2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2626The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific ...
CVE-2009-4121Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attacker...
CVE-2009-4120Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen...
CVE-2009-4119Cross-site scripting (XSS) vulnerability in Feed Element Mapper module 5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2...
CVE-2009-4118The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0...
CVE-2009-4117Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF befor...
CVE-2009-4116Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote ...
CVE-2009-4115Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authentic...
CVE-2009-4114kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate...
CVE-2009-4113Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allo...
CVE-2009-4112Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Meth...
CVE-2009-4030MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM tabl...
CVE-2009-4028The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL...
CVE-2009-4019mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert...
CVE-2009-4110Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attac...
CVE-2009-4109The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related...
CVE-2009-4108XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or...
CVE-2009-4107Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a craft...
CVE-2009-4106Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers...
CVE-2009-4105TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (appen...
CVE-2009-4104SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remot...
CVE-2009-4103Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote FTP servers to cause a denial of service ...
CVE-2009-4102Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote att...
CVE-2009-4101infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remot...
CVE-2009-4100Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now