter to groups_profile.php, (2) cat_id and (3) razd_id parameters to adv_cat.php, and the (4) URL to blogs_full.php.

    Source:DSecRG
    Published:17 Apr 2009
    10
    Critical

    CVE-2009-1314

    Last Modified: 23 Apr 2026

    body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.

    Source:Osirys
    Published:17 Apr 2009
    9.3
    Critical

    CVE-2009-1313

    Last Modified: 22 Apr 2014

    The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulnerability reportedly exists because of an incorrect fix for CVE-2009-1302.

    Source:Marc Gueury
    Published:27 Apr 2009
    4.3
    Medium

    CVE-2009-1312

    Last Modified: 19 Apr 2014

    Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or (2) specifying the content of a Refresh header. NOTE: it was later reported that Firefox 3.6 a1 pre and Mozilla 1.7.x and earlier are also affected.

    Source:Olli Pettay
    Published:21 Apr 2009
    4.3
    Medium

    CVE-2009-1294

    Last Modified: 28 Mar 2019

    Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 through SP3 (1.0.3) allow remote attackers to inject arbitrary web script or HTML via the (1) p_p_state or (2) p_p_mode parameters.

    Source:Michael Kirchner
    Published:16 Apr 2009
    6.8
    Medium

    CVE-2009-1290

    Last Modified: 16 Apr 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration interface in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to hijack the authentication of administrators, as demonstrated by a power-off request to the private/blade_power_action script.

    Source:Henri Lindberg
    Published:13 Apr 2009
    4.3
    Medium

    CVE-2009-1288

    Last Modified: 16 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

    Source:Henri Lindberg
    Published:13 Apr 2009
    4.3
    Medium

    CVE-2009-1287

    Last Modified: 16 Apr 2014

    Cross-site scripting (XSS) vulnerability in Cisco Subscriber Edge Services Manager (SESM) allows remote attackers to inject arbitrary web script or HTML via the URI. NOTE: some of these details are obtained from third party information.

    Source:Usman Saeed
    Published:13 Apr 2009
    5
    Medium

    CVE-2009-1284

    Last Modified: 14 Jul 2017

    Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file.

    Source:Vincent Lafevre
    Published:23 Mar 2009
    6.8
    Medium

    CVE-2009-1283

    Last Modified: 23 Apr 2026

    glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes.

    Source:Nine:Situations:Group
    Published:9 Apr 2009
    7.5
    High

    CVE-2009-1282

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the glf_session cookie parameter.

    Source:Nine:Situations:Group
    Published:9 Apr 2009
    4.3
    Medium

    CVE-2009-1281

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Nine:Situations:Group
    Published:9 Apr 2009
    7.5
    High

    CVE-2009-1278

    Last Modified: 7 Dec 2016

    Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to inject arbitrary PHP code into config.php via the configure action to index.php.

    Source:brain[pillow]
    Published:9 Apr 2009
    7.5
    High

    CVE-2009-1277

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary SQL commands via the member_id parameter in a viewprofile action. NOTE: the board_id issue is already covered by CVE-2008-2996.2.

    Source:brain[pillow]
    Published:9 Apr 2009
    7.5
    High

    CVE-2009-1263

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a comment action to index.php.

    Source:Salvatore Fresta
    Published:7 Apr 2009
    9.3
    Critical

    CVE-2009-1260

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.

    Source:Metasploit
    Published:7 Apr 2009
    6.8
    Medium

    CVE-2009-1259

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/bb/topic.php in Insane Visions AdaptBB 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a topic action to index.php.

    Source:StAkeR
    Published:7 Apr 2009
    9
    Critical

    CVE-2009-1257

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted CCD file.

    Source:Stack
    Published:7 Apr 2009
    7.5
    High

    CVE-2009-1256

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId parameter. NOTE: some of these details are obtained from third party information.

    Source:MisterRichard
    Published:7 Apr 2009
    7.5
    High

    CVE-2009-1248

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitrary PHP code via a URL in the theme_directory parameter to (1) container.php and (2) header.php in themes/.

    Source:SirGod
    Published:6 Apr 2009
    7.5
    High

    CVE-2009-1247

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:SirGod
    Published:6 Apr 2009
    7.5
    High

    CVE-2009-1246

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Blogplus 1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) row_mysql_blocks_center_down[file] parameter to includes/block_center_down.php; (2) row_mysql_blocks_center_top[file] includes/parameter to block_center_top.php; (3) row_mysql_blocks_left[file] parameter to includes/block_left.php; (4) row_mysql_blocks_right[file] parameter to includes/block_right.php; and row_mysql_bloginfo[theme] parameter to (5) includes/window_down.php and (6) includes/window_top.php.

    Source:ahmadbady
    Published:6 Apr 2009
    6.8
    Medium

    CVE-2009-1244

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the virtual machine display function in VMware Workstation 6.5.1 and earlier; VMware Player 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 1.x before 1.0.9 build 156507 and 2.x before 2.0.1 build 156745; VMware Fusion before 2.0.4 build 159196; VMware ESXi 3.5; and VMware ESX 3.0.2, 3.0.3, and 3.5 allows guest OS users to execute arbitrary code on the host OS via unknown vectors, a different vulnerability than CVE-2008-4916.

    Published:13 Apr 2009
    7.2
    High

    CVE-2009-1238

    Last Modified: 23 Apr 2026

    Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of mutex locking for an unspecified global variable.

    Source:mu-b
    Published:2 Apr 2009