2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1624 | — | — | 2.9% | May 12, 2009 | Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files vi... |
| CVE-2009-1623 | — | — | 1.4% | May 12, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary... |
| CVE-2009-1622 | — | — | 1.1% | May 12, 2009 | SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via th... |
| CVE-2009-1621 | — | — | 6.4% | May 12, 2009 | Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .... |
| CVE-2009-1620 | — | — | 1.2% | May 12, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary ... |
| CVE-2009-1619 | — | — | 2.5% | May 12, 2009 | Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw... |
| CVE-2009-1618 | — | — | 2.5% | May 12, 2009 | Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us... |
| CVE-2009-1617 | — | — | 2.5% | May 12, 2009 | Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&l... |
| CVE-2009-1616 | — | — | 1.5% | May 11, 2009 | Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remo... |
| CVE-2009-1615 | — | — | 2.9% | May 11, 2009 | Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading ... |
| CVE-2009-1614 | — | — | 1.3% | May 11, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr... |
| CVE-2009-1613 | — | — | 1.0% | May 11, 2009 | Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at... |
| CVE-2009-1612 | — | — | 33.3% | May 11, 2009 | Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote ... |
| CVE-2009-1611 | — | — | 7.2% | May 11, 2009 | Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ... |
| CVE-2009-1610 | — | — | 6.1% | May 11, 2009 | admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo... |
| CVE-2009-1609 | — | — | 3.6% | May 11, 2009 | Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute ar... |
| CVE-2009-1608 | — | — | 11.2% | May 11, 2009 | Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers... |
| CVE-2009-1607 | — | — | 1.5% | May 11, 2009 | Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers ... |
| CVE-2009-1606 | — | — | 4.6% | May 11, 2009 | Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108... |
| CVE-2009-1605 | MEDIUM | 5.4 | 3.4% | May 11, 2009 | Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-wi... |
| CVE-2009-1604 | — | — | 1.8% | May 11, 2009 | Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive dat... |
| CVE-2009-1603 | HIGH | 7.5 | 1.1% | May 11, 2009 | src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generat... |
| CVE-2009-1602 | — | — | 2.8% | May 11, 2009 | Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa... |
| CVE-2009-1601 | — | — | 0.3% | May 11, 2009 | The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of... |
| CVE-2009-1600 | — | — | 1.7% | May 11, 2009 | Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a fo... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now