2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-4412Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary ...
CVE-2009-4411The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links e...
CVE-2009-4410The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y...
CVE-2009-4137The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookie...
CVE-2009-3305Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request wi...
CVE-2009-4409The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet ...
CVE-2009-4408Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and...
CVE-2009-4407Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly ...
CVE-2009-4406Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2,...
CVE-2009-4405Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (...
CVE-2009-4145nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection e...
CVE-2009-4144NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WP...
CVE-2009-4404Unspecified vulnerability in t-prot (TOFU Protection) before 2.8 allows remote attackers to cause a denial of service vi...
CVE-2009-4403Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web s...
CVE-2009-4402The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations ...
CVE-2009-4133Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote...
CVE-2009-3584SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for rem...
CVE-2009-3583Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include a...
CVE-2009-3582Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to...
CVE-2009-3581Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbi...
CVE-2009-3580Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the auth...
CVE-2009-4401SQL injection vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and earlier for TYP...
CVE-2009-4400Cross-site scripting (XSS) vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and ea...
CVE-2009-4399SQL injection vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) extension 0....
CVE-2009-4398Cross-site scripting (XSS) vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery)...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now