2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-4980Multiple cross-site scripting (XSS) vulnerabilities in Photokorn Gallery 1.81 and earlier allow remote attackers to inje...
CVE-2009-4979Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to exe...
CVE-2009-4978Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .....
CVE-2009-4977PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbi...
CVE-2009-3737The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj m...
CVE-2009-4269The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 perf...
CVE-2009-2696Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application...
CVE-2009-4976Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary we...
CVE-2009-4975Cross-site scripting (XSS) vulnerability in webview.cpp in QtDemoBrowser allows remote attackers to inject arbitrary web...
CVE-2009-4896Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful ...
CVE-2009-4974Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary file...
CVE-2009-4973SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-4972Cross-site scripting (XSS) vulnerability in index.php (aka the log in page) in SimpleID before 0.6.5 allows remote attac...
CVE-2009-4971SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execut...
CVE-2009-4970SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary ...
CVE-2009-4969SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attacke...
CVE-2009-4968SQL injection vulnerability in the Event Registration (event_registr) extension 1.0.0 and earlier for TYPO3 allows remot...
CVE-2009-4967SQL injection vulnerability in the Car (car) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitra...
CVE-2009-4966SQL injection vulnerability in the AST ZipCodeSearch (ast_addresszipsearch) extension 0.5.4 for TYPO3 allows remote atta...
CVE-2009-4965SQL injection vulnerability in the AIRware Lexicon (air_lexicon) extension 0.0.1 for TYPO3 allows remote attackers to ex...
CVE-2009-4964Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a ....
CVE-2009-4963Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated us...
CVE-2009-4962Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a ...
CVE-2009-4961Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls...
CVE-2009-4960Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbit...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now