2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4468 | — | — | 1.4% | Dec 30, 2009 | Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web scr... |
| CVE-2009-4467 | — | — | 1.7% | Dec 30, 2009 | misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio... |
| CVE-2009-4466 | — | — | 2.4% | Dec 30, 2009 | DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which rev... |
| CVE-2009-4465 | — | — | 2.4% | Dec 30, 2009 | DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attac... |
| CVE-2009-4464 | — | — | 1.5% | Dec 30, 2009 | Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to ... |
| CVE-2009-4463 | — | — | 3.4% | Dec 30, 2009 | Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it ea... |
| CVE-2009-4462 | — | — | 19.9% | Dec 30, 2009 | Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA al... |
| CVE-2009-4461 | — | — | 1.5% | Dec 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web sc... |
| CVE-2009-4460 | — | — | 1.1% | Dec 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to i... |
| CVE-2009-4459 | — | — | 1.1% | Dec 30, 2009 | Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote a... |
| CVE-2009-4458 | — | — | 1.8% | Dec 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow re... |
| CVE-2009-4457 | — | — | 1.7% | Dec 30, 2009 | Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact a... |
| CVE-2009-4456 | — | — | 1.0% | Dec 30, 2009 | SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote att... |
| CVE-2009-4455 | — | — | 1.3% | Dec 29, 2009 | The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and ... |
| CVE-2009-4454 | — | — | 0.6% | Dec 29, 2009 | vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a sym... |
| CVE-2009-4445 | — | — | 12.8% | Dec 29, 2009 | Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications... |
| CVE-2009-4444 | — | — | 63.6% | Dec 29, 2009 | Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) cha... |
| CVE-2009-4453 | — | — | 5.1% | Dec 29, 2009 | Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers ... |
| CVE-2009-4452 | — | — | 0.8% | Dec 29, 2009 | Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x),... |
| CVE-2009-4451 | — | — | 3.3% | Dec 29, 2009 | Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co... |
| CVE-2009-4450 | — | — | 1.5% | Dec 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arb... |
| CVE-2009-4449 | MEDIUM | 6.5 | 2.7% | Dec 29, 2009 | Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the... |
| CVE-2009-4448 | — | — | 1.7% | Dec 29, 2009 | inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to c... |
| CVE-2009-4447 | — | — | 2.6% | Dec 29, 2009 | Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ... |
| CVE-2009-4446 | — | — | 1.4% | Dec 29, 2009 | Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitra... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now