2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-4980——Multiple cross-site scripting (XSS) vulnerabilities in Photokorn Gallery 1.81 and earlier allow remote attackers to inje...
CVE-2009-4979——Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to exe...
CVE-2009-4978——Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a .....
CVE-2009-4977——PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbi...
CVE-2009-3737——The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj m...
CVE-2009-4269——The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 perf...
CVE-2009-2696——Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application...
CVE-2009-4976——Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary we...
CVE-2009-4975——Cross-site scripting (XSS) vulnerability in webview.cpp in QtDemoBrowser allows remote attackers to inject arbitrary web...
CVE-2009-4896——Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful ...
CVE-2009-4974——Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary file...
CVE-2009-4973——SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-4972——Cross-site scripting (XSS) vulnerability in index.php (aka the log in page) in SimpleID before 0.6.5 allows remote attac...
CVE-2009-4971——SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execut...
CVE-2009-4970——SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary ...
CVE-2009-4969——SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attacke...
CVE-2009-4968——SQL injection vulnerability in the Event Registration (event_registr) extension 1.0.0 and earlier for TYPO3 allows remot...
CVE-2009-4967——SQL injection vulnerability in the Car (car) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitra...
CVE-2009-4966——SQL injection vulnerability in the AST ZipCodeSearch (ast_addresszipsearch) extension 0.5.4 for TYPO3 allows remote atta...
CVE-2009-4965——SQL injection vulnerability in the AIRware Lexicon (air_lexicon) extension 0.0.1 for TYPO3 allows remote attackers to ex...
CVE-2009-4964——Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a ....
CVE-2009-4963——Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated us...
CVE-2009-4962——Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a ...
CVE-2009-4961——Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls...
CVE-2009-4960——Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbit...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now