2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-1772Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web s...
CVE-2009-1771index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which...
CVE-2009-1770Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack...
CVE-2009-1769The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different er...
CVE-2009-1768Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read a...
CVE-2009-1767admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote...
CVE-2009-1766SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-1765Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to...
CVE-2009-1764SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via ...
CVE-2009-1763Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_...
CVE-2009-1762Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x ...
CVE-2009-1635Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 a...
CVE-2009-1753Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."
CVE-2009-0786Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally intended for a report a...
CVE-2009-1759Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent)...
CVE-2009-1758The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and p...
CVE-2009-1757Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attack...
CVE-2009-1756SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth fr...
CVE-2009-1755Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query....
CVE-2009-1752exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all...
CVE-2009-1751SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to exec...
CVE-2009-1750Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl...
CVE-2009-1749Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject...
CVE-2009-1748Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar...
CVE-2009-1747SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now