2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4468——Cross-site scripting (XSS) vulnerability in misc.php in DeluxeBB 1.3 allows remote attackers to inject arbitrary web scr...
CVE-2009-4467——misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio...
CVE-2009-4466——DeluxeBB 1.3 allows remote attackers to obtain sensitive information via a crafted page parameter to misc.php, which rev...
CVE-2009-4465——DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attac...
CVE-2009-4464——Cross-site scripting (XSS) vulnerability in searchadvance.asp in Active Business Directory 2 allows remote attackers to ...
CVE-2009-4463——Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it ea...
CVE-2009-4462——Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA al...
CVE-2009-4461——Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.909 allow remote attackers to inject arbitrary web sc...
CVE-2009-4460——Multiple cross-site scripting (XSS) vulnerabilities in Auto-Surf Traffic Exchange Script 1.1 allow remote attackers to i...
CVE-2009-4459——Redmine 0.8.7 and earlier uses the title tag before defining the character encoding in a meta tag, which allows remote a...
CVE-2009-4458——Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.5.2 and 2.6.0rc2, and possibly other versions, allow re...
CVE-2009-4457——Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact a...
CVE-2009-4456——SQL injection vulnerability in news_detail.php in Green Desktiny 2.3.1, and possibly earlier versions, allows remote att...
CVE-2009-4455——The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and ...
CVE-2009-4454——vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a sym...
CVE-2009-4445——Microsoft Internet Information Services (IIS), when used in conjunction with unspecified third-party upload applications...
CVE-2009-4444——Microsoft Internet Information Services (IIS) 5.x and 6.x uses only the portion of a filename before a ; (semicolon) cha...
CVE-2009-4453——Insecure method vulnerability in SoftCab Sound Converter ActiveX control (sndConverter.ocx) 1.2 allows remote attackers ...
CVE-2009-4452——Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x),...
CVE-2009-4451——Unrestricted file upload vulnerability in upper.php in kandalf upper 0.1 allows remote attackers to execute arbitrary co...
CVE-2009-4450——Multiple cross-site scripting (XSS) vulnerabilities in map.php in LiveZilla 3.1.8.3 allow remote attackers to inject arb...
CVE-2009-4449MEDIUM6.5Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the...
CVE-2009-4448——inc/functions_time.php in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, allows remote attackers to c...
CVE-2009-4447——Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ...
CVE-2009-4446——Cross-site scripting (XSS) vulnerability in admin.php in phpInstantGallery 1.1 allows remote attackers to inject arbitra...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now