2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2119Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2...
CVE-2009-2118Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to ...
CVE-2009-2117uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by sett...
CVE-2009-2116Directory traversal vulnerability in admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to l...
CVE-2009-2115admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an in...
CVE-2009-2114Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inj...
CVE-2009-2113Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the ...
CVE-2009-2112Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut...
CVE-2009-2111Static code injection vulnerability in add_reg.php in DB Top Sites 1.0 allows remote attackers to inject arbitrary PHP c...
CVE-2009-2110Multiple directory traversal vulnerabilities in DB Top Sites 1.0, when magic_quotes_gpc is disabled, allow remote attack...
CVE-2009-2109Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director...
CVE-2009-2108git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU cons...
CVE-2009-1935Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature ...
CVE-2009-2107Multiple cross-site scripting (XSS) vulnerabilities in index.php in Webmedia Explorer (webmex) 5.09 and 5.10 allow remot...
CVE-2009-2106SQL injection vulnerability in the Virtual Civil Services (civserv) extension 4.3.2 and earlier for TYPO3 allows remote ...
CVE-2009-2105SQL injection vulnerability in the References database (t3references) extension 0.1.1 and earlier for TYPO3 allows remot...
CVE-2009-2104Cross-site scripting (XSS) vulnerability in the Modern Guestbook / Commenting System (ve_guestbook) extension 2.7.1 and ...
CVE-2009-2103SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remot...
CVE-2009-2102SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote ...
CVE-2009-2101Directory traversal vulnerability in archive.php in TorrentVolve 1.4, when register_globals is enabled, allows remote at...
CVE-2009-2100Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows ...
CVE-2009-2099SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to...
CVE-2009-2098SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-2097SQL injection vulnerability in system/application/controllers/catalog.php in Zoki Soft Zoki Catalog (aka Smart Catalog) ...
CVE-2009-2096SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now