2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4207 | — | — | 1.1% | Dec 4, 2009 | Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for D... |
| CVE-2009-4206 | — | — | 1.0% | Dec 4, 2009 | SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attacker... |
| CVE-2009-4205 | — | — | 2.4% | Dec 4, 2009 | Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute... |
| CVE-2009-4204 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL comm... |
| CVE-2009-4203 | — | — | 2.0% | Dec 4, 2009 | Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execu... |
| CVE-2009-4202 | — | — | 8.1% | Dec 4, 2009 | Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows... |
| CVE-2009-4201 | — | — | 4.8% | Dec 4, 2009 | Multiple stack-based buffer overflows in Mp3 Tag Assistant Professional 2.92 build 300 allow remote attackers to execute... |
| CVE-2009-4200 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute a... |
| CVE-2009-4199 | — | — | 0.8% | Dec 4, 2009 | Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Jo... |
| CVE-2009-4198 | — | — | 0.9% | Dec 4, 2009 | SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL co... |
| CVE-2009-4148 | — | — | 5.5% | Dec 4, 2009 | DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .d... |
| CVE-2009-3304 | — | — | 0.3% | Dec 4, 2009 | GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_key... |
| CVE-2009-4197 | — | — | 0.5% | Dec 4, 2009 | rpwizPppoe.htm in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 contains a form that does not disable the au... |
| CVE-2009-4196 | — | — | 1.0% | Dec 4, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T run... |
| CVE-2009-4195 | — | — | 70.7% | Dec 4, 2009 | Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execu... |
| CVE-2009-2631 | — | — | 5.1% | Dec 4, 2009 | Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Cla... |
| CVE-2009-4194 | HIGH | 8.1 | 3.4% | Dec 3, 2009 | Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions all... |
| CVE-2009-4193 | — | — | 0.3% | Dec 3, 2009 | Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log tem... |
| CVE-2009-4192 | — | — | 2.7% | Dec 3, 2009 | Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers t... |
| CVE-2009-1566 | — | — | 6.7% | Dec 3, 2009 | Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to... |
| CVE-2009-4191 | — | — | 0.3% | Dec 3, 2009 | Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local us... |
| CVE-2009-4190 | — | — | 1.2% | Dec 3, 2009 | Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause a denial of service ... |
| CVE-2009-4189 | — | — | 72.7% | Dec 3, 2009 | HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe... |
| CVE-2009-4188 | — | — | 70.2% | Dec 3, 2009 | HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t... |
| CVE-2009-4187 | — | — | 1.7% | Dec 3, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now