2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4397 | — | — | 0.9% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 ... |
| CVE-2009-4396 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in the Diocese of Portsmouth Resources Database (pd_resources) extension 0.1.1 and earlier f... |
| CVE-2009-4395 | — | — | 0.9% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in the Random Prayer 2 (ste_prayer2) extension 0.0.3 and earlier for TYPO3 allo... |
| CVE-2009-4394 | — | — | 1.5% | Dec 22, 2009 | SQL injection vulnerability in the Random Prayer 2 (ste_prayer2) extension 0.0.3 and earlier for TYPO3 allows remote att... |
| CVE-2009-4393 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in the Document Directorys (danp_documentdirs) extension 1.10.7 and earlier for TYPO3 allows... |
| CVE-2009-4392 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in the XDS Staff List (xds_staff) extension 0.0.3 and earlier for TYPO3 allows remote attack... |
| CVE-2009-4391 | — | — | 0.9% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in the File list (dr_blob) extension 2.1.1 for TYPO3 allows remote attackers to... |
| CVE-2009-4390 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in the Car (car) extension 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL ... |
| CVE-2009-4389 | — | — | 1.1% | Dec 22, 2009 | Unspecified vulnerability in the Watchdog (aba_watchdog) extension 2.0.2 and earlier for TYPO3 allows remote attackers t... |
| CVE-2009-4388 | — | — | 0.8% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in the ListMan (nl_listman) extension 1.2.1 for TYPO3 allows remote attackers t... |
| CVE-2009-4387 | — | — | 1.3% | Dec 22, 2009 | The cross-site scripting (XSS) protection mechanism in ShowInContentAreaAction.do in ManageEngine Password Manager Pro (... |
| CVE-2009-4386 | — | — | 1.0% | Dec 22, 2009 | SQL injection vulnerability in hotel_tiempolibre_ext.php in Venalsur Booking Centre Booking System for Hotels Group, whe... |
| CVE-2009-4385 | — | — | 1.0% | Dec 22, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers ... |
| CVE-2009-4384 | — | — | 1.5% | Dec 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inje... |
| CVE-2009-4383 | — | — | 1.6% | Dec 22, 2009 | Directory traversal vulnerability in Pforum.php in Rocomotion P forum before 1.28 allows remote attackers to read arbitr... |
| CVE-2009-4382 | — | — | 1.5% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in module.php in PHPFABER CMS, possibly 1.3.36, allows remote attackers to inje... |
| CVE-2009-4381 | — | — | 1.8% | Dec 22, 2009 | Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inje... |
| CVE-2009-4380 | — | — | 1.1% | Dec 22, 2009 | Multiple SQL injection vulnerabilities in Valarsoft Webmatic before 3.0.3 allow remote attackers to execute arbitrary SQ... |
| CVE-2009-4379 | — | — | 1.0% | Dec 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Valarsoft Webmatic before 3.0.3 allow remote attackers to inject ... |
| CVE-2009-4140 | — | — | 75.8% | Dec 22, 2009 | Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer... |
| CVE-2009-3702 | — | — | 2.4% | Dec 22, 2009 | Multiple absolute path traversal vulnerabilities in PHP-Calendar 1.1 allow remote attackers to include and execute arbit... |
| CVE-2009-4378 | — | — | 2.3% | Dec 21, 2009 | The IPMI dissector in Wireshark 1.2.0 through 1.2.4 on Windows allows remote attackers to cause a denial of service (cra... |
| CVE-2009-4377 | — | — | 2.7% | Dec 21, 2009 | The (1) SMB and (2) SMB2 dissectors in Wireshark 0.9.0 through 1.2.4 allow remote attackers to cause a denial of service... |
| CVE-2009-4376 | — | — | 6.8% | Dec 21, 2009 | Buffer overflow in the daintree_sna_read function in the Daintree SNA file parser in Wireshark 1.2.0 through 1.2.4 allow... |
| CVE-2009-4035 | — | — | 3.8% | Dec 21, 2009 | The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly ot... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now