2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4422Multiple cross-site scripting (XSS) vulnerabilities in the GetURLArguments function in jpgraph.php in Aditus Consulting ...
CVE-2009-4421Directory traversal vulnerability in languages_cgi.php in Simple PHP Blog 0.5.1 and earlier allows remote authenticated ...
CVE-2009-4420Buffer overflow in the bd daemon in F5 Networks BIG-IP Application Security Manager (ASM) 9.4.4 through 9.4.7 and 10.0.0...
CVE-2009-4419Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows ...
CVE-2009-4418The unserialize function in PHP 5.3.0 and earlier allows context-dependent attackers to cause a denial of service (resou...
CVE-2009-4417The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to sen...
CVE-2009-4416Cross-site scripting (XSS) vulnerability in login.php in phpGroupWare 0.9.16.12, and possibly other versions before 0.9....
CVE-2009-4415Multiple directory traversal vulnerabilities in phpGroupWare 0.9.16.12, and possibly other versions before 0.9.16.014, a...
CVE-2009-4414SQL injection vulnerability in phpgwapi /inc/class.auth_sql.inc.php in phpGroupWare 0.9.16.12, and possibly other versio...
CVE-2009-4413The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remot...
CVE-2009-4412Unrestricted file upload vulnerability in Serendipity before 1.5 allows remote authenticated users to execute arbitrary ...
CVE-2009-4411The (1) setfacl and (2) getfacl commands in XFS acl 2.2.47, when running in recursive (-R) mode, follow symbolic links e...
CVE-2009-4410The fuse_ioctl_copy_user function in the ioctl handler in fs/fuse/file.c in the Linux kernel 2.6.29-rc1 through 2.6.30.y...
CVE-2009-4137The loadContentFromCookie function in core/Cookie.php in Piwik before 0.5 does not validate strings obtained from cookie...
CVE-2009-3305Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request wi...
CVE-2009-4409The (1) CHAP and (2) MS-CHAP-V2 authentication capabilities in the PPP Access Concentrator (PPPAC) function in Internet ...
CVE-2009-4408Multiple cross-site scripting (XSS) vulnerabilities in models.parser in PyForum 1.0.3 and possibly earlier versions, and...
CVE-2009-4407Multiple cross-site request forgery (CSRF) vulnerabilities in PyForum 1.0.3 and possibly earlier versions, and possibly ...
CVE-2009-4406Cross-site scripting (XSS) vulnerability in Forms/login1 in American Power Conversion (APC) Switched Rack PDU AP7932 B2,...
CVE-2009-4405Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (...
CVE-2009-4145nm-connection-editor in NetworkManager (NM) 0.7.x exports connection objects over D-Bus upon actions in the connection e...
CVE-2009-4144NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WP...
CVE-2009-4404Unspecified vulnerability in t-prot (TOFU Protection) before 2.8 allows remote attackers to cause a denial of service vi...
CVE-2009-4403Cross-site scripting (XSS) vulnerability in index.php in Rumba XML 1.8 allows remote attackers to inject arbitrary web s...
CVE-2009-4402The default configuration of SQL-Ledger 2.8.24 allows remote attackers to perform unspecified administrative operations ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now