Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2008-5945

Published Jan 22, 2009

Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provenance of this information is unk…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5944

Published Jan 22, 2009

Cross-site scripting (XSS) vulnerability in modules.php in NavBoard 16 (2.6.0) allows remote attackers to inject arbitrary web script or HTML via the module parameter.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5943

Published Jan 22, 2009

Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the module parameter…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5942

Published Jan 22, 2009

Multiple cross-site scripting (XSS) vulnerabilities in MODx before 0.9.6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the preserveUrl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5941

Published Jan 22, 2009

Cross-site request forgery (CSRF) vulnerability in MODx 0.9.6.1p2 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5940

Published Jan 22, 2009

SQL injection vulnerability in index.php in MODx 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the searchid…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5939

Published Jan 22, 2009

Cross-site scripting (XSS) vulnerability in index.php in MODx CMS 0.9.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5938

Published Jan 22, 2009

PHP remote file inclusion vulnerability in assets/snippets/reflect/snippet.reflect.php in MODx CMS 0.9.6.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0245

Published Jan 22, 2009

Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a diff…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5937

Published Jan 22, 2009

AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a bitmap (aka .bmp) file with large height and width values.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5936

Published Jan 22, 2009

front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a filename in the sFileName parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0244

Published Jan 21, 2009

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0030

Published Jan 21, 2009

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to access other users' folder lists a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0026

Published Jan 21, 2009

Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject arbitrary web script or HTML via the q parameter to (1) sear…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0007

Published Jan 21, 2009

Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Q…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-0006

Published Jan 21, 2009

Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a Cin…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 5,451-5,475 of 5,732 CVEsPage 219 of 230