2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2967Multiple cross-site scripting (XSS) vulnerabilities in Buildbot 0.7.6 through 0.7.11p2 allow remote attackers to inject ...
CVE-2009-2966avp.exe in Kaspersky Internet Security 9.0.0.459 and Anti-Virus 9.0.0.463 allows remote attackers to cause a denial of s...
CVE-2009-2965Cross-site scripting (XSS) vulnerability in entry/index.jsp in Radvision Scopia 5.7, and possibly other versions before ...
CVE-2009-2964Multiple cross-site request forgery (CSRF) vulnerabilities in SquirrelMail 1.4.19 and earlier, and NaSMail before 1.7, a...
CVE-2009-2963Unspecified vulnerability in the update feature in Toolbar Uninstaller 1.0.2 allows remote attackers to force the downlo...
CVE-2009-2961Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (cras...
CVE-2009-2960CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to m...
CVE-2009-2959Cross-site scripting (XSS) vulnerability in the waterfall web status view (status/web/waterfall.py) in Buildbot 0.7.6 th...
CVE-2009-2956The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the w...
CVE-2009-2955Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption and applicati...
CVE-2009-2954Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU consumpt...
CVE-2009-2953Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) ...
CVE-2009-2952Unspecified vulnerability in the pollwakeup function in Sun Solaris 10, and OpenSolaris before snv_51, allows local user...
CVE-2009-2951Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dep...
CVE-2009-2934Multiple stack-based buffer overflows in xaudio.dll in Programmed Integration PIPL 2.5.0 and 2.5.0D allow remote attacke...
CVE-2009-2933SQL injection vulnerability in comments.php in Piwigo before 2.0.3 allows remote attackers to execute arbitrary SQL comm...
CVE-2009-2932Cross-site scripting (XSS) vulnerability in uddiclient/process in the UDDI client in SAP NetWeaver Application Server (J...
CVE-2009-2931Directory traversal vulnerability in p.php in SlideShowPro Director 1.1 through 1.3.8 allows remote attackers to read ar...
CVE-2009-2930Cross-site scripting (XSS) vulnerability in the Search feature in elka CMS (aka Elkapax) allows remote attackers to inje...
CVE-2009-2929Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL com...
CVE-2009-2928Cross-site scripting (XSS) vulnerability in login.php in TGS Content Management 0.x allows remote attackers to inject ar...
CVE-2009-2927SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary...
CVE-2009-2926Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute...
CVE-2009-2474neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the su...
CVE-2009-2473neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now