2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2329——KerviNet Forum 1.1 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) admin...
CVE-2009-2328——admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remot...
CVE-2009-2327——Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated...
CVE-2009-2326——Multiple SQL injection vulnerabilities in KerviNet Forum 1.1 and earlier allow remote attackers to execute arbitrary SQL...
CVE-2009-2325——Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a...
CVE-2009-2324——Multiple cross-site scripting (XSS) vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to inject arbitra...
CVE-2009-2323——The web interface on the Axesstel MV 410R redirects users back to the referring page after execution of some CGI scripts...
CVE-2009-2322——Cross-site scripting (XSS) vulnerability in cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to injec...
CVE-2009-2321——cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) v...
CVE-2009-2320——The web interface on the Axesstel MV 410R relies on client-side JavaScript code to validate input, which allows remote a...
CVE-2009-2319——The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier ...
CVE-2009-2318——The Axesstel MV 410R allows remote attackers to cause a denial of service via a flood of SYN packets, a related issue to...
CVE-2009-2317——The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it ...
CVE-2009-2316——Multiple cross-site scripting (XSS) vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0 allow remote attackers to ...
CVE-2009-2315——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2204. Reason: This candidate is a duplicate of...
CVE-2009-2314——Race condition in the Sun Lightweight Availability Collection Tool 3.0 on Solaris 7 through 10 allows local users to ove...
CVE-2009-2295——Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary co...
CVE-2009-2294——Integer overflow in the Png_datainfo_callback function in Dillo 2.1 and earlier allows remote attackers to cause a denia...
CVE-2009-2265——Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil...
CVE-2009-1890——The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when ...
CVE-2009-1648——The YaST2 LDAP module in yast2-ldap-server on SUSE Linux Enterprise Server 11 (aka SLE11) does not enable the firewall i...
CVE-2009-1388MEDIUM5.5The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution ...
CVE-2009-0904——The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25...
CVE-2009-2313——Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu...
CVE-2009-2312——SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in config.txt and uses insecure permissio...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now