2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0810SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via...
CVE-2009-0809The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other pr...
CVE-2009-0808Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL comman...
CVE-2009-0807zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
CVE-2009-0806Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via ...
CVE-2009-0805Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a module for XOOPS, allows remote attackers to inje...
CVE-2009-0804Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint...
CVE-2009-0803SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent in...
CVE-2009-0802Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint,...
CVE-2009-0801Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which ...
CVE-2009-0780The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of se...
CVE-2009-0779Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."
CVE-2009-0759Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the z...
CVE-2009-0758The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account ...
CVE-2009-0757Multiple buffer overflows in GNU MPFR 2.4.0 allow context-dependent attackers to cause a denial of service (crash) via t...
CVE-2009-0756The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic...
CVE-2009-0755The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic...
CVE-2009-0754PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hoste...
CVE-2009-0753Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files vi...
CVE-2009-0752Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vecto...
CVE-2009-0751Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with ...
CVE-2009-0750SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to ex...
CVE-2009-0368OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data obj...
CVE-2009-0749HIGH7.8Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and ear...
CVE-2009-0748The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 d...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now