2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1772 | — | — | 1.6% | May 22, 2009 | Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web s... |
| CVE-2009-1771 | — | — | 2.5% | May 22, 2009 | index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which... |
| CVE-2009-1770 | — | — | 2.3% | May 22, 2009 | Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack... |
| CVE-2009-1769 | — | — | 1.6% | May 22, 2009 | The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different er... |
| CVE-2009-1768 | — | — | 3.5% | May 22, 2009 | Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read a... |
| CVE-2009-1767 | — | — | 2.1% | May 22, 2009 | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote... |
| CVE-2009-1766 | — | — | 0.8% | May 22, 2009 | SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-1765 | — | — | 15.0% | May 22, 2009 | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to... |
| CVE-2009-1764 | — | — | 1.0% | May 22, 2009 | SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2009-1763 | — | — | 0.3% | May 22, 2009 | Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_... |
| CVE-2009-1762 | — | — | 1.4% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x ... |
| CVE-2009-1635 | — | — | 1.9% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 a... |
| CVE-2009-1753 | — | — | 0.3% | May 22, 2009 | Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file." |
| CVE-2009-0786 | — | — | — | May 22, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally intended for a report a... |
| CVE-2009-1759 | — | — | 14.1% | May 22, 2009 | Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent)... |
| CVE-2009-1758 | — | — | 2.2% | May 22, 2009 | The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and p... |
| CVE-2009-1757 | — | — | 0.8% | May 22, 2009 | Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attack... |
| CVE-2009-1756 | — | — | 0.5% | May 22, 2009 | SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth fr... |
| CVE-2009-1755 | — | — | 3.2% | May 22, 2009 | Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.... |
| CVE-2009-1752 | — | — | 2.5% | May 22, 2009 | exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all... |
| CVE-2009-1751 | — | — | 1.0% | May 22, 2009 | SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to exec... |
| CVE-2009-1750 | — | — | 2.7% | May 22, 2009 | Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl... |
| CVE-2009-1749 | — | — | 3.0% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject... |
| CVE-2009-1748 | — | — | 2.3% | May 22, 2009 | Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar... |
| CVE-2009-1747 | — | — | 1.0% | May 22, 2009 | SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now