2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1756 | — | — | 0.5% | May 22, 2009 | SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth fr... |
| CVE-2009-1755 | — | — | 3.2% | May 22, 2009 | Off-by-one error in the packet_read_query_section function in packet.c in nsd 3.2.1, and process_query_section in query.... |
| CVE-2009-1752 | — | — | 2.5% | May 22, 2009 | exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all... |
| CVE-2009-1751 | — | — | 1.0% | May 22, 2009 | SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to exec... |
| CVE-2009-1750 | — | — | 2.7% | May 22, 2009 | Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl... |
| CVE-2009-1749 | — | — | 3.0% | May 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Catviz 0.4.0 beta 1 allow remote attackers to inject... |
| CVE-2009-1748 | — | — | 2.3% | May 22, 2009 | Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar... |
| CVE-2009-1747 | — | — | 1.0% | May 22, 2009 | SQL injection vulnerability in index.php in 26th Avenue bSpeak 1.10 allows remote attackers to execute arbitrary SQL com... |
| CVE-2009-1746 | — | — | 1.0% | May 21, 2009 | SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary ... |
| CVE-2009-1745 | — | — | 2.1% | May 21, 2009 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, an... |
| CVE-2009-0897 | — | — | 1.0% | May 21, 2009 | IBM WebSphere Partner Gateway (WPG) 6.1.0 before 6.1.0.1 and 6.1.1 before 6.1.1.1 allows remote authenticated users to o... |
| CVE-2009-1729 | — | — | 5.3% | May 21, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Communications Express 6 2005Q4 (aka 6.2) and 6.3... |
| CVE-2009-1594 | — | — | 1.4% | May 21, 2009 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "pos... |
| CVE-2009-1593 | — | — | 1.5% | May 21, 2009 | Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "neg... |
| CVE-2009-1161 | — | — | 12.5% | May 21, 2009 | Directory traversal vulnerability in the TFTP service in Cisco CiscoWorks Common Services (CWCS) 3.0.x through 3.2.x on ... |
| CVE-2009-1744 | — | — | 2.2% | May 21, 2009 | InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Systems Pinnacle Studio 12, allows remote... |
| CVE-2009-1743 | — | — | 6.2% | May 21, 2009 | Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Syst... |
| CVE-2009-1742 | — | — | 1.3% | May 20, 2009 | code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks vi... |
| CVE-2009-1741 | — | — | 1.9% | May 20, 2009 | Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow re... |
| CVE-2009-1740 | — | — | 5.6% | May 20, 2009 | Multiple heap-based buffer overflows in the D-Link MPEG4 Viewer ActiveX Control (csviewer.ocx) 2.11.918.2006 allow remot... |
| CVE-2009-1739 | — | — | 2.8% | May 20, 2009 | PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi... |
| CVE-2009-1738 | — | — | 1.0% | May 20, 2009 | Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authen... |
| CVE-2009-1737 | — | — | 1.9% | May 20, 2009 | Directory traversal vulnerability in bom.php in MyPic 2.1 allows remote attackers to list files in arbitrary directories... |
| CVE-2009-1736 | — | — | 1.1% | May 20, 2009 | SQL injection vulnerability in the GridSupport (GS) Ticket System (com_gsticketsystem) component for Joomla! allows remo... |
| CVE-2009-1735 | — | — | 1.7% | May 20, 2009 | Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now