2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2329KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin...
CVE-2009-2328admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remot...
CVE-2009-2327Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated...
CVE-2009-2326Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL...
CVE-2009-2325Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a...
CVE-2009-2324Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitra...
CVE-2009-2323The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts...
CVE-2009-2322Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to injec...
CVE-2009-2321cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) v...
CVE-2009-2320The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote a...
CVE-2009-2319The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier ...
CVE-2009-2318The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to...
CVE-2009-2317The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it ...
CVE-2009-2316Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to ...
CVE-2009-2315Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2204. Reason: This candidate is a duplicate of...
CVE-2009-2314Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to ove...
CVE-2009-2295Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary co...
CVE-2009-2294Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denia...
CVE-2009-2265Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil...
CVE-2009-1890The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when ...
CVE-2009-1648The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall i...
CVE-2009-1388MEDIUM5.5The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution ...
CVE-2009-0904The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25...
CVE-2009-2313Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu...
CVE-2009-2312SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissio...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now