2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4982 | — | — | 0.9% | Aug 25, 2010 | SQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote... |
| CVE-2009-4981 | — | — | 0.5% | Aug 25, 2010 | Multiple cross-site request forgery (CSRF) vulnerabilities in Photokorn Gallery 1.81 allow remote attackers to hijack th... |
| CVE-2009-4980 | — | — | 1.0% | Aug 25, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Photokorn Gallery 1.81 and earlier allow remote attackers to inje... |
| CVE-2009-4979 | — | — | 1.1% | Aug 25, 2010 | Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to exe... |
| CVE-2009-4978 | — | — | 2.9% | Aug 25, 2010 | Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a ..... |
| CVE-2009-4977 | — | — | 2.1% | Aug 25, 2010 | PHP remote file inclusion vulnerability in index.php in MyBackup 1.4.0 allows remote authenticated users to execute arbi... |
| CVE-2009-3737 | — | — | 3.9% | Aug 17, 2010 | The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj m... |
| CVE-2009-4269 | — | — | 1.5% | Aug 16, 2010 | The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 perf... |
| CVE-2009-2696 | — | — | 5.0% | Aug 5, 2010 | Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application... |
| CVE-2009-4976 | — | — | 1.1% | Aug 2, 2010 | Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary we... |
| CVE-2009-4975 | — | — | 1.1% | Aug 2, 2010 | Cross-site scripting (XSS) vulnerability in webview.cpp in QtDemoBrowser allows remote attackers to inject arbitrary web... |
| CVE-2009-4896 | — | — | 1.8% | Aug 2, 2010 | Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful ... |
| CVE-2009-4974 | — | — | 2.3% | Jul 28, 2010 | Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary file... |
| CVE-2009-4973 | — | — | 0.9% | Jul 28, 2010 | SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2009-4972 | — | — | 1.1% | Jul 28, 2010 | Cross-site scripting (XSS) vulnerability in index.php (aka the log in page) in SimpleID before 0.6.5 allows remote attac... |
| CVE-2009-4971 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execut... |
| CVE-2009-4970 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary ... |
| CVE-2009-4969 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attacke... |
| CVE-2009-4968 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the Event Registration (event_registr) extension 1.0.0 and earlier for TYPO3 allows remot... |
| CVE-2009-4967 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the Car (car) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitra... |
| CVE-2009-4966 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the AST ZipCodeSearch (ast_addresszipsearch) extension 0.5.4 for TYPO3 allows remote atta... |
| CVE-2009-4965 | — | — | 1.1% | Jul 28, 2010 | SQL injection vulnerability in the AIRware Lexicon (air_lexicon) extension 0.0.1 for TYPO3 allows remote attackers to ex... |
| CVE-2009-4964 | — | — | 5.8% | Jul 28, 2010 | Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .... |
| CVE-2009-4963 | — | — | 0.8% | Jul 28, 2010 | Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated us... |
| CVE-2009-4962 | — | — | 31.4% | Jul 28, 2010 | Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now