2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2361——SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arb...
CVE-2009-2360——Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at...
CVE-2009-2359——Multiple SQL injection vulnerabilities in TekRADIUS 3.0 allow context-dependent attackers to execute arbitrary SQL comma...
CVE-2009-2358——TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated...
CVE-2009-2357——The default configuration of TekRADIUS 3.0 uses the sa account to communicate with Microsoft SQL Server, which makes it ...
CVE-2009-2356——Multiple stack-based buffer overflows in the pgsqlQuery function in NullLogic Groupware 1.2.7, when PostgreSQL is used, ...
CVE-2009-2355——The forum module in NullLogic Groupware 1.2.7 allows remote authenticated users to cause a denial of service (applicatio...
CVE-2009-2354——SQL injection vulnerability in the auth_checkpass function in the login page in NullLogic Groupware 1.2.7 allows remote ...
CVE-2009-2353——encoder.php in eAccelerator allows remote attackers to execute arbitrary code by copying a local executable file to a lo...
CVE-2009-2352——Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows ...
CVE-2009-2351——Opera 9.52 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attacke...
CVE-2009-2350——Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP respons...
CVE-2009-2345——Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL com...
CVE-2009-2344——The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica...
CVE-2009-2343——Cross-site scripting (XSS) vulnerability in people.php in Zoph before 0.7.0.6 allows remote attackers to inject arbitrar...
CVE-2009-2342——Cross-site scripting (XSS) vulnerability in admin.php (aka the login page) in Content Management Made Easy (CMME) before...
CVE-2009-2341——SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2340——SQL injection vulnerability in admin/index.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2339——SQL injection vulnerability in index.php in Rentventory allows remote attackers to execute arbitrary SQL commands via th...
CVE-2009-2338——Directory traversal vulnerability in includes/startmodules.inc.php in FreeWebshop.org 2.2.9 R2, when register_globals is...
CVE-2009-2337——SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag...
CVE-2009-2333——Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut...
CVE-2009-2332——CMS Chainuk 1.2 and earlier allows remote attackers to obtain sensitive information via (1) a crafted id parameter to in...
CVE-2009-2331——Multiple static code injection vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to inject arbitrary...
CVE-2009-2330——Cross-site scripting (XSS) vulnerability in admin/admin_menu.php in CMS Chainuk 1.2 and earlier allows remote attackers ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now