4.3
    Medium

    CVE-2009-0374

    Last Modified: 23 Apr 2026

    Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability. NOTE: a third party disputes the relevance of this issue, stating that "every sufficiently featured browser is and likely will remain susceptible to the behavior known as clickjacking," and adding that the exploit code "is not a valid demonstration of the issue.

    Source:x0x
    Published:28 Jan 2009
    7.5
    High

    CVE-2009-0373

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mag_id parameter in a magazine action to index.php.

    Source:TurkGuvenligi
    Published:30 Jan 2009
    6.5
    Medium

    CVE-2009-0372

    Last Modified: 6 Jan 2017

    Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/.

    Source:StAkeR
    Published:30 Jan 2009
    6.8
    Medium

    CVE-2009-0371

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the type parameter.

    Source:darkjoker
    Published:30 Jan 2009
    4.3
    Medium

    CVE-2009-0369

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Clickjacking" vulnerability.

    Source:UzmiX
    Published:30 Jan 2009
    2.1
    Low

    CVE-2009-0368

    Last Modified: 11 Apr 2014

    OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data objects via a (1) low level APDU command or (2) debugging tool, as demonstrated by reading the 4601 or 4701 file with the opensc-explorer or opensc-tool program.

    Source:Andreas Jellinghaus
    Published:2 Mar 2009
    9.3
    Critical

    CVE-2009-0367

    Last Modified: 13 Apr 2014

    The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a whitelisted module that imports an unsafe module, then using a hierarchical module name to access the unsafe module through the whitelisted module.

    Source:Wesnoth
    Published:5 Mar 2009
    6.2
    Medium

    CVE-2009-0360

    Last Modified: 23 Apr 2026

    Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application.

    Source:Jon Oberheide
    Published:13 Feb 2009
    9
    Critical

    CVE-2009-0351

    Last Modified: 27 Sept 2016

    Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code via a long LIST argument beginning with an * (asterisk) character.

    Source:joe walko
    Published:29 Jan 2009
    9.3
    Critical

    CVE-2009-0350

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip. NOTE: some of these details are obtained from third party information.

    Source:Houssamix
    Published:29 Jan 2009
    9.3
    Critical

    CVE-2009-0349

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (persistent daemon crash) and possibly execute arbitrary code via a long string in a licensing key (aka .key) file.

    Source:LiquidWorm
    Published:29 Jan 2009
    5
    Medium

    CVE-2009-0348

    Last Modified: 9 Apr 2014

    The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7.1 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

    Source:Marco Mella
    Published:29 Jan 2009
    5.8
    Medium

    CVE-2009-0347

    Last Modified: 9 Apr 2014

    Open redirect vulnerability in cs.html in the Autonomy (formerly Verity) Ultraseek search engine allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the url parameter.

    Source:buzzy
    Published:29 Jan 2009
    7.2
    High

    CVE-2009-0343

    Last Modified: 12 Dec 2018

    Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions that occur in monitoring 64-bit processes.

    Source:Chris Evans
    Published:29 Jan 2009
    9.3
    Critical

    CVE-2009-0341

    Last Modified: 9 Apr 2014

    The shell32 module in Microsoft Internet Explorer 7.0 on Windows XP SP3 might allow remote attackers to execute arbitrary code via a long VALUE attribute in an INPUT element, possibly related to a stack consumption vulnerability.

    Source:Juan Pablo Lopez Yacubian
    Published:29 Jan 2009
    6.8
    Medium

    CVE-2009-0340

    Last Modified: 23 Jan 2017

    Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files via a .. (dot dot) in the olang parameter to (1) mail.php and (2) mailbar.php.

    Source:ahmadbady
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0339

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to execute arbitrary SQL commands via the itemID parameter in a view action.

    Source:Pouya_Server
    Published:29 Jan 2009
    4.3
    Medium

    CVE-2009-0338

    Last Modified: 15 Dec 2016

    Cross-site scripting (XSS) vulnerability in inc_webblogmanager.asp in DMXReady Blog Manager allows remote attackers to inject arbitrary web script or HTML via the CategoryID parameter in a refer action.

    Source:Pouya_Server
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Pouya_Server
    Published:29 Jan 2009
    5
    Medium

    CVE-2009-0336

    Last Modified: 23 Apr 2026

    Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb. NOTE: some of these details are obtained from third party information.

    Source:Pouya_Server
    Published:29 Jan 2009
    4.3
    Medium

    CVE-2009-0335

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrary web script or HTML via the view parameter.

    Source:Pouya_Server
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0334

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL commands via the day parameter in an archive action.

    Source:Pouya_Server
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0333

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the WebAmoeba (WA) Ticket System (com_waticketsystem) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action to index.php.

    Source:InjEctOr5
    Published:29 Jan 2009
    7.8
    High

    CVE-2009-0331

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in gallery/comment.php in Enhanced Simple PHP Gallery (ESPG) 1.72 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. NOTE: the vulnerability may be in my little homepage Comment script. If so, then this should not be treated as a vulnerability in ESPG.

    Source:bd0rk
    Published:29 Jan 2009
    6.8
    Medium

    CVE-2009-0330

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.

    Source:ahmadbady
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0329

    Last Modified: 11 Nov 2016

    SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php, a different vector than CVE-2008-0844.

    Source:InjEctOr5
    Published:29 Jan 2009
    5
    Medium

    CVE-2009-0328

    Last Modified: 23 Apr 2026

    ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for Database/Sales.mdb.

    Source:Moudi
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0327

    Last Modified: 17 Jan 2017

    SQL injection vulnerability in readbible.php in Free Bible Search PHP Script 1.0 allows remote attackers to execute arbitrary SQL commands via the version parameter.

    Source:nuclear
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0326

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Dark Age CMS 0.2c beta allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:darkjoker
    Published:29 Jan 2009
    4.3
    Medium

    CVE-2009-0325

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the cat parameter.

    Source:Danny Moules
    Published:29 Jan 2009
    7.5
    High

    CVE-2009-0324

    Last Modified: 23 Jan 2017

    Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.

    Source:nuclear
    Published:29 Jan 2009
    10
    Critical

    CVE-2009-0323

    Last Modified: 24 Jan 2017

    Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.

    Source:Core Security
    Published:28 Jan 2009
    4.3
    Medium

    CVE-2009-0321

    Last Modified: 9 Apr 2014

    Apple Safari 3.2.1 (aka AppVer 3.525.27.1) on Windows allows remote attackers to cause a denial of service (infinite loop or access violation) via a link to an http URI in which the authority (aka hostname) portion is either a (1) . (dot) or (2) .. (dot dot) sequence.

    Source:Lostmon
    Published:28 Jan 2009
    4.3
    Medium

    CVE-2009-0307

    Last Modified: 18 Apr 2014

    Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in the MDS Connection Service in Research in Motion (RIM) BlackBerry Enterprise Server (BES) before 4.1.6 MR5 allows remote attackers to inject arbitrary web script or HTML via the (1) customDate, (2) interval, (3) lastCustomInterval, (4) lastIntervalLength, (5) nextCustomInterval, (6) nextIntervalLength, (7) action, (8) delIntervalIndex, (9) addStatIndex, (10) delStatIndex, and (11) referenceTime parameters.

    Source:Ken Millar
    Published:22 Apr 2009
    7.8
    High

    CVE-2009-0304

    Last Modified: 23 Apr 2026

    The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial of service (system crash) via a crafted IPv6 packet, related to an "insufficient validation security vulnerability," as demonstrated by SunOSipv6.c.

    Source:kingcope
    Published:27 Jan 2009
    4.6
    Medium

    CVE-2009-0302

    Last Modified: 23 Nov 2011

    SQL injection vulnerability in the Downloads module for PHP-Nuke 8.0 8.1.0.3.5b and earlier allows remote authenticated users to execute arbitrary SQL commands via the url parameter in the Add operation to modules.php.

    Source:Dante90
    Published:27 Jan 2009
    6.8
    Medium

    CVE-2009-0301

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.6.9 allow remote attackers to create and overwrite arbitrary files via the (1) SaveFile and (2) ExportToXML methods.

    Source:Houssamix
    Published:27 Jan 2009
    Low

    CVE-2009-0300

    Last Modified: 9 Apr 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2636. Reason: This candidate is a duplicate of CVE-2006-2636. Notes: All CVE users should reference CVE-2006-2636 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:FarhadKey
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0299

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:nuclear
    Published:27 Jan 2009
    9.3
    Critical

    CVE-2009-0298

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allows remote attackers to execute arbitrary code via a long Supplement property.

    Source:Houssamix
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0297

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login_check.asp in ClickAuction allows remote attackers to execute arbitrary SQL commands via the (1) txtEmail and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0296

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in shop_display_products.php in Script Toko Online 5.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:k1n9k0ng
    Published:27 Jan 2009
    6.8
    Medium

    CVE-2009-0295

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:fuzion
    Published:27 Jan 2009
    6.8
    Medium

    CVE-2009-0294

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the config[installdir] parameter to (1) search.php, (2) archive.php, (3) comments.php, and (4) news.php; (5) News.php, (6) SendFriend.php, (7) Archive.php, and (8) Comments.php in base/; and possibly other components, different vectors than CVE-2007-1288.

    Source:ahmadbady
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0293

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Source:nuclear
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0292

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in show_cat2.php in SHOP-INET 4 allows remote attackers to execute arbitrary SQL commands via the grid parameter.

    Source:FeDeReR
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0291

    Last Modified: 9 Apr 2014

    Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the MAX_type parameter.

    Source:Sarid Harper
    Published:27 Jan 2009
    6.8
    Medium

    CVE-2009-0290

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the g4_path parameter. NOTE: in some environments, this can be leveraged for remote code execution via a data: URI or a UNC share pathname.

    Source:flyh4t
    Published:27 Jan 2009
    2.6
    Low

    CVE-2009-0286

    Last Modified: 23 Jan 2017

    Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the form_data[script_class] parameter.

    Source:fuzion
    Published:27 Jan 2009
    4.3
    Medium

    CVE-2009-0285

    Last Modified: 8 Apr 2014

    Cross-site scripting (XSS) vulnerability in error.asp in BBSXP 5.13 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:arashps0
    Published:27 Jan 2009