2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4437 | — | — | 1.0% | Dec 28, 2009 | Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL comma... |
| CVE-2009-4436 | — | — | 1.0% | Dec 28, 2009 | Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQ... |
| CVE-2009-4435 | — | — | 2.0% | Dec 28, 2009 | Multiple directory traversal vulnerabilities in F3Site 2009 allow remote attackers to include and execute arbitrary loca... |
| CVE-2009-4434 | — | — | 2.7% | Dec 28, 2009 | Directory traversal vulnerability in index.php in IDevSpot iSupport 1.8 and earlier allows remote attackers to read arbi... |
| CVE-2009-4433 | — | — | 2.2% | Dec 28, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to injec... |
| CVE-2009-4432 | — | — | 1.0% | Dec 28, 2009 | SQL injection vulnerability in index.php in CodeMight VideoCMS 3.1 allows remote attackers to execute arbitrary SQL comm... |
| CVE-2009-4431 | — | — | 2.1% | Dec 28, 2009 | PHP remote file inclusion vulnerability in cal_popup.php in the Anything Digital Development JCal Pro (aka com_jcalpro o... |
| CVE-2009-4430 | — | — | 0.9% | Dec 28, 2009 | SQL injection vulnerability in index.php in VirtueMart 1.0 allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2009-4429 | — | — | 2.8% | Dec 28, 2009 | Cross-site scripting (XSS) vulnerability in the Sections module 5.x before 5.x-1.3 and 6.x before 6.x-1.3 for Drupal all... |
| CVE-2009-4428 | — | — | 1.0% | Dec 28, 2009 | SQL injection vulnerability in the JoomPortfolio (com_joomportfolio) component 1.0.0 for Joomla! allows remote attackers... |
| CVE-2009-4427 | — | — | 10.0% | Dec 28, 2009 | Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbi... |
| CVE-2009-4426 | — | — | 2.3% | Dec 28, 2009 | Multiple directory traversal vulnerabilities in Ignition 1.2, when magic_quotes_gpc is disabled, allow remote attackers ... |
| CVE-2009-4425 | — | — | 1.1% | Dec 28, 2009 | Cross-site scripting (XSS) vulnerability in index.php in iDevCart 1.09 allows remote attackers to inject arbitrary web s... |
| CVE-2009-4424 | — | — | 2.8% | Dec 28, 2009 | SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi... |
| CVE-2009-4423 | — | — | 1.0% | Dec 24, 2009 | SQL injection vulnerability in index.php in weenCompany 4.0.0 allows remote attackers to execute arbitrary SQL commands ... |
| CVE-2009-4422 | — | — | 1.1% | Dec 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the GetURLArguments function in jpgraph.php in Aditus Consulting ... |
| CVE-2009-4421 | — | — | 2.0% | Dec 24, 2009 | Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated ... |
| CVE-2009-4420 | — | — | 2.2% | Dec 24, 2009 | Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0... |
| CVE-2009-4419 | — | — | 0.4% | Dec 24, 2009 | Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows ... |
| CVE-2009-4418 | — | — | 1.0% | Dec 24, 2009 | The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resou... |
| CVE-2009-4417 | — | — | 0.9% | Dec 24, 2009 | The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to sen... |
| CVE-2009-4416 | — | — | 2.3% | Dec 24, 2009 | Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.... |
| CVE-2009-4415 | — | — | 3.4% | Dec 24, 2009 | Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, a... |
| CVE-2009-4414 | — | — | 1.3% | Dec 24, 2009 | SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versio... |
| CVE-2009-4413 | — | — | 8.7% | Dec 24, 2009 | The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remot... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now