2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-5007 | — | — | 0.3% | Oct 14, 2010 | The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symli... |
| CVE-2009-5003 | — | — | 1.0% | Sep 22, 2010 | SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbit... |
| CVE-2009-5002 | — | — | 1.0% | Sep 20, 2010 | The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not ... |
| CVE-2009-5001 | — | — | 1.0% | Sep 20, 2010 | The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.2-P8AE-FP002 grants a ... |
| CVE-2009-5000 | — | — | 0.8% | Sep 20, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application En... |
| CVE-2009-4999 | — | — | 0.8% | Sep 20, 2010 | Cross-site scripting (XSS) vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE)... |
| CVE-2009-4998 | — | — | 1.1% | Sep 20, 2010 | The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-019 and 4.0.2.x before 4... |
| CVE-2009-4895 | MEDIUM | 4.7 | 0.3% | Sep 8, 2010 | Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local user... |
| CVE-2009-4997 | — | — | 0.3% | Sep 7, 2010 | gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking t... |
| CVE-2009-4996 | — | — | 0.3% | Sep 7, 2010 | Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make ... |
| CVE-2009-4898 | — | — | 0.6% | Sep 7, 2010 | Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authenticati... |
| CVE-2009-3743 | — | — | 6.8% | Aug 26, 2010 | Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remot... |
| CVE-2009-4995 | — | — | 0.9% | Aug 25, 2010 | Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote a... |
| CVE-2009-4994 | — | — | 1.0% | Aug 25, 2010 | Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote ... |
| CVE-2009-4993 | — | — | 2.1% | Aug 25, 2010 | PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbit... |
| CVE-2009-4992 | — | — | 0.9% | Aug 25, 2010 | SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary S... |
| CVE-2009-4991 | — | — | 1.3% | Aug 25, 2010 | Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to ... |
| CVE-2009-4990 | — | — | 1.0% | Aug 25, 2010 | Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to ... |
| CVE-2009-4989 | — | — | 1.5% | Aug 25, 2010 | Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbit... |
| CVE-2009-4988 | — | — | 65.5% | Aug 25, 2010 | Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta... |
| CVE-2009-4987 | — | — | 6.4% | Aug 25, 2010 | admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain ad... |
| CVE-2009-4986 | — | — | 2.0% | Aug 25, 2010 | Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote atta... |
| CVE-2009-4985 | — | — | 0.9% | Aug 25, 2010 | SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute ... |
| CVE-2009-4984 | — | — | 1.3% | Aug 25, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Accessories Me PHP Affiliate Script 1.4 allow remote attackers to... |
| CVE-2009-4983 | — | — | 1.3% | Aug 25, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Silurus Classifieds 1.0 allow remote attackers to inject arbitrar... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now