2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4156 | — | — | 2.1% | Dec 2, 2009 | PHP remote file inclusion vulnerability in modules/pms/index.php in Ciamos CMS 0.9.5 and earlier allows remote attackers... |
| CVE-2009-4155 | — | — | 0.9% | Dec 2, 2009 | Multiple SQL injection vulnerabilities in Eshopbuilde CMS allow remote attackers to execute arbitrary SQL commands via t... |
| CVE-2009-4154 | — | — | 2.9% | Dec 2, 2009 | Directory traversal vulnerability in includes/feedcreator.class.php in Elxis CMS allows remote attackers to read arbitra... |
| CVE-2009-4153 | — | — | 1.2% | Dec 2, 2009 | Unspecified vulnerability in the XMLAccess component in IBM WebSphere Portal 6.1.x before 6.1.0.3 has unknown impact and... |
| CVE-2009-4152 | — | — | 1.1% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in the Collaboration component in IBM WebSphere Portal 6.1.x before 6.1.0.3 all... |
| CVE-2009-4151 | — | — | 1.8% | Dec 2, 2009 | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 an... |
| CVE-2009-4027 | — | — | 2.3% | Dec 2, 2009 | Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to ... |
| CVE-2009-4026 | — | — | 3.1% | Dec 2, 2009 | The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of ... |
| CVE-2009-3585 | — | — | 2.7% | Dec 2, 2009 | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 an... |
| CVE-2009-2686 | — | — | 0.4% | Dec 2, 2009 | Unspecified vulnerability in HP NonStop G06.12.00 through G06.32.00, H06.08.00 through H06.18.01, and J06.04.00 through ... |
| CVE-2009-4150 | — | — | 0.4% | Dec 2, 2009 | dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged u... |
| CVE-2009-4055 | — | — | 2.8% | Dec 2, 2009 | rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.... |
| CVE-2009-3672 | — | — | 71.8% | Dec 2, 2009 | Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or... |
| CVE-2009-4128 | — | — | 0.6% | Dec 1, 2009 | GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, w... |
| CVE-2009-2626 | — | — | 8.3% | Dec 1, 2009 | The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific ... |
| CVE-2009-4121 | — | — | 0.6% | Dec 1, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.CMS 2.4 and Quick.CMS.Lite 2.4 allow remote attacker... |
| CVE-2009-4120 | — | — | 1.0% | Dec 1, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen... |
| CVE-2009-4119 | — | — | 1.3% | Dec 1, 2009 | Cross-site scripting (XSS) vulnerability in Feed Element Mapper module 5.x before 5.x-1.3, 6.x before 6.x-1.3, and 6.x-2... |
| CVE-2009-4118 | — | — | 2.5% | Dec 1, 2009 | The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0... |
| CVE-2009-4117 | — | — | 7.8% | Dec 1, 2009 | Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF befor... |
| CVE-2009-4116 | — | — | 2.0% | Nov 30, 2009 | Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote ... |
| CVE-2009-4115 | — | — | 2.0% | Nov 30, 2009 | Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authentic... |
| CVE-2009-4114 | — | — | 0.8% | Nov 30, 2009 | kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate... |
| CVE-2009-4113 | — | — | 1.3% | Nov 30, 2009 | Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allo... |
| CVE-2009-4112 | — | — | 11.5% | Nov 30, 2009 | Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Meth... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now