2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1756——SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth fr...
CVE-2009-1755——Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query....
CVE-2009-1752——exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all...
CVE-2009-1751——SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to exec...
CVE-2009-1750——Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl...
CVE-2009-1749——Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject...
CVE-2009-1748——Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar...
CVE-2009-1747——SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com...
CVE-2009-1746——SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary ...
CVE-2009-1745——Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, an...
CVE-2009-0897——IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to o...
CVE-2009-1729——Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3...
CVE-2009-1594——Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "pos...
CVE-2009-1593——Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "neg...
CVE-2009-1161——Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on ...
CVE-2009-1744——InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote...
CVE-2009-1743——Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Syst...
CVE-2009-1742——code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks vi...
CVE-2009-1741——Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow re...
CVE-2009-1740——Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remot...
CVE-2009-1739——PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi...
CVE-2009-1738——Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authen...
CVE-2009-1737——Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories...
CVE-2009-1736——SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remo...
CVE-2009-1735——Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now