2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0024The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denia...
CVE-2009-0113Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allo...
CVE-2009-0112Cross-site request forgery (CSRF) vulnerability in admin/agent_edit.asp in PollPro 3.0 allows remote attackers to create...
CVE-2009-0111SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrar...
CVE-2009-0110SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL com...
CVE-2009-0109SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL co...
CVE-2009-0108PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via m...
CVE-2009-0107Cross-site scripting (XSS) vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to...
CVE-2009-0106SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbi...
CVE-2009-0105Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web sc...
CVE-2009-0104SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via t...
CVE-2009-0103Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code...
CVE-2009-0072Microsoft Internet Explorer 6.0 through 8.0 beta2 allows remote attackers to cause a denial of service (application cras...
CVE-2009-0071Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial ...
CVE-2009-0070Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cau...
CVE-2009-0043The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not pro...
CVE-2009-0069Unspecified vulnerability in the nfs4rename_persistent_fh function in the NFS 4 (aka NFSv4) client in the kernel in Sun ...
CVE-2009-0068Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME ...
CVE-2009-0066Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to ...
CVE-2009-0065Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission Protocol (sctp) implementation in the Linu...
CVE-2009-0051ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote...
CVE-2009-0050Lasso 2.2.1 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remo...
CVE-2009-0049Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFi...
CVE-2009-0048OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which...
CVE-2009-0047Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows r...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now