2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2422CRITICAL9.8The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defi...
CVE-2009-2386——Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions...
CVE-2009-1891——The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associa...
CVE-2009-1725——WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone OS before 3.1.1 for iPod touch, and other p...
CVE-2009-1724——Cross-site scripting (XSS) vulnerability in WebKit in Apple Safari before 4.0.2, as used on iPhone OS before 3.1, iPhone...
CVE-2009-0667——Untrusted search path vulnerability in Agent/Backend.pm in Ocsinventory-Agent before 0.0.9.3, and 1.x before 1.0.1, in O...
CVE-2009-2421——The CFCharacterSetInitInlineBuffer method in CoreFoundation.dll in Apple Safari 3.2.3 allows remote attackers to cause a...
CVE-2009-2420——Apple Safari 3.2.3 does not properly implement the file: protocol handler, which allows remote attackers to read arbitra...
CVE-2009-2419——Use-after-free vulnerability in the servePendingRequests function in WebCore in WebKit in Apple Safari 4.0 and 4.0.1 all...
CVE-2009-2403——Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or ex...
CVE-2009-2402——SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute a...
CVE-2009-2401——Cross-site scripting (XSS) vulnerability in PHPEcho CMS 2.0-rc3 allows remote attackers to inject arbitrary web script o...
CVE-2009-2400——SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL ...
CVE-2009-2399——PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals i...
CVE-2009-2398——Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files vi...
CVE-2009-2397——Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary f...
CVE-2009-2396——PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p...
CVE-2009-2395——SQL injection vulnerability in the K2 (com_k2) component 1.0.1 Beta and earlier for Joomla! allows remote attackers to e...
CVE-2009-2394——SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allow...
CVE-2009-2393——admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remo...
CVE-2009-2392——SQL injection vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to execute ar...
CVE-2009-2391——Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers ...
CVE-2009-2390——SQL injection vulnerability in the BookFlip (com_bookflip) component 2.1 for Joomla! allows remote attackers to execute ...
CVE-2009-2389——Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, ...
CVE-2009-2388——SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now