9.3
    Critical

    CVE-2009-0075

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, aka "Uninitialized Memory Corruption Vulnerability."

    Source:anonymous
    Published:10 Feb 2009
    2.6
    Low

    CVE-2009-0071

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call. NOTE: it was later reported that 3.0.6 and 3.0.7 are also affected.

    Source:Skylined
    Published:8 Jan 2009
    9.3
    Critical

    CVE-2009-0070

    Last Modified: 23 Apr 2026

    Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.

    Source:Skylined
    Published:8 Jan 2009
    10
    Critical

    CVE-2009-0065

    Last Modified: 22 Nov 2017

    Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.28-git8 allows remote attackers to have an unknown impact via an FWD-TSN (aka FORWARD-TSN) chunk with a large stream ID.

    Source:sgrakkyu
    Published:26 Dec 2008
    10
    Critical

    CVE-2009-0043

    Last Modified: 7 Apr 2014

    The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.

    Source:Michel Arboi
    Published:8 Jan 2009
    6.8
    Medium

    CVE-2009-0039

    Last Modified: 18 Apr 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to hijack the authentication of administrators for requests that (1) change the web administration password, (2) upload applications, and perform unspecified other administrative actions, as demonstrated by (3) a Shutdown request to console/portal//Server/Shutdown.

    Source:DSecRG
    Published:17 Apr 2009
    4.3
    Medium

    CVE-2009-0038

    Last Modified: 18 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) ip, (3) username, or (4) description parameter to console/portal/Server/Monitoring; or (5) the PATH_INFO to the default URI under console/portal/.

    Source:DSecRG
    Published:17 Apr 2009
    6.8
    Medium

    CVE-2009-0037

    Last Modified: 13 Apr 2014

    The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3) execute arbitrary commands via a redirect to an scp: URL.

    Source:David Kierznowski
    Published:3 Mar 2009
    4.4
    Medium

    CVE-2009-0036

    Last Modified: 23 Apr 2026

    Buffer overflow in the proxyReadClientSocket function in proxy/libvirt_proxy.c in libvirt_proxy 0.5.1 might allow local users to gain privileges by sending a portion of the header of a virProxyPacket packet, and then sending the remainder of the packet with crafted values in the header, related to use of uninitialized memory in a validation check.

    Source:Jon Oberheide
    Published:27 Jan 2009
    2.1
    Low

    CVE-2009-0028

    Last Modified: 11 Apr 2014

    The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new process exit.

    Source:Chris Evans
    Published:25 Feb 2009
    4.3
    Medium

    CVE-2009-0026

    Last Modified: 8 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) search.jsp or (2) swr.jsp.

    Source:Red Hat
    Published:20 Jan 2009
    7.5
    High

    CVE-2008-7301

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in admin/login.php in jSite 1.0 OE allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:S.W.A.T.
    Published:5 Oct 2011
    4.3
    Medium

    CVE-2008-7271

    Last Modified: 27 Oct 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647.

    Source:Rob
    Published:24 Apr 2008
    5.8
    Medium

    CVE-2008-7269

    Last Modified: 26 Mar 2014

    Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.

    Source:xuanmumu
    Published:1 Dec 2010
    7.5
    High

    CVE-2008-7267

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:xy7
    Published:1 Dec 2010
    2.1
    Low

    CVE-2008-7258

    Last Modified: 20 Aug 2014

    The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue because it is solely a usability problem for senders of messages with certain long lines, and has no security impact

    Source:Brendan Boerner
    Published:20 Aug 2010
    4.3
    Medium

    CVE-2008-7257

    Last Modified: 29 Jul 2014

    CRLF injection vulnerability in +webvpn+/index.html in WebVPN on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary HTTP headers as demonstrated by a redirect attack involving a %0d%0aLocation%3a sequence in a URI, or conduct HTTP response splitting attacks via unspecified vectors, aka Bug ID CSCsr09163.

    Source:Daniel King
    Published:29 Jun 2010
    6.8
    Medium

    CVE-2008-7254

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, when register_globals is enabled, allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the _Root_Path parameter. NOTE: some of these details are obtained from third party information.

    Source:eidelweiss
    Published:7 Apr 2010
    6.8
    Medium

    CVE-2008-7248

    Last Modified: 18 May 2014

    Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

    Source:p0deje
    Published:18 Nov 2008
    5
    Medium

    CVE-2008-7246

    Last Modified: 23 Apr 2026

    Google Chrome 0.2.149.29 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Source:Dr_IDE
    Published:18 Sept 2009
    5
    Medium

    CVE-2008-7245

    Last Modified: 23 Apr 2026

    Opera 9.52 and earlier allows remote attackers to cause a denial of service (unusable browser) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Source:Dr_IDE
    Published:18 Sept 2009
    5
    Medium

    CVE-2008-7244

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.

    Source:Dr_IDE
    Published:19 Sept 2008
    4.3
    Medium

    CVE-2008-7242

    Last Modified: 22 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject arbitrary web script or HTML via the (1) search, (2) "a," (3) messagesubject, and (4) messagebody parameters to certain pages as reachable from manager/index.php; (5) highlight, (6) id, (7) email, (8) name, and (9) parent parameters to index.php; and the (10) docgrp and (11) moreResultsPage parameters to index-ajax.php.

    Source:Alexandr Polyakov
    Published:17 Sept 2009
    7.5
    High

    CVE-2008-7240

    Last Modified: 14 Nov 2016

    Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows remote attackers to include and execute arbitrary local files via the template parameter.

    Source:BeyazKurt
    Published:17 Sept 2009
    10
    Critical

    CVE-2008-7232

    Last Modified: 1 Apr 2017

    Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted CONNECT TACACS command.

    Source:MC
    Published:14 Sept 2009
    7.5
    High

    CVE-2008-7226

    Last Modified: 30 Jan 2014

    SQL injection vulnerability in index.php in the Recipes module 1.3, 1.4, and possibly other versions for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the recipeid parameter.

    Source:S@BUN
    Published:14 Sept 2009
    4.3
    Medium

    CVE-2008-7222

    Last Modified: 28 Jan 2014

    Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action.

    Source:NBBN
    Published:14 Sept 2009
    7.5
    High

    CVE-2008-7220

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Prototype JavaScript framework (prototypejs) before 1.6.0.2 allows attackers to make "cross-site ajax requests" via unknown vectors.

    Published:23 Jan 2008
    4.3
    Medium

    CVE-2008-7216

    Last Modified: 19 Jan 2014

    Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip.

    Source:Romero
    Published:11 Sept 2009
    4.3
    Medium

    CVE-2008-7213

    Last Modified: 20 Jan 2014

    Cross-site scripting (XSS) vulnerability in mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php in MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to inject arbitrary web script or HTML via the Command parameter.

    Source:AmnPardaz
    Published:11 Sept 2009
    6.9
    Medium

    CVE-2008-7211

    Last Modified: 20 Jan 2014

    CreativeLabs es1371mp.sys 5.1.3612.0 WDM audio driver, as used in Ensoniq PCI 1371 sound cards and when running on Windows Vista, does not create a Functional Device Object (FDO) to prevent user-moade access to the Physical Device Object (PDO), which allows local users to gain SYSTEM privileges via a crafted IRP request that dereferences a NULL FsContext pointer.

    Source:Ruben Santamarta
    Published:11 Sept 2009
    7.5
    High

    CVE-2008-7210

    Last Modified: 8 Nov 2016

    directory.php in AJchat 0.10 allows remote attackers to bypass input validation and conduct SQL injection attacks via a numeric parameter with a value matching the s parameter's hash value, which prevents the associated $_GET["s"] variable from being unset. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in AJChat.

    Source:Eugene Minaev
    Published:11 Sept 2009
    7.5
    High

    CVE-2008-7209

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file with an executable extension and using a safe content type such as image/gif, then accessing it via a direct request to the file in an unspecified directory.

    Source:BugReport.IR
    Published:11 Sept 2009
    6.8
    Medium

    CVE-2008-7208

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in OneCMS 2.4, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) username parameter ($usernameb variable) to a_login.php or (2) user parameter to staff.php.

    Source:BugReport.IR
    Published:11 Sept 2009
    5
    Medium

    CVE-2008-7203

    Last Modified: 23 Apr 2026

    Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple crafted login packets.

    Source:Eugene Minaev
    Published:11 Sept 2009
    6.8
    Medium

    CVE-2008-7192

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.x versions, allows remote attackers to hijack the authentication of users for requests that delete private messages via the pmID parameter in a delete action in a PM page, a different vulnerability than CVE-2008-0472.

    Source:StAkeR
    Published:9 Sept 2009
    7.5
    High

    CVE-2008-7188

    Last Modified: 23 Apr 2026

    ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via a modified uid variable to siteadmin/useredit.php. NOTE: this can be used to recover the password of the user by using the modified e-mail address in the email parameter to recoverpass.php.

    Source:Pr0metheuS
    Published:9 Sept 2009
    4.3
    Medium

    CVE-2008-7185

    Last Modified: 28 Feb 2014

    GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlist (.pls) file with a long Title field, possibly related to the g_hash_table_lookup function in b-playlist-manager.c.

    Source:Juan Pablo Lopez Yacubian
    Published:8 Sept 2009
    4.3
    Medium

    CVE-2008-7184

    Last Modified: 25 Feb 2014

    Cross-site scripting (XSS) vulnerability in Diigo Toolbar and Diigolet allows remote attackers to inject arbitrary web script or HTML via a public comment.

    Source:Ferruh Mavituna
    Published:8 Sept 2009
    4
    Medium

    CVE-2008-7182

    Last Modified: 23 Apr 2026

    Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long first argument to the APPEND command, a different vector than CVE-2008-1497 and CVE-2008-1498. NOTE: due to lack of details, it is not certain whether this is the same issue as CVE-2008-2859.

    Source:Travis Warren
    Published:8 Sept 2009
    7.5
    High

    CVE-2008-7181

    Last Modified: 23 Apr 2026

    Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with the is_js_confirmed parameter set to 1, or (2) delete arbitrary accounts via the mytable parameter to delete.php.

    Source:Stack
    Published:8 Sept 2009
    5
    Medium

    CVE-2008-7180

    Last Modified: 7 Dec 2016

    del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request with a modified id variable.

    Source:Stack
    Published:8 Sept 2009
    7.5
    High

    CVE-2008-7179

    Last Modified: 14 Dec 2016

    OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADMIN_Nome cookies to certain values, as reachable in Admin/index.php.

    Source:Virangar Security
    Published:8 Sept 2009
    7.5
    High

    CVE-2008-7178

    Last Modified: 7 Dec 2016

    Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.

    Source:MEEKAAH
    Published:8 Sept 2009
    6.8
    Medium

    CVE-2008-7176

    Last Modified: 7 Dec 2016

    Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) change_lang parameter to index.php or (2) modload parameter to modules.php.

    Source:CWH Underground
    Published:8 Sept 2009
    7.5
    High

    CVE-2008-7172

    Last Modified: 8 Dec 2016

    Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administrator privileges via direct requests to admin.php with the (1) potd_delete, (2) potd, (3) vote_update, (4) vote, or (5) modifynews actions.

    Source:storm
    Published:8 Sept 2009
    4.3
    Medium

    CVE-2008-7171

    Last Modified: 8 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Lightweight news portal (LNP) 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) photo parameter to show_photo.php, (2) potd parameter to show_potd.php, or (3) the Current question field in a vote action to admin.php.

    Source:storm
    Published:8 Sept 2009
    10
    Critical

    CVE-2008-7170

    Last Modified: 9 Apr 2014

    GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator commands via a crafted packet.

    Source:Michael Gray
    Published:8 Sept 2009
    7.5
    High

    CVE-2008-7169

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a sign task to index.php.

    Source:His0k4
    Published:8 Sept 2009
    9.3
    Critical

    CVE-2008-7168

    Last Modified: 28 Feb 2014

    Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.

    Source:Symantec
    Published:8 Sept 2009