2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4412 | — | — | 1.9% | Dec 24, 2009 | Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary ... |
| CVE-2009-4411 | — | — | 0.3% | Dec 24, 2009 | The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links e... |
| CVE-2009-4410 | — | — | 0.4% | Dec 24, 2009 | The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y... |
| CVE-2009-4137 | — | — | 16.9% | Dec 24, 2009 | The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookie... |
| CVE-2009-3305 | — | — | 10.1% | Dec 24, 2009 | Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request wi... |
| CVE-2009-4409 | — | — | 1.4% | Dec 23, 2009 | The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet ... |
| CVE-2009-4408 | — | — | 1.0% | Dec 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and... |
| CVE-2009-4407 | — | — | 0.6% | Dec 23, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly ... |
| CVE-2009-4406 | — | — | 1.1% | Dec 23, 2009 | Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2,... |
| CVE-2009-4405 | — | — | 2.0% | Dec 23, 2009 | Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (... |
| CVE-2009-4145 | — | — | 0.4% | Dec 23, 2009 | nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection e... |
| CVE-2009-4144 | — | — | 1.9% | Dec 23, 2009 | NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WP... |
| CVE-2009-4404 | — | — | 1.2% | Dec 23, 2009 | Unspecified vulnerability in t-prot (TOFU Protection) before 2.8 allows remote attackers to cause a denial of service vi... |
| CVE-2009-4403 | — | — | 1.5% | Dec 23, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web s... |
| CVE-2009-4402 | — | — | 1.4% | Dec 23, 2009 | The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations ... |
| CVE-2009-4133 | — | — | 2.1% | Dec 23, 2009 | Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote... |
| CVE-2009-3584 | — | — | 1.2% | Dec 23, 2009 | SQL-Ledger 2.8.24 does not set the secure flag for the session cookie in an https session, which makes it easier for rem... |
| CVE-2009-3583 | — | — | 1.3% | Dec 23, 2009 | Directory traversal vulnerability in the Preferences menu item in SQL-Ledger 2.8.24 allows remote attackers to include a... |
| CVE-2009-3582 | — | — | 0.9% | Dec 23, 2009 | Multiple SQL injection vulnerabilities in the delete subroutine in SQL-Ledger 2.8.24 allow remote authenticated users to... |
| CVE-2009-3581 | — | — | 0.9% | Dec 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in SQL-Ledger 2.8.24 allow remote authenticated users to inject arbi... |
| CVE-2009-3580 | — | — | 0.6% | Dec 23, 2009 | Cross-site request forgery (CSRF) vulnerability in am.pl in SQL-Ledger 2.8.24 allows remote attackers to hijack the auth... |
| CVE-2009-4401 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and earlier for TYP... |
| CVE-2009-4400 | — | — | 0.9% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in the Parish Administration Database (ste_parish_admin) extension 0.1.3 and ea... |
| CVE-2009-4399 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery) extension 0.... |
| CVE-2009-4398 | — | — | 0.9% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in the Parish of the Holy Spirit Religious Art Gallery (hs_religiousartgallery)... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now