2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1779 | — | — | 3.9% | May 22, 2009 | PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to... |
| CVE-2009-1778 | — | — | 1.2% | May 22, 2009 | SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, a... |
| CVE-2009-1777 | — | — | 2.0% | May 22, 2009 | CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers ... |
| CVE-2009-1776 | — | — | 1.5% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, a... |
| CVE-2009-1775 | — | — | 1.0% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Ulteo Open Virtual Desktop 1.0 allow remote attackers to inject a... |
| CVE-2009-1381 | — | — | 2.9% | May 22, 2009 | The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.19-1 on Debian GNU/Linux, and possibl... |
| CVE-2009-1774 | — | — | 17.9% | May 22, 2009 | Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and exe... |
| CVE-2009-1773 | — | — | 1.9% | May 22, 2009 | activeCollab 2.1 Corporate allows remote attackers to obtain sensitive information via an invalid re_route parameter to ... |
| CVE-2009-1772 | — | — | 1.6% | May 22, 2009 | Cross-site scripting (XSS) vulnerability in activeCollab 2.1 Corporate allows remote attackers to inject arbitrary web s... |
| CVE-2009-1771 | — | — | 2.5% | May 22, 2009 | index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which... |
| CVE-2009-1770 | — | — | 2.3% | May 22, 2009 | Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack... |
| CVE-2009-1769 | — | — | 1.6% | May 22, 2009 | The web interface in Open Computer and Software Inventory Next Generation (OCS Inventory NG) 1.01 generates different er... |
| CVE-2009-1768 | — | — | 3.5% | May 22, 2009 | Directory traversal vulnerability in download.php in Rama Zaiten CMS 0.9.8 and earlier allows remote attackers to read a... |
| CVE-2009-1767 | — | — | 2.1% | May 22, 2009 | admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote... |
| CVE-2009-1766 | — | — | 0.8% | May 22, 2009 | SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-1765 | — | — | 15.0% | May 22, 2009 | Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to... |
| CVE-2009-1764 | — | — | 1.0% | May 22, 2009 | SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via ... |
| CVE-2009-1763 | — | — | 0.3% | May 22, 2009 | Unspecified vulnerability in the Solaris Secure Digital slot driver (aka sdhost) in Sun OpenSolaris snv_105 through snv_... |
| CVE-2009-1762 | — | — | 1.4% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess login page (aka gw/webacc) in Novell GroupWise 7.x ... |
| CVE-2009-1635 | — | — | 1.9% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the WebAccess component in Novell GroupWise 7.x before 7.03 HP3 a... |
| CVE-2009-1753 | — | — | 0.3% | May 22, 2009 | Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file." |
| CVE-2009-0786 | — | — | — | May 22, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This was originally intended for a report a... |
| CVE-2009-1759 | — | — | 14.1% | May 22, 2009 | Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent)... |
| CVE-2009-1758 | — | — | 2.2% | May 22, 2009 | The hypervisor_callback function in Xen, possibly before 3.4.0, as applied to the Linux kernel 2.6.30-rc4, 2.6.18, and p... |
| CVE-2009-1757 | — | — | 0.8% | May 22, 2009 | Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attack... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now