10
    Critical

    CVE-2009-0837

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "Open/Execute a file" action.

    Source:SkD
    Published:10 Mar 2009
    3.6
    Low

    CVE-2009-0835

    Last Modified: 12 Apr 2014

    The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit process making a 32-bit syscall, which allows local users to bypass intended access restrictions via crafted syscalls that are misinterpreted as (a) stat or (b) chmod, a related issue to CVE-2009-0342 and CVE-2009-0343.

    Source:Chris Evans
    Published:25 Feb 2009
    9.3
    Critical

    CVE-2009-0833

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via a playlist (.pls) file with a long URL in the File1 field. NOTE: some of these details are obtained from third party information.

    Source:SkD
    Published:5 Mar 2009
    7.5
    High

    CVE-2009-0832

    Last Modified: 22 Nov 2016

    SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the CA parameter.

    Source:Khashayar Fereidani
    Published:5 Mar 2009
    6
    Medium

    CVE-2009-0831

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter.

    Source:Khashayar Fereidani
    Published:5 Mar 2009
    7.5
    High

    CVE-2009-0829

    Last Modified: 13 Jan 2017

    Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Moudi
    Published:5 Mar 2009
    5
    Medium

    CVE-2009-0828

    Last Modified: 13 Jan 2017

    QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database information, including user credentials, via a direct request.

    Source:Moudi
    Published:5 Mar 2009
    5
    Medium

    CVE-2009-0827

    Last Modified: 12 Jan 2017

    PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.

    Source:ahmadbady
    Published:5 Mar 2009
    5
    Medium

    CVE-2009-0826

    Last Modified: 12 Jan 2017

    BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.

    Source:ahmadbady
    Published:5 Mar 2009
    7.5
    High

    CVE-2009-0825

    Last Modified: 13 Apr 2014

    SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Dmitriy Evteev
    Published:9 Mar 2009
    4.9
    Medium

    CVE-2009-0824

    Last Modified: 14 Apr 2014

    Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.4.2.3 and earlier, CloneDVD 2.9.2.0 and earlier, and CloneCD 5.3.1.3 and earlier, uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to cause a denial of service (system crash) via a crafted IOCTL call.

    Source:Nikita Tarakanov
    Published:14 Mar 2009
    5
    Medium

    CVE-2009-0821

    Last Modified: 13 Apr 2014

    Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.

    Source:b3hz4d
    Published:5 Mar 2009
    7.5
    High

    CVE-2009-0820

    Last Modified: 23 Dec 2016

    Multiple eval injection vulnerabilities in phpScheduleIt before 1.2.11 allow remote attackers to execute arbitrary code via (1) the end_date parameter to reserve.php and (2) the start_date and end_date parameters to check.php. NOTE: the start_date/reserve.php vector is already covered by CVE-2008-6132.

    Source:EgiX
    Published:5 Mar 2009
    4
    Medium

    CVE-2009-0819

    Last Modified: 13 Apr 2014

    sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial of service (crash) via "an XPath expression employing a scalar expression as a FilterExpr with ExtractValue() or UpdateXML()," which triggers an assertion failure.

    Source:Shane Bester
    Published:5 Mar 2009
    5
    Medium

    CVE-2009-0815

    Last Modified: 23 Apr 2026

    The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 before 4.2.6, and 4.3alpha1 leaks a hash secret (juHash) in an error message, which allows remote attackers to read arbitrary files by including the hash in a request.

    Source:Lolek
    Published:5 Mar 2009
    4.3
    Medium

    CVE-2009-0814

    Last Modified: 13 Apr 2014

    Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchText parameter.

    Source:DJR
    Published:5 Mar 2009
    9.3
    Critical

    CVE-2009-0813

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the ImeraIEPlugin ActiveX control (ImeraIEPlugin.dll 1.0.2.54) in Imera TeamLinks Client allows remote attackers to force the download and execution of arbitrary URLs via modified DownloadProtocol, DownloadHost, DownloadPort, and DownloadURI parameters.

    Source:Elazar
    Published:5 Mar 2009
    9.3
    Critical

    CVE-2009-0812

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions allows remote attackers to execute arbitrary code via a crafted Intel Hex Code (.hex) file. NOTE: some of these details are obtained from third party information.

    Source:hack4love
    Published:4 Mar 2009
    9.3
    Critical

    CVE-2009-0811

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to execute arbitrary programs via an executable file name in the argument to the SetExternalPlayer method.

    Source:Nine:Situations:Group
    Published:4 Mar 2009
    7.5
    High

    CVE-2009-0810

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Source:Fireshot
    Published:4 Mar 2009
    7.5
    High

    CVE-2009-0807

    Last Modified: 23 Apr 2026

    zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.

    Source:ahmadbady
    Published:4 Mar 2009
    2.6
    Low

    CVE-2009-0796

    Last Modified: 31 Jan 2017

    Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 for the Apache HTTP Server, when /perl-status is accessible, allows remote attackers to inject arbitrary web script or HTML via the URI.

    Source:Richard H. Brain
    Published:1 Apr 2009
    Low

    CVE-2009-0795

    Last Modified: 31 Jan 2017

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-0796, CVE-2009-1265. Reason: this candidate was intended for one issue, but a typo caused it to be associated with a different issue. Notes: All CVE users should consult CVE-2009-0796 and CVE-2009-1265 to determine which ID is appropriate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Richard H. Brain
    Published:8 Apr 2009
    4.3
    Medium

    CVE-2009-0769

    Last Modified: 10 Apr 2014

    QIP 2005 build 8082 allows remote attackers to cause a denial of service (CPU consumption and application hang) via a crafted Rich Text Format (RTF) ICQ message, as demonstrated by an {\rtf\pict\&&} message. NOTE: the vulnerability may be in Sergey Tkachenko TRichView. If so, then this should not be treated as a vulnerability in QIP.

    Source:ShineShadow
    Published:3 Mar 2009
    7.5
    High

    CVE-2009-0768

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the forumID parameter in a next action.

    Source:darkjoker
    Published:3 Mar 2009
    5
    Medium

    CVE-2009-0767

    Last Modified: 23 Apr 2026

    Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing credentials via a direct request for job/config.data.

    Source:RoMaNcYxHaCkEr
    Published:3 Mar 2009
    7.5
    High

    CVE-2009-0766

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in default.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the configfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:RoMaNcYxHaCkEr
    Published:3 Mar 2009
    7.5
    High

    CVE-2009-0765

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the configfile parameter.

    Source:RoMaNcYxHaCkEr
    Published:3 Mar 2009
    4.3
    Medium

    CVE-2009-0764

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kipper 2.01 allow remote attackers to inject arbitrary web script or HTML via the charm parameter to (1) index.php and (2) kipper.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:RoMaNcYxHaCkEr
    Published:3 Mar 2009
    4.3
    Medium

    CVE-2009-0763

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.

    Source:RoMaNcYxHaCkEr
    Published:3 Mar 2009
    4.3
    Medium

    CVE-2009-0761

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in online.asp in Team Board 1.x allows remote attackers to inject arbitrary web script or HTML via the lookname parameter.

    Source:Pouya_Server
    Published:3 Mar 2009
    5
    Medium

    CVE-2009-0760

    Last Modified: 23 Apr 2026

    Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for data/team.mdb.

    Source:Pouya_Server
    Published:3 Mar 2009
    5
    Medium

    CVE-2009-0756

    Last Modified: 14 Dec 2016

    The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file that triggers a parsing error, which is not properly handled by JBIG2SymbolDict::~JBIG2SymbolDict and triggers an invalid memory dereference.

    Source:Romario
    Published:22 Jan 2009
    5
    Medium

    CVE-2009-0755

    Last Modified: 14 Dec 2016

    The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of service (crash) via a PDF file with an invalid Form Opt entry.

    Source:Romario
    Published:27 Jan 2009
    2.1
    Low

    CVE-2009-0754

    Last Modified: 9 Apr 2014

    PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hosted on the same web server by modifying the mbstring.func_overload setting within .htaccess, which causes this setting to be applied to other virtual hosts on the same server.

    Source:strategma
    Published:27 Feb 2004
    5
    Medium

    CVE-2009-0753

    Last Modified: 14 Feb 2017

    Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.

    Source:Michael Peselnik
    Published:22 Feb 2009
    5
    Medium

    CVE-2009-0751

    Last Modified: 23 Apr 2026

    Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of headers.

    Source:Praveen Darshanam
    Published:2 Mar 2009
    7.5
    High

    CVE-2009-0750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:x0r
    Published:2 Mar 2009
    4.9
    Medium

    CVE-2009-0746

    Last Modified: 11 Apr 2014

    The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not validate a certain rec_len field, which allows local users to cause a denial of service (OOPS) by attempting to mount a crafted ext4 filesystem.

    Source:Sami Liedes
    Published:11 Jan 2009
    5
    Medium

    CVE-2009-0744

    Last Modified: 11 Apr 2014

    Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a feeds: URI beginning with a (1) % (percent), (2) { (open curly bracket), (3) } (close curly bracket), (4) ^ (caret), (5) ` (backquote), or (6) | (pipe) character, followed by an & (ampersand) character.

    Source:Trancer
    Published:27 Feb 2009
    7.5
    High

    CVE-2009-0741

    Last Modified: 11 Apr 2014

    SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the LoginName parameter.

    Source:Francesco Bianchino
    Published:25 Feb 2009
    7.5
    High

    CVE-2009-0740

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Source:x0r
    Published:25 Feb 2009
    7.5
    High

    CVE-2009-0739

    Last Modified: 8 Feb 2017

    SQL injection vulnerability in login.php in MyNews 0.10 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Source:x0r
    Published:25 Feb 2009
    7.5
    High

    CVE-2009-0738

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) passwd parameters.

    Source:x0r
    Published:25 Feb 2009
    5.1
    Medium

    CVE-2009-0735

    Last Modified: 8 Feb 2017

    Directory traversal vulnerability in lib/classes/message_class.php in Papoo CMS 3.6, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the pfadhier parameter. NOTE: some of these details are obtained from third party information.

    Source:SirGod
    Published:25 Feb 2009
    9.3
    Critical

    CVE-2009-0734

    Last Modified: 10 Apr 2014

    Heap-based buffer overflow in MultimediaPlayer.exe 6.86.240.7 in Nokia PC Suite 6.86.9.3 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.

    Source:zer0in
    Published:25 Feb 2009
    9.3
    Critical

    CVE-2009-0731

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.

    Source:Osirys
    Published:24 Feb 2009
    6.8
    Medium

    CVE-2009-0730

    Last Modified: 6 Dec 2016

    Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which is not properly handled by venuedetails.php, and (2) the gigcal_bands_id parameter in a details action to index.php, which is not properly handled by banddetails.php, different vectors than CVE-2009-0726.

    Source:Salvatore Fresta
    Published:24 Feb 2009
    7.5
    High

    CVE-2009-0728

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.

    Source:StAkeR
    Published:24 Feb 2009
    7.5
    High

    CVE-2009-0727

    Last Modified: 14 Feb 2017

    SQL injection vulnerability in jobdetails.php in taifajobs 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the jobid parameter.

    Source:K-159
    Published:24 Feb 2009