2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4468Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web scr...
CVE-2009-4467misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio...
CVE-2009-4466DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which rev...
CVE-2009-4465DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attac...
CVE-2009-4464Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to ...
CVE-2009-4463Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it ea...
CVE-2009-4462Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA al...
CVE-2009-4461Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web sc...
CVE-2009-4460Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to i...
CVE-2009-4459Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote a...
CVE-2009-4458Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow re...
CVE-2009-4457Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact a...
CVE-2009-4456SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote att...
CVE-2009-4455The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and ...
CVE-2009-4454vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a sym...
CVE-2009-4445Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications...
CVE-2009-4444Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) cha...
CVE-2009-4453Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers ...
CVE-2009-4452Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x),...
CVE-2009-4451Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co...
CVE-2009-4450Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arb...
CVE-2009-4449MEDIUM6.5Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the...
CVE-2009-4448inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to c...
CVE-2009-4447Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ...
CVE-2009-4446Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitra...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now