2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2373Cross-site scripting (XSS) vulnerability in the Forum module in Drupal 6.x before 6.13 allows remote attackers to inject...
CVE-2009-2372Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has bee...
CVE-2009-2371Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the ...
CVE-2009-2370Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupa...
CVE-2009-2369Integer overflow in the wxImage::Create function in src/common/image.cpp in wxWidgets 2.8.10 allows attackers to cause a...
CVE-2009-2368Unspecified vulnerability in Socks Server 5 before 3.7.8-8 has unknown impact and attack vectors.
CVE-2009-2366SQL injection vulnerability in login.asp in DataCheck Solutions ForumPal FE 1.1 and ForumPal 1.5 allows remote attackers...
CVE-2009-2365SQL injection vulnerability in login.asp in DataCheck Solutions GalleryPal FE 1.5 allows remote attackers to execute arb...
CVE-2009-2364Stack-based buffer overflow in Mp3-Nator 2.0 allows remote attackers to execute arbitrary code via (1) a long string in ...
CVE-2009-2363Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls ...
CVE-2009-2362Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long...
CVE-2009-2361SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb...
CVE-2009-2360Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at...
CVE-2009-2359Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL comma...
CVE-2009-2358TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated...
CVE-2009-2357The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it ...
CVE-2009-2356Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, ...
CVE-2009-2355The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (applicatio...
CVE-2009-2354SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote ...
CVE-2009-2353encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a lo...
CVE-2009-2352Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows ...
CVE-2009-2351Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attacke...
CVE-2009-2350Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP respons...
CVE-2009-2345Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL com...
CVE-2009-2344The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now