2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1624——Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files vi...
CVE-2009-1623——Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary...
CVE-2009-1622——SQL injection vulnerability in user.php in EcShop 2.5.0 allows remote attackers to execute arbitrary SQL commands via th...
CVE-2009-1621——Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a ....
CVE-2009-1620——Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary ...
CVE-2009-1619——Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw...
CVE-2009-1618——Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us...
CVE-2009-1617——Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&l...
CVE-2009-1616——Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remo...
CVE-2009-1615——Unrestricted file upload vulnerability in Leap CMS 0.1.4 allows remote attackers to execute arbitrary code by uploading ...
CVE-2009-1614——Multiple cross-site scripting (XSS) vulnerabilities in Leap CMS 0.1.4 allow remote attackers to inject arbitrary web scr...
CVE-2009-1613——Multiple SQL injection vulnerabilities in leap.php in Leap CMS 0.1.4, when magic_quotes_gpc is disabled, allow remote at...
CVE-2009-1612——Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote ...
CVE-2009-1611——Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ...
CVE-2009-1610——admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo...
CVE-2009-1609——Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute ar...
CVE-2009-1608——Multiple buffer overflows in Microchip MPLAB IDE 8.30 and possibly earlier versions allow user-assisted remote attackers...
CVE-2009-1607——Cross-site scripting (XSS) vulnerability in the administrator panel in phpForm.net LinkBase 2.0 allows remote attackers ...
CVE-2009-1606——Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108...
CVE-2009-1605MEDIUM5.4Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-wi...
CVE-2009-1604——Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive dat...
CVE-2009-1603HIGH7.5src/tools/pkcs11-tool.c in pkcs11-tool in OpenSC 0.11.7, when used with unspecified third-party PKCS#11 modules, generat...
CVE-2009-1602——Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa...
CVE-2009-1601——The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of...
CVE-2009-1600——Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a fo...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now