2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1624Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files vi...
CVE-2009-1623Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary...
CVE-2009-1622SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via th...
CVE-2009-1621Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a ....
CVE-2009-1620Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary ...
CVE-2009-1619Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw...
CVE-2009-1618Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us...
CVE-2009-1617Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&l...
CVE-2009-1616Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remo...
CVE-2009-1615Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading ...
CVE-2009-1614Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr...
CVE-2009-1613Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at...
CVE-2009-1612Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote ...
CVE-2009-1611Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ...
CVE-2009-1610admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo...
CVE-2009-1609Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute ar...
CVE-2009-1608Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers...
CVE-2009-1607Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers ...
CVE-2009-1606Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108...
CVE-2009-1605MEDIUM5.4Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-wi...
CVE-2009-1604Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive dat...
CVE-2009-1603HIGH7.5src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generat...
CVE-2009-1602Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa...
CVE-2009-1601The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of...
CVE-2009-1600Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a fo...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now