2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4099 | — | — | 2.3% | Nov 29, 2009 | SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlie... |
| CVE-2009-4098 | — | — | 18.7% | Nov 29, 2009 | Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticate... |
| CVE-2009-4097 | — | — | 5.8% | Nov 29, 2009 | Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta... |
| CVE-2009-4096 | — | — | 2.3% | Nov 29, 2009 | RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows r... |
| CVE-2009-4111 | — | — | 1.6% | Nov 29, 2009 | Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions f... |
| CVE-2009-4081 | — | — | 0.3% | Nov 29, 2009 | Untrusted search path vulnerability in dstat before r3199 allows local users to gain privileges via a Trojan horse Pytho... |
| CVE-2009-4080 | — | — | 0.3% | Nov 29, 2009 | Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 ... |
| CVE-2009-3894 | — | — | 0.3% | Nov 29, 2009 | Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan h... |
| CVE-2009-3736 | — | — | 0.4% | Nov 29, 2009 | ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly... |
| CVE-2009-4025 | — | — | 6.1% | Nov 29, 2009 | Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.... |
| CVE-2009-4024 | — | — | 6.1% | Nov 29, 2009 | Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows r... |
| CVE-2009-4023 | — | — | 2.4% | Nov 29, 2009 | Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail... |
| CVE-2009-4095 | — | — | 1.5% | Nov 29, 2009 | myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are o... |
| CVE-2009-4094 | — | — | 2.3% | Nov 29, 2009 | PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for... |
| CVE-2009-4093 | — | — | 3.9% | Nov 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remo... |
| CVE-2009-4092 | — | — | 5.4% | Nov 29, 2009 | Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta... |
| CVE-2009-4091 | — | — | 6.5% | Nov 29, 2009 | comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers ... |
| CVE-2009-4090 | — | — | 3.2% | Nov 29, 2009 | Unrestricted file upload vulnerability in ajax/addComment.php in telepark.wiki 2.4.23 and earlier script allows remote a... |
| CVE-2009-4089 | — | — | 6.6% | Nov 29, 2009 | telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a mo... |
| CVE-2009-4088 | — | — | 2.8% | Nov 29, 2009 | Multiple directory traversal vulnerabilities in telepark.wiki 2.4.23 and earlier allow remote attackers to read arbitrar... |
| CVE-2009-4087 | — | — | 1.1% | Nov 29, 2009 | Cross-site scripting (XSS) vulnerability in index.php in telepark.wiki 2.4.23 and earlier allows remote attackers to inj... |
| CVE-2009-4086 | — | — | 4.8% | Nov 29, 2009 | CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP header... |
| CVE-2009-4085 | — | — | 2.3% | Nov 29, 2009 | PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attacke... |
| CVE-2009-4084 | — | — | 1.1% | Nov 29, 2009 | SQL injection vulnerability in the search feature in e107 0.7.16 and earlier allows remote attackers to execute arbitrar... |
| CVE-2009-4083 | — | — | 1.0% | Nov 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.16 and earlier allow remote attackers to inject arbitrar... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now