2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4220 | — | — | 2.3% | Dec 7, 2009 | PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote... |
| CVE-2009-4219 | — | — | 9.3% | Dec 7, 2009 | Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Univ... |
| CVE-2009-4218 | — | — | 0.9% | Dec 7, 2009 | Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attacke... |
| CVE-2009-4217 | — | — | 0.9% | Dec 7, 2009 | SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote at... |
| CVE-2009-4216 | — | — | 5.6% | Dec 7, 2009 | Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remot... |
| CVE-2009-4215 | — | — | 0.4% | Dec 7, 2009 | Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Contro... |
| CVE-2009-4214 | — | — | 3.0% | Dec 7, 2009 | Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.... |
| CVE-2009-4211 | — | — | 1.7% | Dec 4, 2009 | The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform e... |
| CVE-2009-4020 | — | — | 5.0% | Dec 4, 2009 | Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecifi... |
| CVE-2009-3560 | — | — | 24.3% | Dec 4, 2009 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows con... |
| CVE-2009-4209 | — | — | 1.2% | Dec 4, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inj... |
| CVE-2009-4208 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary S... |
| CVE-2009-4207 | — | — | 1.1% | Dec 4, 2009 | Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for D... |
| CVE-2009-4206 | — | — | 1.0% | Dec 4, 2009 | SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attacker... |
| CVE-2009-4205 | — | — | 2.4% | Dec 4, 2009 | Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute... |
| CVE-2009-4204 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL comm... |
| CVE-2009-4203 | — | — | 2.0% | Dec 4, 2009 | Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execu... |
| CVE-2009-4202 | — | — | 8.1% | Dec 4, 2009 | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows... |
| CVE-2009-4201 | — | — | 4.8% | Dec 4, 2009 | Multiple stack-based buffer overflows in Mp3 Tag Assistant Professional 2.92 build 300 allow remote attackers to execute... |
| CVE-2009-4200 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute a... |
| CVE-2009-4199 | — | — | 0.8% | Dec 4, 2009 | Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Jo... |
| CVE-2009-4198 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL co... |
| CVE-2009-4148 | — | — | 5.5% | Dec 4, 2009 | DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .d... |
| CVE-2009-3304 | — | — | 0.3% | Dec 4, 2009 | GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_key... |
| CVE-2009-4197 | — | — | 0.5% | Dec 4, 2009 | rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the au... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now