2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-1772——Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web s...
CVE-2009-1771——index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which...
CVE-2009-1770——Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack...
CVE-2009-1769——The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different er...
CVE-2009-1768——Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read a...
CVE-2009-1767——admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote...
CVE-2009-1766——SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-1765——Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to...
CVE-2009-1764——SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via ...
CVE-2009-1763——Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_...
CVE-2009-1762——Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x ...
CVE-2009-1635——Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 a...
CVE-2009-1753——Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."
CVE-2009-0786——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally intended for a report a...
CVE-2009-1759——Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent)...
CVE-2009-1758——The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and p...
CVE-2009-1757——Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attack...
CVE-2009-1756——SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth fr...
CVE-2009-1755——Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query....
CVE-2009-1752——exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all...
CVE-2009-1751——SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to exec...
CVE-2009-1750——Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl...
CVE-2009-1749——Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject...
CVE-2009-1748——Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar...
CVE-2009-1747——SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now