7.5
    High

    CVE-2009-0284

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:JIKO
    Published:27 Jan 2009
    4.3
    Medium

    CVE-2009-0283

    Last Modified: 8 Apr 2014

    Cross-site scripting (XSS) vulnerability in err.asp in Oblog allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Source:arash.setayeshi
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0281

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.aspx in WarHound Walking Club allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Source:ByALBAYX
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0280

    Last Modified: 23 Jan 2017

    Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

    Source:Khashayar Fereidani
    Published:27 Jan 2009
    7.5
    High

    CVE-2009-0279

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in comentar.php in Pardal CMS 0.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:darkjoker
    Published:27 Jan 2009
    6.5
    Medium

    CVE-2009-0275

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Osirys
    Published:26 Jan 2009
    9.3
    Critical

    CVE-2009-0266

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Triologic Media Player 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3l playlist file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:zAx
    Published:26 Jan 2009
    10
    Critical

    CVE-2009-0263

    Last Modified: 23 Jan 2017

    Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file.

    Source:securfrog
    Published:23 Jan 2009
    9.3
    Critical

    CVE-2009-0262

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.

    Source:zAx
    Published:23 Jan 2009
    9.3
    Critical

    CVE-2009-0261

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary code via a Skins\DefaultSkin\DefaultSkin.ini file with a large ColumnHeaderSpan value.

    Source:His0k4
    Published:23 Jan 2009
    4.3
    Medium

    CVE-2009-0260

    Last Modified: 8 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename parameter or (2) the drawing parameter (aka the basename variable).

    Source:SecureState
    Published:23 Jan 2009
    9.3
    Critical

    CVE-2009-0259

    Last Modified: 23 Apr 2026

    The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.

    Source:securfrog
    Published:9 Dec 2008
    6.8
    Medium

    CVE-2009-0253

    Last Modified: 23 Jan 2017

    Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.

    Source:MrDoug
    Published:21 Jan 2009
    7.5
    High

    CVE-2009-0252

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arbitrary SQL commands via the (1) Login parameter (aka username field) or the (2) Password parameter (aka password field). NOTE: some of these details are obtained from third party information.

    Source:ByALBAYX
    Published:22 Jan 2009
    6.5
    Medium

    CVE-2009-0251

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/footer via the footer parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: some of these details are obtained from third party information.

    Source:Osirys
    Published:22 Jan 2009
    5
    Medium

    CVE-2009-0250

    Last Modified: 23 Apr 2026

    Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the file containing the administrator's password hash via a direct request for config/password.

    Source:Osirys
    Published:22 Jan 2009
    5
    Medium

    CVE-2009-0249

    Last Modified: 4 Jan 2017

    Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for database/topsites.mdb.

    Source:Pouya_Server
    Published:22 Jan 2009
    4.3
    Medium

    CVE-2009-0248

    Last Modified: 4 Jan 2017

    Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrary web script or HTML via the siteID parameter.

    Source:Pouya_Server
    Published:22 Jan 2009
    7.5
    High

    CVE-2009-0241

    Last Modified: 7 Apr 2014

    Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname.

    Source:Spike Spiegel
    Published:13 Jan 2009
    4.9
    Medium

    CVE-2009-0229

    Last Modified: 23 Apr 2026

    The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows local users to read arbitrary files via a crafted separator page, aka "Print Spooler Read File Vulnerability."

    Published:10 Jun 2009
    9.3
    Critical

    CVE-2009-0215

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Metasploit
    Published:25 Mar 2009
    5
    Medium

    CVE-2009-0192

    Last Modified: 23 Apr 2026

    Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.

    Source:Praveen Darshanam
    Published:14 Jul 2009
    9.3
    Critical

    CVE-2009-0187

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote attackers to execute arbitrary code via a crafted HTTP URL with a long host name, which is not properly handled when constructing a "Connecting" log message.

    Source:Metasploit
    Published:26 Feb 2009
    9.3
    Critical

    CVE-2009-0184

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.

    Source:Carsten Eiram
    Published:3 Feb 2009
    10
    Critical

    CVE-2009-0183

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request.

    Source:Praveen Darshanam
    Published:3 Feb 2009
    8.8
    High

    CVE-2009-0182

    Last Modified: 27 Apr 2011

    Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL on a File1 line.

    Source:SkD
    Published:20 Jan 2009
    5
    Medium

    CVE-2009-0177

    Last Modified: 11 Jan 2017

    vmwarebase.dll, as used in the vmware-authd service (aka vmware-authd.exe), in VMware Workstation 6.5.1 build 126130, 6.5.1 and earlier; VMware Player 2.5.1 build 126130, 2.5.1 and earlier; VMware ACE 2.5.1 and earlier; VMware Server 2.0.x before 2.0.1 build 156745; and VMware Fusion before 2.0.2 build 147997 allows remote attackers to cause a denial of service (daemon crash) via a long (1) USER or (2) PASS command.

    Source:laurent gaffié
    Published:20 Jan 2009
    9.3
    Critical

    CVE-2009-0175

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.

    Source:Houssamix
    Published:20 Jan 2009
    9.3
    Critical

    CVE-2009-0174

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.

    Source:aBo MoHaMeD
    Published:20 Jan 2009
    5
    Medium

    CVE-2009-0172

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNECT data stream.

    Source:Dennis Yurichev
    Published:16 Jan 2009
    4.3
    Medium

    CVE-2009-0162

    Last Modified: 23 Apr 2014

    Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7 and Windows allows remote attackers to inject arbitrary web script or HTML via a crafted feed: URL.

    Source:Billy Rios
    Published:13 May 2009
    9.3
    Critical

    CVE-2009-0134

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

    Source:Houssamix
    Published:16 Jan 2009
    10
    Critical

    CVE-2009-0133

    Last Modified: 14 Sept 2016

    Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.

    Source:darkeagle
    Published:15 Jan 2009
    7.5
    High

    CVE-2009-0121

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:darkjoker
    Published:15 Jan 2009
    7.8
    High

    CVE-2009-0120

    Last Modified: 7 Apr 2014

    The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.

    Source:Erik
    Published:15 Jan 2009
    10
    Critical

    CVE-2009-0119

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .chm file.

    Source:securfrog
    Published:14 Jan 2009
    5
    Medium

    CVE-2009-0113

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the X_CMS_LIBRARY_PATH HTTP header.

    Source:irk4z
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0111

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:darkjoker
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0110

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Source:cOndemned
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0109

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Source:ZoRLu
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0108

    Last Modified: 23 Apr 2026

    PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID, (2) PHPAUCTION_RM_NAME, (3) PHPAUCTION_RM_USERNAME, and (4) PHPAUCTION_RM_EMAIL cookies.

    Source:ZoRLu
    Published:9 Jan 2009
    4.3
    Medium

    CVE-2009-0107

    Last Modified: 12 Jan 2017

    Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to inject arbitrary web script or HTML via the user_id parameter.

    Source:x0r
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0106

    Last Modified: 12 Jan 2017

    SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Source:x0r
    Published:9 Jan 2009
    4.3
    Medium

    CVE-2009-0105

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web script or HTML via the mdfd parameter in a prog action.

    Source:!-BUGJACK-!
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0104

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via the qType parameter in a webboard prog action.

    Source:!-BUGJACK-!
    Published:9 Jan 2009
    7.5
    High

    CVE-2009-0103

    Last Modified: 23 Jan 2017

    Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/gateway/gnokii/init.php, the (2) apps_path[themes] parameter to plugin/themes/default/init.php, and the (3) apps_path[libs] parameter to lib/function.php.

    Source:ahmadbady
    Published:9 Jan 2009
    6.9
    Medium

    CVE-2009-0080

    Last Modified: 17 Apr 2014

    The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."

    Source:Cesar Cerrudo
    Published:15 Apr 2009
    6.9
    Medium

    CVE-2009-0079

    Last Modified: 17 Apr 2014

    The RPCSS service in Microsoft Windows XP SP2 and SP3 and Server 2003 SP1 and SP2 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows RPCSS Service Isolation Vulnerability."

    Source:Cesar Cerrudo
    Published:15 Apr 2009
    7.2
    High

    CVE-2009-0078

    Last Modified: 17 Apr 2014

    The Windows Management Instrumentation (WMI) provider in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by accessing the resources of one of the processes, aka "Windows WMI Service Isolation Vulnerability."

    Source:Cesar Cerrudo
    Published:15 Apr 2009
    9.3
    Critical

    CVE-2009-0076

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directive in conjunction with unspecified other directives in a malformed Cascading Style Sheets (CSS) stylesheet in a crafted HTML document, aka "CSS Memory Corruption Vulnerability."

    Source:webDEViL
    Published:10 Feb 2009