2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4838——SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows rem...
CVE-2009-4837——Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow re...
CVE-2009-4836——Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi...
CVE-2009-4835——The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions...
CVE-2009-4834——lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibl...
CVE-2009-4833——MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allow...
CVE-2009-4832——The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80...
CVE-2009-4831——Cerulean Studios Trillian 3.1 Basic does not check SSL certificates during MSN authentication, which allows remote attac...
CVE-2009-4830——Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to...
CVE-2009-4829——Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2....
CVE-2009-4828——Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 al...
CVE-2009-4827——Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the a...
CVE-2009-4826——Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote at...
CVE-2009-4825——8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote ...
CVE-2009-4824——Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspe...
CVE-2009-4823——Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote a...
CVE-2009-4822——Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kasseler CMS 1.3.4 allow remote attackers to inject ...
CVE-2009-4821——The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remot...
CVE-2009-4820——Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote a...
CVE-2009-4819——Multiple unrestricted file upload vulnerabilities in upload.php in PHPhotoalbum allow remote attackers to execute arbitr...
CVE-2009-4818——Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers...
CVE-2009-4817——Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary ...
CVE-2009-4816——Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to rea...
CVE-2009-4815——Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via...
CVE-2009-4814——Cross-site scripting (XSS) vulnerability in Wolfram Research webMathematica allows remote attackers to inject arbitrary ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now