2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1572——The BGP daemon (bgpd) in Quagga 0.99.11 and earlier allows remote attackers to cause a denial of service (crash) via an ...
CVE-2009-1561——Cross-site request forgery (CSRF) vulnerability in administration.cgi on the Cisco Linksys WRT54GC router with firmware ...
CVE-2009-1560——The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network...
CVE-2009-1559——Absolute path traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware ...
CVE-2009-1558——Directory traversal vulnerability in adm/file.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00...
CVE-2009-1557——Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WVC54GCA wireless video camera with firmware 1....
CVE-2009-1556——img/main.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote authent...
CVE-2009-1555——The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 sends configuration data in response ...
CVE-2009-1554——Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise ...
CVE-2009-1553——Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow re...
CVE-2009-1552——Unspecified vulnerability in the IGMP driver in SCO Unixware Release 7.1.4 Maintenance Pack 4 allows attackers to cause ...
CVE-2009-1551——Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP cod...
CVE-2009-1550——Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to...
CVE-2009-1549——AGTC MyShop 3.2b allows remote attackers to bypass authentication and obtain administrative access setting the log_accep...
CVE-2009-1548——SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the...
CVE-2009-1527——Race condition in the ptrace_attach function in kernel/ptrace.c in the Linux kernel before 2.6.30-rc4 allows local users...
CVE-2009-1526——JBMC Software DirectAdmin before 1.334 allows local users to create or overwrite any file via a symlink attack on an arb...
CVE-2009-1525——CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metachar...
CVE-2009-1469——CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and Web...
CVE-2009-1468——Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eM...
CVE-2009-1467——Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote...
CVE-2009-1184——The selinux_ip_postroute_iptables_compat function in security/selinux/hooks.c in the SELinux subsystem in the Linux kern...
CVE-2009-1491——McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products f...
CVE-2009-1490——Heap-based buffer overflow in Sendmail before 8.13.2 allows remote attackers to cause a denial of service (daemon crash)...
CVE-2009-1524——Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now