2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2785 | — | — | 1.3% | Aug 17, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in PHP Open Classifieds Script allow remote attackers to inject arbi... |
| CVE-2009-2784 | — | — | 3.7% | Aug 17, 2009 | Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to... |
| CVE-2009-2783 | — | — | 1.9% | Aug 17, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.3.3 allow remote attackers to inject arbitrary web script... |
| CVE-2009-2782 | — | — | 0.9% | Aug 17, 2009 | SQL injection vulnerability in the JFusion (com_jfusion) component for Joomla! allows remote attackers to execute arbitr... |
| CVE-2009-2781 | — | — | 0.7% | Aug 17, 2009 | SQL injection vulnerability in forum.php in Arab Portal 2.x, when magic_quotes_gpc is disabled, allows remote authentica... |
| CVE-2009-2780 | — | — | 2.2% | Aug 17, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web... |
| CVE-2009-2779 | — | — | 1.0% | Aug 17, 2009 | SQL injection vulnerability in index.php in AJ Matrix DNA allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2009-2778 | — | — | 1.5% | Aug 14, 2009 | Cross-site scripting (XSS) vulnerability in visitor/view.php in GarageSales Script allows remote attackers to inject arb... |
| CVE-2009-2777 | — | — | 2.0% | Aug 14, 2009 | SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL c... |
| CVE-2009-2776 | — | — | 1.0% | Aug 14, 2009 | SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL comma... |
| CVE-2009-2775 | — | — | 0.9% | Aug 14, 2009 | SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute... |
| CVE-2009-2774 | — | — | 1.0% | Aug 14, 2009 | SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL... |
| CVE-2009-2773 | — | — | 2.9% | Aug 14, 2009 | PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitra... |
| CVE-2009-2772 | — | — | 1.8% | Aug 14, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbi... |
| CVE-2009-2771 | — | — | 1.1% | Aug 14, 2009 | Cross-site scripting (XSS) vulnerability in Free Arcade Script 1.3 allows remote attackers to inject arbitrary web scrip... |
| CVE-2009-2770 | — | — | 2.6% | Aug 14, 2009 | PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value... |
| CVE-2009-2769 | — | — | 1.7% | Aug 14, 2009 | PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is en... |
| CVE-2009-2767 | — | — | 0.7% | Aug 14, 2009 | The init_posix_timers function in kernel/posix-timers.c in the Linux kernel before 2.6.31-rc6 allows local users to caus... |
| CVE-2009-2766 | — | — | 5.1% | Aug 14, 2009 | httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs unde... |
| CVE-2009-2765 | — | — | 82.5% | Aug 14, 2009 | httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers ... |
| CVE-2009-2764 | — | — | 11.0% | Aug 14, 2009 | Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of ... |
| CVE-2009-2691 | — | — | 0.4% | Aug 14, 2009 | The mm_for_maps function in fs/proc/base.c in the Linux kernel 2.6.30.4 and earlier allows local users to read (1) maps ... |
| CVE-2009-2677 | — | — | 1.3% | Aug 14, 2009 | Cross-site request forgery (CSRF) vulnerability in HP Insight Control Suite For Linux (aka ICE-LX) before 2.11 allows re... |
| CVE-2009-2417 | — | — | 3.6% | Aug 14, 2009 | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in ... |
| CVE-2009-2094 | — | — | 0.2% | Aug 13, 2009 | Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local u... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now