2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2373 | — | — | 1.8% | Jul 8, 2009 | Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject... |
| CVE-2009-2372 | — | — | 2.3% | Jul 8, 2009 | Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has bee... |
| CVE-2009-2371 | — | — | 1.1% | Jul 8, 2009 | Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the ... |
| CVE-2009-2370 | — | — | 1.3% | Jul 8, 2009 | Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupa... |
| CVE-2009-2369 | — | — | 2.8% | Jul 8, 2009 | Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a... |
| CVE-2009-2368 | — | — | 1.4% | Jul 8, 2009 | Unspecified vulnerability in Socks Server 5 before 3.7.8-8 has unknown impact and attack vectors. |
| CVE-2009-2366 | — | — | 1.1% | Jul 8, 2009 | SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers... |
| CVE-2009-2365 | — | — | 1.0% | Jul 8, 2009 | SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arb... |
| CVE-2009-2364 | — | — | 10.1% | Jul 8, 2009 | Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in ... |
| CVE-2009-2363 | — | — | 6.1% | Jul 8, 2009 | Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls ... |
| CVE-2009-2362 | — | — | 7.2% | Jul 8, 2009 | Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long... |
| CVE-2009-2361 | — | — | 5.2% | Jul 8, 2009 | SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb... |
| CVE-2009-2360 | — | — | 5.1% | Jul 8, 2009 | Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at... |
| CVE-2009-2359 | — | — | 0.9% | Jul 7, 2009 | Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL comma... |
| CVE-2009-2358 | — | — | 0.3% | Jul 7, 2009 | TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated... |
| CVE-2009-2357 | — | — | 2.1% | Jul 7, 2009 | The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it ... |
| CVE-2009-2356 | — | — | 3.9% | Jul 7, 2009 | Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, ... |
| CVE-2009-2355 | — | — | 1.1% | Jul 7, 2009 | The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (applicatio... |
| CVE-2009-2354 | — | — | 1.1% | Jul 7, 2009 | SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote ... |
| CVE-2009-2353 | — | — | 2.0% | Jul 7, 2009 | encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a lo... |
| CVE-2009-2352 | — | — | 2.0% | Jul 7, 2009 | Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows ... |
| CVE-2009-2351 | — | — | 1.7% | Jul 7, 2009 | Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attacke... |
| CVE-2009-2350 | — | — | 14.4% | Jul 7, 2009 | Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP respons... |
| CVE-2009-2345 | — | — | 1.1% | Jul 7, 2009 | Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL com... |
| CVE-2009-2344 | — | — | 9.3% | Jul 7, 2009 | The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now