2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4786 | — | — | 1.6% | Apr 21, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web... |
| CVE-2009-4785 | — | — | 0.9% | Apr 21, 2010 | SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute a... |
| CVE-2009-4784 | — | — | 1.0% | Apr 21, 2010 | SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute ... |
| CVE-2009-4783 | — | — | 1.0% | Apr 21, 2010 | Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL com... |
| CVE-2009-4782 | — | — | 1.5% | Apr 21, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbit... |
| CVE-2009-4781 | — | — | 0.8% | Apr 21, 2010 | TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c... |
| CVE-2009-4780 | — | — | 1.2% | Apr 21, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inje... |
| CVE-2009-4779 | — | — | 2.1% | Apr 21, 2010 | Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitra... |
| CVE-2009-4778 | — | — | 4.3% | Apr 21, 2010 | Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM... |
| CVE-2009-4777 | — | — | 1.4% | Apr 21, 2010 | Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated M... |
| CVE-2009-4776 | — | — | 3.1% | Apr 21, 2010 | Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in pr... |
| CVE-2009-4775 | — | — | 5.6% | Apr 21, 2010 | Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of ... |
| CVE-2009-4774 | — | — | 0.3% | Apr 21, 2010 | Unspecified vulnerability in Sun Solaris 10 and OpenSolaris snv_49 through snv_117, when 64bit mode is used on the Intel... |
| CVE-2009-4773 | — | — | 0.6% | Apr 20, 2010 | Cross-site request forgery (CSRF) vulnerability in the order-management functionality in the Ubercart module 5.x before ... |
| CVE-2009-4772 | — | — | 0.9% | Apr 20, 2010 | Unspecified vulnerability in the PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.... |
| CVE-2009-4771 | — | — | 1.2% | Apr 20, 2010 | The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for ... |
| CVE-2009-4770 | — | — | 1.3% | Apr 20, 2010 | The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderato... |
| CVE-2009-4769 | — | — | 37.9% | Apr 20, 2010 | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo... |
| CVE-2009-4768 | — | — | 3.4% | Apr 20, 2010 | Unspecified vulnerability in the JASS script interpreter in Warcraft III: The Frozen Throne 1.24b and earlier allows use... |
| CVE-2009-4767 | — | — | 1.5% | Apr 20, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject... |
| CVE-2009-4766 | — | — | 1.3% | Apr 13, 2010 | YP Portal MS-Pro Surumu (aka MS-Pro Portal Scripti) 1.0 and 1.2 stores sensitive information under the web root with ins... |
| CVE-2009-4765 | — | — | 1.4% | Apr 13, 2010 | CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows rem... |
| CVE-2009-4511 | — | — | 5.5% | Apr 13, 2010 | Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Ser... |
| CVE-2009-4510 | — | — | 2.1% | Apr 13, 2010 | The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier... |
| CVE-2009-4509 | — | — | 4.5% | Apr 13, 2010 | The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session coo... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now