2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-4836Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi...
CVE-2009-4835The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions...
CVE-2009-4834lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibl...
CVE-2009-4833MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allow...
CVE-2009-4832The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80...
CVE-2009-4831Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attac...
CVE-2009-4830Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to...
CVE-2009-4829Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2....
CVE-2009-4828Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 al...
CVE-2009-4827Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the a...
CVE-2009-4826Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote at...
CVE-2009-48258pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote ...
CVE-2009-4824Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspe...
CVE-2009-4823Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote a...
CVE-2009-4822Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject ...
CVE-2009-4821The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remot...
CVE-2009-4820Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote a...
CVE-2009-4819Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr...
CVE-2009-4818Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers...
CVE-2009-4817Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary ...
CVE-2009-4816Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to rea...
CVE-2009-4815Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via...
CVE-2009-4814Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary ...
CVE-2009-4813Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inj...
CVE-2009-4812Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now