2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1734 | — | — | 1.1% | May 20, 2009 | SQL injection vulnerability in listing_video.php in VidSharePro allows remote attackers to execute arbitrary SQL command... |
| CVE-2009-1733 | — | — | 0.6% | May 20, 2009 | Cross-site request forgery (CSRF) vulnerability in IPplan 4.91a allows remote attackers to hijack the authentication of ... |
| CVE-2009-1732 | — | — | 1.9% | May 20, 2009 | Cross-site scripting (XSS) vulnerability in admin/usermanager in IPplan 4.91a allows remote attackers to inject arbitrar... |
| CVE-2009-1731 | — | — | 1.2% | May 20, 2009 | SQL injection vulnerability in panel/index.php in MLFFAT 2.1 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-1730 | — | — | 54.5% | May 20, 2009 | Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read ... |
| CVE-2009-1418 | — | — | 2.9% | May 19, 2009 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers ... |
| CVE-2009-1379 | — | — | 18.2% | May 19, 2009 | Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 a... |
| CVE-2009-1378 | — | — | 12.7% | May 19, 2009 | Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.... |
| CVE-2009-1377 | — | — | 11.3% | May 19, 2009 | The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to... |
| CVE-2009-1252 | — | — | 21.1% | May 19, 2009 | Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4... |
| CVE-2009-1678 | — | — | 2.4% | May 18, 2009 | Directory traversal vulnerability in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier all... |
| CVE-2009-1677 | — | — | 2.1% | May 18, 2009 | Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 an... |
| CVE-2009-1676 | — | — | — | May 18, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1535. Reason: This candidate is a duplicate of... |
| CVE-2009-1675 | — | — | 13.8% | May 18, 2009 | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ... |
| CVE-2009-1674 | — | — | 4.9% | May 18, 2009 | Stack-based buffer overflow in Microchip MPLAB IDE 8.30 allows user-assisted remote attackers to execute arbitrary code ... |
| CVE-2009-1673 | — | — | 0.4% | May 18, 2009 | The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argume... |
| CVE-2009-1672 | — | — | 9.6% | May 18, 2009 | The Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 1... |
| CVE-2009-1671 | — | — | 10.3% | May 18, 2009 | Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Env... |
| CVE-2009-1670 | — | — | 6.9% | May 18, 2009 | user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin a... |
| CVE-2009-1669 | — | — | 14.1% | May 18, 2009 | The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers ... |
| CVE-2009-1668 | — | — | 6.0% | May 18, 2009 | TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort... |
| CVE-2009-1667 | — | — | 21.4% | May 18, 2009 | Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a lo... |
| CVE-2009-1666 | — | — | 2.9% | May 18, 2009 | Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary c... |
| CVE-2009-0721 | — | — | 9.9% | May 18, 2009 | Unspecified vulnerability in Easy Login in the Sender module in HP Remote Graphics Software (RGS) 4.0.0 through 5.2.4 al... |
| CVE-2009-1665 | — | — | 2.3% | May 18, 2009 | myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now