2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1453 | — | — | 0.9% | Apr 28, 2009 | SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote... |
| CVE-2009-1452 | — | — | 2.3% | Apr 28, 2009 | Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execut... |
| CVE-2009-1451 | — | — | 1.3% | Apr 28, 2009 | Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary w... |
| CVE-2009-1450 | — | — | 2.1% | Apr 28, 2009 | PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP ... |
| CVE-2009-1449 | — | — | 5.9% | Apr 27, 2009 | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attacker... |
| CVE-2009-1448 | — | — | 1.0% | Apr 27, 2009 | Cross-site scripting (XSS) vulnerability in apricot.php in LovPop.net APRICOT, probably 1.20, allows remote attackers to... |
| CVE-2009-1190 | — | — | 2.8% | Apr 27, 2009 | Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) bef... |
| CVE-2009-1447 | — | — | 3.5% | Apr 27, 2009 | Unrestricted file upload vulnerability in admin/editor/image.php in e-cart.biz Free Shopping Cart allows remote attacker... |
| CVE-2009-1446 | — | — | 3.4% | Apr 27, 2009 | Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to... |
| CVE-2009-1445 | — | — | 6.1% | Apr 27, 2009 | Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary file... |
| CVE-2009-1444 | — | — | 2.3% | Apr 27, 2009 | PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbit... |
| CVE-2009-1443 | — | — | 4.0% | Apr 27, 2009 | Multiple unspecified vulnerabilities in the Server component in OCS Inventory NG before 1.02 have unknown impact and att... |
| CVE-2009-1440 | — | — | 1.5% | Apr 27, 2009 | Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument in... |
| CVE-2009-1439 | — | — | 4.3% | Apr 27, 2009 | Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a d... |
| CVE-2009-1438 | — | — | 4.7% | Apr 27, 2009 | Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer... |
| CVE-2009-1437 | — | — | 14.0% | Apr 27, 2009 | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem... |
| CVE-2009-1436 | — | — | 0.9% | Apr 27, 2009 | The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berke... |
| CVE-2009-1435 | — | — | 0.8% | Apr 27, 2009 | NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of servic... |
| CVE-2009-1189 | — | — | 1.3% | Apr 27, 2009 | The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incor... |
| CVE-2009-1433 | — | — | 1.1% | Apr 24, 2009 | SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to ... |
| CVE-2009-1414 | — | — | 0.4% | Apr 24, 2009 | Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for ... |
| CVE-2009-1413 | — | — | 0.8% | Apr 24, 2009 | Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Univ... |
| CVE-2009-1412 | — | — | 1.2% | Apr 24, 2009 | Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by... |
| CVE-2009-1192 | — | — | 0.4% | Apr 24, 2009 | The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsys... |
| CVE-2009-0798 | — | — | 2.3% | Apr 24, 2009 | ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connec... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now