2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0711——filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Acco...
CVE-2009-0710——Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc...
CVE-2009-0709——SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-0708——Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) ...
CVE-2009-0707——SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma...
CVE-2009-0706——SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote...
CVE-2009-0705——SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot...
CVE-2009-0704——SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-0703——SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co...
CVE-2009-0702——SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote atta...
CVE-2009-0701——Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled...
CVE-2009-0700——Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens...
CVE-2009-0699——Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear...
CVE-2009-0698——Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denia...
CVE-2009-0680——cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de...
CVE-2009-0679——Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject ...
CVE-2009-0678——images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet...
CVE-2009-0677——avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remo...
CVE-2009-0676——The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct...
CVE-2009-0675——The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests...
CVE-2009-0674——images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows re...
CVE-2009-0673——Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3...
CVE-2009-0672——SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated ...
CVE-2009-0671——Rejected reason: Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IM...
CVE-2009-0440——IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, w...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now