2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2285 | — | — | 8.0% | Jul 1, 2009 | Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial o... |
| CVE-2009-2284 | — | — | 2.0% | Jul 1, 2009 | Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web sc... |
| CVE-2009-2283 | — | — | 1.7% | Jul 1, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5,... |
| CVE-2009-2282 | — | — | 0.4% | Jul 1, 2009 | The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris sn... |
| CVE-2009-2276 | — | — | 0.9% | Jul 1, 2009 | SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote atta... |
| CVE-2009-2275 | — | — | 3.7% | Jul 1, 2009 | Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrar... |
| CVE-2009-2274 | — | — | 0.9% | Jul 1, 2009 | The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, ... |
| CVE-2009-2273 | — | — | 0.7% | Jul 1, 2009 | The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for r... |
| CVE-2009-2272 | HIGH | 7.5 | 0.6% | Jul 1, 2009 | The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-depe... |
| CVE-2009-2271 | — | — | 1.3% | Jul 1, 2009 | The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password ch... |
| CVE-2009-2270 | — | — | 1.8% | Jul 1, 2009 | Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbi... |
| CVE-2009-2269 | — | — | 0.9% | Jul 1, 2009 | SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid para... |
| CVE-2009-2268 | — | — | 1.6% | Jul 1, 2009 | Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager ... |
| CVE-2009-1889 | — | — | 3.4% | Jul 1, 2009 | The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS mess... |
| CVE-2009-0689 | — | — | 28.2% | Jul 1, 2009 | Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation... |
| CVE-2009-2263 | — | — | 2.4% | Jun 30, 2009 | Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include a... |
| CVE-2009-2262 | — | — | 1.2% | Jun 30, 2009 | PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary... |
| CVE-2009-2261 | — | — | 41.4% | Jun 30, 2009 | PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z... |
| CVE-2009-2260 | — | — | 2.1% | Jun 30, 2009 | stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which al... |
| CVE-2009-2259 | — | — | — | Jun 30, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of... |
| CVE-2009-2258 | — | — | 6.7% | Jun 30, 2009 | Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar... |
| CVE-2009-2257 | — | — | 7.2% | Jun 30, 2009 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic... |
| CVE-2009-2256 | — | — | 7.4% | Jun 30, 2009 | The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o... |
| CVE-2009-2255 | — | — | 31.0% | Jun 30, 2009 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which a... |
| CVE-2009-2254 | — | — | 10.9% | Jun 30, 2009 | Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now