2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4422——Multiple cross-site scripting (XSS) vulnerabilities in the GetURLArguments function in jpgraph.php in Aditus Consulting ...
CVE-2009-4421——Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated ...
CVE-2009-4420——Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0...
CVE-2009-4419——Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows ...
CVE-2009-4418——The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resou...
CVE-2009-4417——The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to sen...
CVE-2009-4416——Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9....
CVE-2009-4415——Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, a...
CVE-2009-4414——SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versio...
CVE-2009-4413——The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remot...
CVE-2009-4412——Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary ...
CVE-2009-4411——The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links e...
CVE-2009-4410——The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y...
CVE-2009-4137——The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookie...
CVE-2009-3305——Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request wi...
CVE-2009-4409——The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet ...
CVE-2009-4408——Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and...
CVE-2009-4407——Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly ...
CVE-2009-4406——Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2,...
CVE-2009-4405——Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (...
CVE-2009-4145——nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection e...
CVE-2009-4144——NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WP...
CVE-2009-4404——Unspecified vulnerability in t-prot (TOFU Protection) before 2.8 allows remote attackers to cause a denial of service vi...
CVE-2009-4403——Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web s...
CVE-2009-4402——The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now