2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-4099——SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlie...
CVE-2009-4098——Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticate...
CVE-2009-4097——Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta...
CVE-2009-4096——RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows r...
CVE-2009-4111——Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions f...
CVE-2009-4081——Untrusted search path vulnerability in dstat before r3199 allows local users to gain privileges via a Trojan horse Pytho...
CVE-2009-4080——Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 ...
CVE-2009-3894——Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan h...
CVE-2009-3736——ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly...
CVE-2009-4025——Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21....
CVE-2009-4024——Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows r...
CVE-2009-4023——Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail...
CVE-2009-4095——myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are o...
CVE-2009-4094——PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for...
CVE-2009-4093——Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remo...
CVE-2009-4092——Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta...
CVE-2009-4091——comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers ...
CVE-2009-4090——Unrestricted file upload vulnerability in ajax/addComment.php in telepark.wiki 2.4.23 and earlier script allows remote a...
CVE-2009-4089——telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a mo...
CVE-2009-4088——Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrar...
CVE-2009-4087——Cross-site scripting (XSS) vulnerability in index.php in telepark.wiki 2.4.23 and earlier allows remote attackers to inj...
CVE-2009-4086——CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP header...
CVE-2009-4085——PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attacke...
CVE-2009-4084——SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrar...
CVE-2009-4083——Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.16 and earlier allow remote attackers to inject arbitrar...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now