2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4838SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows rem...
CVE-2009-4837Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow re...
CVE-2009-4836Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi...
CVE-2009-4835The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions...
CVE-2009-4834lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibl...
CVE-2009-4833MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allow...
CVE-2009-4832The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80...
CVE-2009-4831Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attac...
CVE-2009-4830Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to...
CVE-2009-4829Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2....
CVE-2009-4828Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 al...
CVE-2009-4827Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the a...
CVE-2009-4826Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote at...
CVE-2009-48258pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote ...
CVE-2009-4824Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspe...
CVE-2009-4823Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote a...
CVE-2009-4822Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject ...
CVE-2009-4821The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remot...
CVE-2009-4820Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote a...
CVE-2009-4819Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr...
CVE-2009-4818Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers...
CVE-2009-4817Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary ...
CVE-2009-4816Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to rea...
CVE-2009-4815Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via...
CVE-2009-4814Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now