2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4459 | — | — | 1.1% | Dec 30, 2009 | Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote a... |
| CVE-2009-4458 | — | — | 1.8% | Dec 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow re... |
| CVE-2009-4457 | — | — | 1.7% | Dec 30, 2009 | Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact a... |
| CVE-2009-4456 | — | — | 1.0% | Dec 30, 2009 | SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote att... |
| CVE-2009-4455 | — | — | 1.3% | Dec 29, 2009 | The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and ... |
| CVE-2009-4454 | — | — | 0.6% | Dec 29, 2009 | vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a sym... |
| CVE-2009-4445 | — | — | 12.8% | Dec 29, 2009 | Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications... |
| CVE-2009-4444 | — | — | 63.6% | Dec 29, 2009 | Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) cha... |
| CVE-2009-4453 | — | — | 5.1% | Dec 29, 2009 | Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers ... |
| CVE-2009-4452 | — | — | 0.8% | Dec 29, 2009 | Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x),... |
| CVE-2009-4451 | — | — | 3.3% | Dec 29, 2009 | Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co... |
| CVE-2009-4450 | — | — | 1.5% | Dec 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arb... |
| CVE-2009-4448 | — | — | 1.7% | Dec 29, 2009 | inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to c... |
| CVE-2009-4447 | — | — | 2.6% | Dec 29, 2009 | Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ... |
| CVE-2009-4446 | — | — | 1.4% | Dec 29, 2009 | Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitra... |
| CVE-2009-3295 | — | — | 40.3% | Dec 29, 2009 | The prep_reprocess_req function in kdc/do_tgs_req.c in the cross-realm referral implementation in the Key Distribution C... |
| CVE-2009-4443 | — | — | 2.1% | Dec 28, 2009 | Unspecified vulnerability in the psearch (aka persistent search) functionality in Directory Proxy Server (DPS) in Sun Ja... |
| CVE-2009-4442 | — | — | 2.5% | Dec 28, 2009 | Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly ... |
| CVE-2009-4441 | — | — | 2.5% | Dec 28, 2009 | Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not enable th... |
| CVE-2009-4440 | — | — | 1.6% | Dec 28, 2009 | Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly ... |
| CVE-2009-4439 | — | — | 2.0% | Dec 28, 2009 | Unspecified vulnerability in the Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.5 before FP5 allows remot... |
| CVE-2009-4438 | — | — | 1.6% | Dec 28, 2009 | The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does ... |
| CVE-2009-4007 | — | — | 2.1% | Dec 28, 2009 | Unspecified vulnerability in the NormaliseTrainConsist function in src/train_cmd.cpp in OpenTTD before 0.7.5-RC1 allows ... |
| CVE-2009-1798 | — | — | 2.0% | Dec 28, 2009 | Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (A... |
| CVE-2009-1797 | — | — | 0.7% | Dec 28, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conver... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now