2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-0711 | — | — | 1.2% | Feb 23, 2009 | filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Acco... |
| CVE-2009-0710 | — | — | 1.5% | Feb 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc... |
| CVE-2009-0709 | — | — | 1.0% | Feb 23, 2009 | SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2009-0708 | — | — | 0.5% | Feb 23, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) ... |
| CVE-2009-0707 | — | — | 2.0% | Feb 23, 2009 | SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma... |
| CVE-2009-0706 | — | — | 1.2% | Feb 23, 2009 | SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote... |
| CVE-2009-0705 | — | — | 1.0% | Feb 23, 2009 | SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot... |
| CVE-2009-0704 | — | — | 1.0% | Feb 23, 2009 | SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2009-0703 | — | — | 1.0% | Feb 23, 2009 | SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co... |
| CVE-2009-0702 | — | — | 1.0% | Feb 23, 2009 | SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote atta... |
| CVE-2009-0701 | — | — | 1.8% | Feb 23, 2009 | Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled... |
| CVE-2009-0700 | — | — | 2.5% | Feb 23, 2009 | Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens... |
| CVE-2009-0699 | — | — | 1.3% | Feb 23, 2009 | Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear... |
| CVE-2009-0698 | — | — | 3.6% | Feb 23, 2009 | Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denia... |
| CVE-2009-0680 | — | — | 8.4% | Feb 22, 2009 | cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de... |
| CVE-2009-0679 | — | — | 1.1% | Feb 22, 2009 | Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject ... |
| CVE-2009-0678 | — | — | 2.8% | Feb 22, 2009 | images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet... |
| CVE-2009-0677 | — | — | 9.0% | Feb 22, 2009 | avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remo... |
| CVE-2009-0676 | — | — | 0.7% | Feb 22, 2009 | The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct... |
| CVE-2009-0675 | — | — | 0.4% | Feb 22, 2009 | The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests... |
| CVE-2009-0674 | — | — | 2.3% | Feb 22, 2009 | images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows re... |
| CVE-2009-0673 | — | — | 2.6% | Feb 22, 2009 | Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3... |
| CVE-2009-0672 | — | — | 1.3% | Feb 22, 2009 | SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated ... |
| CVE-2009-0671 | — | — | — | Feb 22, 2009 | Rejected reason: Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IM... |
| CVE-2009-0440 | — | — | 1.2% | Feb 22, 2009 | IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, w... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now