2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1512 | — | — | 4.0% | May 1, 2009 | Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP ... |
| CVE-2009-1511 | — | — | 14.2% | May 1, 2009 | GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha... |
| CVE-2009-1510 | — | — | 2.2% | May 1, 2009 | Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execut... |
| CVE-2009-1509 | — | — | 1.0% | May 1, 2009 | SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary... |
| CVE-2009-1508 | — | — | 2.0% | May 1, 2009 | SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers t... |
| CVE-2009-1507 | — | — | 1.4% | May 1, 2009 | The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interp... |
| CVE-2009-1506 | — | — | 0.9% | May 1, 2009 | SQL injection vulnerability in classes/Xp.php in eLitius 1.0 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-1505 | — | — | 1.1% | May 1, 2009 | SQL injection vulnerability in the News Page module 5.x before 5.x-1.2 for Drupal allows remote authenticated users, wit... |
| CVE-2009-1504 | — | — | 2.4% | May 1, 2009 | Absolute Form Processor XE 1.5 allows remote attackers to bypass authentication and gain administrative access by settin... |
| CVE-2009-1503 | — | — | 1.0% | May 1, 2009 | Multiple SQL injection vulnerabilities in login.php in Tiger Document Management System (DMS) allow remote attackers to ... |
| CVE-2009-1502 | — | — | 2.3% | May 1, 2009 | Directory traversal vulnerability in plugin.php in S-Cms 1.1 Stable and 1.5.2 allows remote attackers to include and exe... |
| CVE-2009-1501 | — | — | 1.0% | May 1, 2009 | Cross-site scripting (XSS) vulnerability in the Exif module 5.x-1.x before 5.x-1.2 and 6.x-1.x-dev before April 13, 2009... |
| CVE-2009-1500 | — | — | 0.9% | May 1, 2009 | SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL command... |
| CVE-2009-1365 | — | — | 3.3% | May 1, 2009 | Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media ... |
| CVE-2009-1364 | — | — | 3.5% | May 1, 2009 | Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a ... |
| CVE-2009-1499 | — | — | 1.8% | May 1, 2009 | SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbit... |
| CVE-2009-1498 | — | — | 1.9% | May 1, 2009 | Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp... |
| CVE-2009-1497 | — | — | 6.8% | May 1, 2009 | Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attacke... |
| CVE-2009-1496 | — | — | 7.2% | May 1, 2009 | Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote at... |
| CVE-2009-1495 | — | — | 2.3% | May 1, 2009 | Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem... |
| CVE-2009-1313 | — | — | 8.4% | Apr 30, 2009 | The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote at... |
| CVE-2009-1494 | — | — | 1.5% | Apr 30, 2009 | The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc comman... |
| CVE-2009-1493 | — | — | 21.8% | Apr 30, 2009 | The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and ... |
| CVE-2009-1492 | — | — | 25.5% | Apr 30, 2009 | The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote ... |
| CVE-2009-1434 | — | — | 0.7% | Apr 30, 2009 | Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentica... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now