2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-1614——Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr...
CVE-2009-1613——Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at...
CVE-2009-1612——Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote ...
CVE-2009-1611——Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ...
CVE-2009-1610——admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo...
CVE-2009-1609——Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute ar...
CVE-2009-1608——Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers...
CVE-2009-1607——Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers ...
CVE-2009-1606——Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108...
CVE-2009-1604——Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive dat...
CVE-2009-1602——Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa...
CVE-2009-1601——The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of...
CVE-2009-1600——Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a fo...
CVE-2009-1599——Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form cont...
CVE-2009-1598——Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a f...
CVE-2009-1597——Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a...
CVE-2009-1194——Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-...
CVE-2009-0194——The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garm...
CVE-2009-1595——The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authentic...
CVE-2009-1592——Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ...
CVE-2009-1591——CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP heade...
CVE-2009-1590——Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipie...
CVE-2009-1589——Unspecified vulnerability in CGI RESCUE MiniBBS22 before 1.01 allows remote attackers to send email to arbitrary recipie...
CVE-2009-1588——Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 bef...
CVE-2009-1587——index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now