2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4836 | — | — | 5.6% | May 6, 2010 | Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi... |
| CVE-2009-4835 | — | — | 1.4% | May 6, 2010 | The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions... |
| CVE-2009-4834 | — | — | 4.0% | May 4, 2010 | lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibl... |
| CVE-2009-4833 | — | — | 0.9% | Apr 29, 2010 | MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allow... |
| CVE-2009-4832 | — | — | 0.8% | Apr 29, 2010 | The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80... |
| CVE-2009-4831 | — | — | 1.4% | Apr 29, 2010 | Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attac... |
| CVE-2009-4830 | — | — | 2.4% | Apr 27, 2010 | Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to... |
| CVE-2009-4829 | — | — | 1.0% | Apr 27, 2010 | Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.... |
| CVE-2009-4828 | — | — | 0.9% | Apr 27, 2010 | Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 al... |
| CVE-2009-4827 | — | — | 0.9% | Apr 27, 2010 | Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the a... |
| CVE-2009-4826 | — | — | 0.9% | Apr 27, 2010 | Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote at... |
| CVE-2009-4825 | — | — | 2.5% | Apr 27, 2010 | 8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote ... |
| CVE-2009-4824 | — | — | 1.9% | Apr 27, 2010 | Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspe... |
| CVE-2009-4823 | — | — | 1.7% | Apr 27, 2010 | Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote a... |
| CVE-2009-4822 | — | — | 1.5% | Apr 27, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject ... |
| CVE-2009-4821 | — | — | 1.3% | Apr 27, 2010 | The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remot... |
| CVE-2009-4820 | — | — | 2.5% | Apr 27, 2010 | Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote a... |
| CVE-2009-4819 | — | — | 3.3% | Apr 27, 2010 | Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr... |
| CVE-2009-4818 | — | — | 4.2% | Apr 27, 2010 | Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers... |
| CVE-2009-4817 | — | — | 3.4% | Apr 27, 2010 | Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary ... |
| CVE-2009-4816 | — | — | 2.7% | Apr 27, 2010 | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to rea... |
| CVE-2009-4815 | — | — | 2.9% | Apr 27, 2010 | Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via... |
| CVE-2009-4814 | — | — | 1.5% | Apr 27, 2010 | Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary ... |
| CVE-2009-4813 | — | — | 1.5% | Apr 27, 2010 | Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inj... |
| CVE-2009-4812 | — | — | 1.1% | Apr 27, 2010 | Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now