2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0711filter.php in PHPFootball 1.6 and earlier allows remote attackers to retrieve password hashes via a request with an Acco...
CVE-2009-0710Multiple cross-site scripting (XSS) vulnerabilities in PHPFootball 1.6 allow remote attackers to inject arbitrary web sc...
CVE-2009-0709SQL injection vulnerability in login.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-0708Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) ...
CVE-2009-0707SQL injection vulnerability in admin/index.php in PowerClan 1.14a allows remote attackers to execute arbitrary SQL comma...
CVE-2009-0706SQL injection vulnerability in the Simple Review (com_simple_review) component 1.3.5 for Joomla! and Mambo allows remote...
CVE-2009-0705SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot...
CVE-2009-0704SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2009-0703SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co...
CVE-2009-0702SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote atta...
CVE-2009-0701Multiple PHP remote file inclusion vulnerabilities in index.php in Cybershade CMS 0.2b, when register_globals is enabled...
CVE-2009-0700Plunet BusinessManager 4.1 and earlier allows remote authenticated users to bypass access restrictions and (1) read sens...
CVE-2009-0699Cross-site scripting (XSS) vulnerability in pagesUTF8/auftrag_allgemeinauftrag.jsp in Plunet BusinessManager 4.1 and ear...
CVE-2009-0698Integer overflow in the 4xm demuxer (demuxers/demux_4xm.c) in xine-lib 1.1.16.1 allows remote attackers to cause a denia...
CVE-2009-0680cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de...
CVE-2009-0679Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject ...
CVE-2009-0678images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet...
CVE-2009-0677avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remo...
CVE-2009-0676The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct...
CVE-2009-0675The skfp_ioctl function in drivers/net/skfp/skfddi.c in the Linux kernel before 2.6.28.6 permits SKFP_CLR_STATS requests...
CVE-2009-0674images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows re...
CVE-2009-0673Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3...
CVE-2009-0672SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated ...
CVE-2009-0671Rejected reason: Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IM...
CVE-2009-0440IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, w...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now