2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2296 | — | — | 4.4% | Jul 2, 2009 | The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_po... |
| CVE-2009-1421 | — | — | 0.5% | Jul 2, 2009 | Unspecified vulnerability in NFS / ONCplus B.11.31_06 and B.11.31_07 on HP HP-UX B.11.31 allows local users to cause a d... |
| CVE-2009-2293 | — | — | 2.5% | Jul 1, 2009 | Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administ... |
| CVE-2009-2292 | — | — | 1.3% | Jul 1, 2009 | Cross-site scripting (XSS) vulnerability in Appleple a-News 2.32 allows remote attackers to inject arbitrary web script ... |
| CVE-2009-2291 | — | — | 1.2% | Jul 1, 2009 | Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow users to login using... |
| CVE-2009-2290 | — | — | 0.9% | Jul 1, 2009 | SQL injection vulnerability in the Boy Scout Advancement (com_bsadv) component 0.3 and earlier for Joomla! allows remote... |
| CVE-2009-2289 | — | — | 1.4% | Jul 1, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Arcade Trade Script 1.0 beta allows remote attackers to inject ... |
| CVE-2009-2288 | — | — | 83.5% | Jul 1, 2009 | statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t... |
| CVE-2009-2287 | — | — | 0.4% | Jul 1, 2009 | The kvm_arch_vcpu_ioctl_set_sregs function in the KVM in Linux kernel 2.6 before 2.6.30, when running on x86 systems, do... |
| CVE-2009-2286 | — | — | 3.1% | Jul 1, 2009 | Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a ... |
| CVE-2009-2285 | — | — | 8.0% | Jul 1, 2009 | Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial o... |
| CVE-2009-2284 | — | — | 2.0% | Jul 1, 2009 | Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web sc... |
| CVE-2009-2283 | — | — | 1.7% | Jul 1, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5,... |
| CVE-2009-2282 | — | — | 0.4% | Jul 1, 2009 | The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris sn... |
| CVE-2009-2276 | — | — | 0.9% | Jul 1, 2009 | SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote atta... |
| CVE-2009-2275 | — | — | 3.7% | Jul 1, 2009 | Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrar... |
| CVE-2009-2274 | — | — | 0.9% | Jul 1, 2009 | The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, ... |
| CVE-2009-2273 | — | — | 0.7% | Jul 1, 2009 | The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for r... |
| CVE-2009-2271 | — | — | 1.3% | Jul 1, 2009 | The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password ch... |
| CVE-2009-2270 | — | — | 1.8% | Jul 1, 2009 | Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbi... |
| CVE-2009-2269 | — | — | 0.9% | Jul 1, 2009 | SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid para... |
| CVE-2009-2268 | — | — | 1.6% | Jul 1, 2009 | Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager ... |
| CVE-2009-1889 | — | — | 3.4% | Jul 1, 2009 | The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS mess... |
| CVE-2009-0689 | — | — | 28.2% | Jul 1, 2009 | Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation... |
| CVE-2009-2263 | — | — | 2.4% | Jun 30, 2009 | Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include a... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now