2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2444Directory traversal vulnerability in maillinglist/setup/step1.php.inc in ADbNewsSender before 1.5.6, and 2.0 before RC2,...
CVE-2009-2443Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct requ...
CVE-2009-2442Cross-site scripting (XSS) vulnerability in public/index.php in Linea21 1.2.1 allows remote attackers to inject arbitrar...
CVE-2009-2441Cross-site scripting (XSS) vulnerability in ogp_show.php in Online Guestbook Pro 5.1 allows remote attackers to inject a...
CVE-2009-2440Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary w...
CVE-2009-2439Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrar...
CVE-2009-2438Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remo...
CVE-2009-2437Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject a...
CVE-2009-2436SQL injection vulnerability in page.php in Online Dating Software MyPHPDating 1.0 allows remote attackers to execute arb...
CVE-2009-2435The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logo...
CVE-2009-2434Buffer overflow in the syscall implementation in IBM AIX 5.3 allows local users to gain privileges via unspecified vecto...
CVE-2009-2433Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a ...
CVE-2009-2432WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to w...
CVE-2009-2431WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensi...
CVE-2009-2336The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password reque...
CVE-2009-2335WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u...
CVE-2009-2334wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access t...
CVE-2009-2430Unspecified vulnerability in auditconfig in Sun Solaris 8, 9, 10, and OpenSolaris snv_01 through snv_58, when Solaris Au...
CVE-2009-2429SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecu...
CVE-2009-2428Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL command...
CVE-2009-2427SQL injection vulnerability in co-profile.php in Jobbr 2.2.7 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-2426The connection_edge_process_relay_cell_not_open function in src/or/relay.c in Tor 0.2.x before 0.2.0.35 and 0.1.x before...
CVE-2009-2425Tor before 0.2.0.35 allows remote attackers to cause a denial of service (application crash) via a malformed router desc...
CVE-2009-2424Cross-site scripting (XSS) vulnerability in search.php in Ebay Clone 2009 allows remote attackers to inject arbitrary we...
CVE-2009-2423SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now