2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2285Buffer underflow in the LZWDecodeCompat function in libtiff 3.8.2 allows context-dependent attackers to cause a denial o...
CVE-2009-2284Cross-site scripting (XSS) vulnerability in phpMyAdmin before 3.2.0.1 allows remote attackers to inject arbitrary web sc...
CVE-2009-2283Multiple cross-site scripting (XSS) vulnerabilities in the help jsp scripts in Sun Java Web Console 3.0.2 through 3.0.5,...
CVE-2009-2282The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris sn...
CVE-2009-2276SQL injection vulnerability in voteforus.php in the Vote For Us extension 1.0.1 and earlier for PunBB allows remote atta...
CVE-2009-2275Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrar...
CVE-2009-2274The Huawei D100 allows remote attackers to obtain sensitive information via a direct request to (1) lan_status_adv.asp, ...
CVE-2009-2273The default configuration of the Wi-Fi component on the Huawei D100 does not use encryption, which makes it easier for r...
CVE-2009-2272HIGH7.5The Huawei D100 stores the administrator's account name and password in cleartext in a cookie, which allows context-depe...
CVE-2009-2271The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password ch...
CVE-2009-2270Unrestricted file upload vulnerability in member/uploads_edit.php in dedecms 5.3 allows remote attackers to execute arbi...
CVE-2009-2269SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid para...
CVE-2009-2268Cross-site scripting (XSS) vulnerability in the Cross-Domain Controller (CDC) servlet in Sun Java System Access Manager ...
CVE-2009-1889The OSCAR protocol implementation in Pidgin before 2.5.8 misinterprets the ICQWebMessage message type as the ICQSMS mess...
CVE-2009-0689Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation...
CVE-2009-2263Directory traversal vulnerability in index.php in Awesome PHP Mega File Manager 1.0 allows remote attackers to include a...
CVE-2009-2262PHP remote file inclusion vulnerability in install/di.php in AjaxPortal 3.0 allows remote attackers to execute arbitrary...
CVE-2009-2261PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z...
CVE-2009-2260stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which al...
CVE-2009-2259Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2608. Reason: This candidate is a duplicate of...
CVE-2009-2258Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar...
CVE-2009-2257The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic...
CVE-2009-2256The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o...
CVE-2009-2255Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which a...
CVE-2009-2254Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now