2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0810——SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via...
CVE-2009-0809——The Web Editor in Dassault Systemes ENOVIA SmarTeam V5 before Release 18 Service Pack 8, and possibly CATIA and other pr...
CVE-2009-0808——Multiple SQL injection vulnerabilities in SimpleCMMS before 0.1.0 allow remote attackers to execute arbitrary SQL comman...
CVE-2009-0807——zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
CVE-2009-0806——Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via ...
CVE-2009-0805——Cross-site scripting (XSS) vulnerability in piCal 0.91h and earlier, a module for XOOPS, allows remote attackers to inje...
CVE-2009-0804——Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint...
CVE-2009-0803——SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent in...
CVE-2009-0802——Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint,...
CVE-2009-0801——Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which ...
CVE-2009-0780——The aspath_prepend function in rde_attr.c in bgpd in OpenBSD 4.3 and 4.4 allows remote attackers to cause a denial of se...
CVE-2009-0779——Buffer overflow in pppdial in IBM AIX 5.3 and 6.1 allows local users to gain privileges via a long "input string."
CVE-2009-0759——Multiple CRLF injection vulnerabilities in webadmin in ZNC before 0.066 allow remote authenticated users to modify the z...
CVE-2009-0758——The originates_from_local_legacy_unicast_socket function in avahi-core/server.c in avahi-daemon 0.6.23 does not account ...
CVE-2009-0757——Multiple buffer overflows in GNU MPFR 2.4.0 allow context-dependent attackers to cause a denial of service (crash) via t...
CVE-2009-0756——The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic...
CVE-2009-0755——The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic...
CVE-2009-0754——PHP 4.4.4, 5.1.6, and other versions, when running on Apache, allows local users to modify behavior of other sites hoste...
CVE-2009-0753——Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files vi...
CVE-2009-0752——Unspecified vulnerability in Movable Type Pro and Community Solution 4.x before 4.24 has unknown impact and attack vecto...
CVE-2009-0751——Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with ...
CVE-2009-0750——SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to ex...
CVE-2009-0368——OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data obj...
CVE-2009-0749HIGH7.8Use-after-free vulnerability in the GIFReadNextExtension function in lib/pngxtern/gif/gifread.c in OptiPNG 0.6.2 and ear...
CVE-2009-0748——The ext4_fill_super function in fs/ext4/super.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 d...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now