2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2100 | — | — | 8.2% | Jun 17, 2009 | Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows ... |
| CVE-2009-2099 | — | — | 1.0% | Jun 17, 2009 | SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to... |
| CVE-2009-2098 | — | — | 1.0% | Jun 17, 2009 | SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2009-2097 | — | — | 1.1% | Jun 17, 2009 | SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) ... |
| CVE-2009-2096 | — | — | 1.0% | Jun 17, 2009 | SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar... |
| CVE-2009-2095 | — | — | 1.7% | Jun 17, 2009 | PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi... |
| CVE-2009-2084 | — | — | 0.4% | Jun 16, 2009 | Simple Linux Utility for Resource Management (SLURM) 1.2 and 1.3 before 1.3.14 does not properly set supplementary group... |
| CVE-2009-1761 | — | — | 2.2% | Jun 16, 2009 | The message engine in CA ARCserve Backup r12.0 and r12.0 SP1 for Windows allows remote attackers to cause a denial of se... |
| CVE-2009-1719 | — | — | 5.3% | Jun 16, 2009 | The Aqua Look and Feel for Java implementation in Java 1.5 on Mac OS X 10.5 allows remote attackers to execute arbitrary... |
| CVE-2009-1391 | — | — | 7.1% | Jun 16, 2009 | Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, ... |
| CVE-2009-1389 | — | — | 5.5% | Jun 16, 2009 | Buffer overflow in the RTL8169 NIC driver (drivers/net/r8169.c) in the Linux kernel before 2.6.30 allows remote attacker... |
| CVE-2009-2083 | — | — | 0.9% | Jun 16, 2009 | Cross-site scripting (XSS) vulnerability in the term data detail page in Taxonomy manager 5.x before 5.x-1.2, a module f... |
| CVE-2009-2082 | — | — | 1.1% | Jun 16, 2009 | SQL injection vulnerability in insidepage.php in Creative Web Solutions Multi-Level CMS 1.21 allows remote attackers to ... |
| CVE-2009-2011 | — | — | 40.2% | Jun 16, 2009 | Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p... |
| CVE-2009-1390 | — | — | 1.9% | Jun 16, 2009 | Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when onl... |
| CVE-2009-2081 | — | — | 2.5% | Jun 16, 2009 | Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo... |
| CVE-2009-2080 | — | — | 2.7% | Jun 16, 2009 | admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obta... |
| CVE-2009-2079 | — | — | 1.0% | Jun 16, 2009 | Cross-site scripting (XSS) vulnerability in the administrative page interface in Taxonomy manager 5.x before 5.x-1.2 and... |
| CVE-2009-2078 | — | — | 1.1% | Jun 16, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Booktree 5.x before 5.x-7.3 and 6.x before 6.x-1.1, a module for ... |
| CVE-2009-2077 | — | — | 1.0% | Jun 16, 2009 | Drupal 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated users to bypass access restrictions and (1) ... |
| CVE-2009-2076 | — | — | 0.9% | Jun 16, 2009 | Cross-site scripting (XSS) vulnerability in Views 6.x before 6.x-2.6, a module for Drupal, allows remote authenticated u... |
| CVE-2009-2075 | — | — | 1.2% | Jun 16, 2009 | Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, does not properly restrict access when display... |
| CVE-2009-2074 | — | — | 1.0% | Jun 16, 2009 | Cross-site scripting (XSS) vulnerability in Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, al... |
| CVE-2009-2073 | — | — | 0.7% | Jun 15, 2009 | Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows... |
| CVE-2009-2072 | — | — | 0.3% | Jun 15, 2009 | Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now