4.9
    Medium

    CVE-2009-1237

    Last Modified: 23 Apr 2026

    Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.

    Source:mu-b
    Published:2 Apr 2009
    10
    Critical

    CVE-2009-1236

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.

    Source:mu-b
    Published:2 Apr 2009
    7.2
    High

    CVE-2009-1235

    Last Modified: 23 Apr 2026

    XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl calls.

    Source:mu-b
    Published:2 Apr 2009
    4.3
    Medium

    CVE-2009-1234

    Last Modified: 23 Apr 2026

    Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.

    Source:Ahmed Obied
    Published:2 Apr 2009
    4.3
    Medium

    CVE-2009-1233

    Last Modified: 23 Apr 2026

    Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an XML document containing many nested A elements.

    Source:Ahmed Obied
    Published:2 Apr 2009
    4.3
    Medium

    CVE-2009-1232

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0.10 and earlier are also affected.

    Source:Wojciech Pawlikowski
    Published:2 Apr 2009
    6.5
    Medium

    CVE-2009-1230

    Last Modified: 23 Nov 2016

    Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.

    Source:BlackHawk
    Published:2 Apr 2009
    7.5
    High

    CVE-2009-1229

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter.

    Source:ZoRLu
    Published:2 Apr 2009
    4.3
    Medium

    CVE-2009-1228

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject arbitrary web script or HTML via the username field (user_name parameter).

    Source:Anarchy Angel
    Published:2 Apr 2009
    10
    Critical

    CVE-2009-1227

    Last Modified: 23 Apr 2026

    NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) Authorization or (2) Referer HTTP header to TCP port 18624. NOTE: the vendor has disputed this issue, stating "Check Point Security Alert Team has analyzed this report. We've tried to reproduce the attack on all VPN-1 versions from NG FP2 and above with and without HFAs. The issue was not reproduced. We have conducted a thorough analysis of the relevant code and verified that we are secure against this attack. We consider this attack to pose no risk to Check Point customers." In addition, the original researcher, whose reliability is unknown as of 20090407, also states that the issue "was discovered during a pen-test where the client would not allow further analysis.

    Source:Bugs NotHugs
    Published:2 Apr 2009
    7.5
    High

    CVE-2009-1226

    Last Modified: 23 Nov 2016

    core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.

    Source:BlackHawk
    Published:2 Apr 2009
    4.3
    Medium

    CVE-2009-1225

    Last Modified: 15 Apr 2014

    Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.

    Source:TEAMELITE
    Published:2 Apr 2009
    7.5
    High

    CVE-2009-1224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.

    Source:Dimi4
    Published:2 Apr 2009
    5.1
    Medium

    CVE-2009-1222

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the WE_LANGUAGE parameter.

    Source:Salvatore Fresta
    Published:2 Apr 2009
    4.3
    Medium

    CVE-2009-1220

    Last Modified: 15 Apr 2014

    Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA) 5520 with software 7.2(4)30 and earlier 7.2 versions including 7.2(2)22, and 8.0(4)28 and earlier 8.0 versions, when clientless mode is enabled, allows remote attackers to inject arbitrary web script or HTML via the Host HTTP header.

    Source:Bugs NotHugs
    Published:1 Apr 2009
    5
    Medium

    CVE-2009-1219

    Last Modified: 14 Apr 2014

    Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.

    Source:SCS team
    Published:1 Apr 2009
    4.3
    Medium

    CVE-2009-1218

    Last Modified: 14 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allow remote attackers to inject arbitrary web script or HTML via (1) the fmt-out parameter to login.wcap or (2) the date parameter to command.shtml.

    Source:SCS team
    Published:1 Apr 2009
    4.3
    Medium

    CVE-2009-1217

    Last Modified: 23 Apr 2026

    Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."

    Source:Black Security
    Published:1 Apr 2009
    7.8
    High

    CVE-2009-1212

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datamatrix) allow remote attackers to overwrite arbitrary files via the (1) SaveBarCode and (2) SaveEnhWMF methods.

    Source:DSecRG
    Published:1 Apr 2009
    10
    Critical

    CVE-2009-1210

    Last Modified: 23 Apr 2026

    Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.

    Source:THCX Labs
    Published:30 Mar 2009
    9.3
    Critical

    CVE-2009-1209

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defer attribute.

    Source:Alfons Luja
    Published:1 Apr 2009
    4.3
    Medium

    CVE-2009-1204

    Last Modified: 14 Apr 2014

    Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrary web script or HTML via the PHP_SELF portion of a URI to (1) tiki-galleries.php, (2) tiki-list_file_gallery.php, (3) tiki-listpages.php, and (4) tiki-orphan_pages.php.

    Source:iliz
    Published:1 Apr 2009
    6
    Medium

    CVE-2009-1203

    Last Modified: 27 Apr 2014

    WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 does not properly distinguish its own login screen from the login screens it produces for third-party (1) FTP and (2) CIFS servers, which makes it easier for remote attackers to trick a user into sending WebVPN credentials to an arbitrary server via a URL associated with that server, aka Bug ID CSCsy80709.

    Source:David Byrne
    Published:25 Jun 2009
    4.3
    Medium

    CVE-2009-1201

    Last Modified: 27 Apr 2014

    Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN['process'] to the name of a crafted function, aka Bug ID CSCsy80694.

    Source:Trustwave's SpiderLabs
    Published:25 Jun 2009
    7.2
    High

    CVE-2009-1185

    Last Modified: 23 Apr 2026

    udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.

    Source:kingcope
    Published:15 Apr 2009
    4.3
    Medium

    CVE-2009-1171

    Last Modified: 23 Apr 2026

    The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assisted attackers to read arbitrary files via an input command in a "$$" sequence, which causes LaTeX to include the contents of the file.

    Source:Christian J. Eibl
    Published:30 Mar 2009
    9.3
    Critical

    CVE-2009-1169

    Last Modified: 23 Apr 2026

    The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.

    Source:Guido Landi
    Published:25 Mar 2009
    7.3
    High

    CVE-2009-1152

    Last Modified: 23 Apr 2026

    Siemens Gigaset SE461 WiMAX router 1.5-BL024.9.6401, and possibly other versions, allows remote attackers to cause a denial of service (device restart and loss of configuration) by connecting to TCP port 53, then closing the connection.

    Source:Benkei
    Published:26 Mar 2009
    9.8
    Critical

    CVE-2009-1151

    Last Modified: 22 Apr 2026

    Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

    Source:Adrian _pagvac_ Pastor
    Published:26 Mar 2009
    7.1
    High

    CVE-2009-1140

    Last Modified: 26 Apr 2014

    Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not prevent HTML rendering of cached content, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Cross-Domain Information Disclosure Vulnerability."

    Source:Jorge Luis Alvarez Medina
    Published:10 Jun 2009
    9.3
    Critical

    CVE-2009-1136

    Last Modified: 27 Oct 2016

    The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 Gold and SP1, and Office Small Business Accounting 2006, when used in Internet Explorer, allows remote attackers to execute arbitrary code via a crafted call to the msDataSourceObject method, as exploited in the wild in July and August 2009, aka "Office Web Components HTML Script Vulnerability."

    Source:anonymous
    Published:15 Jul 2009
    7.5
    High

    CVE-2009-1122

    Last Modified: 23 Apr 2026

    The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 WebDAV Authentication Bypass Vulnerability," a different vulnerability than CVE-2009-1535.

    Source:ka0x
    Published:10 Jun 2009
    9.3
    Critical

    CVE-2009-1092

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.

    Source:Nine:Situations:Group
    Published:25 Mar 2009
    9
    Critical

    CVE-2009-1088

    Last Modified: 23 Apr 2026

    Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.

    Source:Emory University
    Published:25 Mar 2009
    9.3
    Critical

    CVE-2009-1087

    Last Modified: 23 Apr 2026

    Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. NOTE: some of these details are obtained from third party information.

    Source:Nine:Situations:Group
    Published:25 Mar 2009
    9.3
    Critical

    CVE-2009-1071

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file.

    Source:His0k4
    Published:24 Mar 2009
    4.3
    Medium

    CVE-2009-1070

    Last Modified: 15 Apr 2014

    Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter.

    Source:Adam Baldwin
    Published:24 Mar 2009
    9.3
    Critical

    CVE-2009-1068

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long hostname in a .bsl playlist file.

    Source:His0k4
    Published:24 Mar 2009
    4.3
    Medium

    CVE-2009-1067

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web script or HTML via the x parameter.

    Source:Justin Keane
    Published:24 Mar 2009
    7.5
    High

    CVE-2009-1066

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the referral function in admin/lib/lib_logs.php in Pixie CMS 1.01a allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request.

    Source:Justin Keane
    Published:24 Mar 2009
    5.8
    Medium

    CVE-2009-1064

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allows remote attackers to overwrite arbitrary files via whitespace and a command-line switch, followed by a full pathname, in the third argument to the download method.

    Source:waraxe
    Published:24 Mar 2009
    6.8
    Medium

    CVE-2009-1063

    Last Modified: 23 Apr 2026

    Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file.

    Source:Koshi
    Published:24 Mar 2009
    9.3
    Critical

    CVE-2009-1059

    Last Modified: 9 Jan 2011

    Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted .zip file. NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.

    Source:fl0 fl0w
    Published:24 Mar 2009
    10
    Critical

    CVE-2009-1058

    Last Modified: 9 Jan 2011

    Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file that triggers an SEH overwrite. NOTE: it is possible that this overlaps CVE-2005-3317. NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.

    Source:fl0 fl0w
    Published:24 Mar 2009
    10
    Critical

    CVE-2009-1057

    Last Modified: 9 Jan 2011

    MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, related to a "format string buffer overflow." NOTE: CVE has not investigated whether the specified file.zip file can be used for exploitation of this product.

    Source:fl0 fl0w
    Published:24 Mar 2009
    7.5
    High

    CVE-2009-1050

    Last Modified: 27 Oct 2016

    Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie.

    Source:Fireshot
    Published:24 Mar 2009
    7.5
    High

    CVE-2009-1049

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Fireshot
    Published:24 Mar 2009
    4.7
    Medium

    CVE-2009-1046

    Last Modified: 14 Jun 2017

    The console selection feature in the Linux kernel 2.6.28 before 2.6.28.4, 2.6.25, and possibly earlier versions, when the UTF-8 console is used, allows physically proximate attackers to cause a denial of service (memory corruption) by selecting a small number of 3-byte UTF-8 characters, which triggers an "off-by-two memory error." NOTE: it is not clear whether this issue crosses privilege boundaries.

    Source:sgrakkyu
    Published:30 Jan 2009
    5
    Medium

    CVE-2009-1045

    Last Modified: 23 Nov 2016

    requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via a long input argument in an in_play action.

    Source:TheLeader
    Published:23 Mar 2009
    7.2
    High

    CVE-2009-1041

    Last Modified: 23 Apr 2026

    The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel memory via an out-of-bounds timer value.

    Source:mu-b
    Published:24 Mar 2009