2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2433——Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a ...
CVE-2009-2432——WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to w...
CVE-2009-2431——WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensi...
CVE-2009-2336——The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password reque...
CVE-2009-2335——WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u...
CVE-2009-2334——wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access t...
CVE-2009-2430——Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Au...
CVE-2009-2429——SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecu...
CVE-2009-2428——Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL command...
CVE-2009-2427——SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-2426——The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before...
CVE-2009-2425——Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router desc...
CVE-2009-2424——Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary we...
CVE-2009-2423——SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands...
CVE-2009-2386——Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions...
CVE-2009-1891——The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associa...
CVE-2009-1725——WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other p...
CVE-2009-1724——Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone...
CVE-2009-0667——Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in O...
CVE-2009-2421——The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a...
CVE-2009-2420——Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitra...
CVE-2009-2419——Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 all...
CVE-2009-2403——Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or ex...
CVE-2009-2402——SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute a...
CVE-2009-2401——Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script o...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now