2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2119——Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2...
CVE-2009-2118——Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to ...
CVE-2009-2117——uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by sett...
CVE-2009-2116——Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to l...
CVE-2009-2115——admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an in...
CVE-2009-2114——Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inj...
CVE-2009-2113——Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the ...
CVE-2009-2112——Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut...
CVE-2009-2111——Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c...
CVE-2009-2110——Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack...
CVE-2009-2109——Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director...
CVE-2009-2108——git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU cons...
CVE-2009-1935——Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature ...
CVE-2009-2107——Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remot...
CVE-2009-2106——SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote ...
CVE-2009-2105——SQL injection vulnerability in the References database (t3references) extension 0.1.1 and earlier for TYPO3 allows remot...
CVE-2009-2104——Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and ...
CVE-2009-2103——SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remot...
CVE-2009-2102——SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote ...
CVE-2009-2101——Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote at...
CVE-2009-2100——Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows ...
CVE-2009-2099——SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to...
CVE-2009-2098——SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2097——SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) ...
CVE-2009-2096——SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now