2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4531 | — | — | 7.1% | Dec 31, 2009 | httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) charact... |
| CVE-2009-4530 | — | — | 1.2% | Dec 31, 2009 | Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the ... |
| CVE-2009-4529 | — | — | 1.7% | Dec 31, 2009 | InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page vi... |
| CVE-2009-4528 | — | — | 1.3% | Dec 31, 2009 | The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to byp... |
| CVE-2009-4527 | — | — | 0.3% | Dec 31, 2009 | The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly r... |
| CVE-2009-4526 | — | — | 1.5% | Dec 31, 2009 | The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x befo... |
| CVE-2009-4525 | — | — | 1.3% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 a... |
| CVE-2009-4524 | — | — | 1.2% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attacker... |
| CVE-2009-4523 | — | — | 1.5% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2009-4522 | — | — | 1.5% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrar... |
| CVE-2009-4521 | — | — | 2.0% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) ... |
| CVE-2009-4520 | — | — | 1.2% | Dec 31, 2009 | The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers... |
| CVE-2009-4519 | — | — | 1.5% | Dec 31, 2009 | Multiple unspecified vulnerabilities in Ortro before 1.3.4 have unknown impact and attack vectors. |
| CVE-2009-4518 | — | — | 1.1% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x before 5.x-1.2 for Drupal allows remote attackers... |
| CVE-2009-4517 | — | — | 0.6% | Dec 31, 2009 | Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, a... |
| CVE-2009-4516 | — | — | 1.0% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows r... |
| CVE-2009-4515 | — | — | 1.3% | Dec 31, 2009 | The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, whic... |
| CVE-2009-4514 | — | — | 0.9% | Dec 31, 2009 | Cross-site scripting (XSS) vulnerability in the OpenSocial Shindig-Integrator module 5.x and 6.x before 6.x-2.1, a modul... |
| CVE-2009-4513 | — | — | 1.0% | Dec 31, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the Workflow module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a ... |
| CVE-2009-4512 | — | — | 2.1% | Dec 31, 2009 | Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attack... |
| CVE-2009-4502 | — | — | 21.6% | Dec 31, 2009 | The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote att... |
| CVE-2009-4501 | — | — | 8.5% | Dec 31, 2009 | The zbx_get_next_field function in libs/zbxcommon/str.c in Zabbix Server before 1.6.8 allows remote attackers to cause a... |
| CVE-2009-4500 | — | — | 2.3% | Dec 31, 2009 | The process_trap function in trapper/trapper.c in Zabbix Server before 1.6.6 allows remote attackers to cause a denial o... |
| CVE-2009-4499 | — | — | 2.4% | Dec 31, 2009 | SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.... |
| CVE-2009-4498 | — | — | 31.9% | Dec 31, 2009 | The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now