2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4082 | — | — | 3.0% | Nov 29, 2009 | PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli... |
| CVE-2009-4032 | — | — | 5.7% | Nov 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web scrip... |
| CVE-2009-4031 | — | — | 3.1% | Nov 29, 2009 | The do_insn_fetch function in arch/x86/kvm/emulate.c in the x86 emulator in the KVM subsystem in the Linux kernel before... |
| CVE-2009-4018 | — | — | 11.3% | Nov 29, 2009 | The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) ... |
| CVE-2009-4079 | — | — | 0.7% | Nov 25, 2009 | Cross-site request forgery (CSRF) vulnerability in Redmine 0.8.5 and earlier allows remote attackers to hijack the authe... |
| CVE-2009-4078 | — | — | 1.5% | Nov 25, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Redmine 0.8.5 and earlier allow remote attackers to inject arbitr... |
| CVE-2009-4077 | — | — | 1.3% | Nov 25, 2009 | Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack... |
| CVE-2009-4076 | — | — | 1.3% | Nov 25, 2009 | Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail 0.2.2 and earlier allows remote attackers to hijack... |
| CVE-2009-4075 | — | — | 2.7% | Nov 25, 2009 | Unspecified vulnerability in the timeout mechanism in sshd in Sun Solaris 10, and OpenSolaris snv_99 through snv_123, al... |
| CVE-2009-4074 | — | — | 14.8% | Nov 25, 2009 | The XSS Filter in Microsoft Internet Explorer 8 allows remote attackers to leverage the "response-changing mechanism" to... |
| CVE-2009-4022 | — | — | 8.0% | Nov 25, 2009 | Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2... |
| CVE-2009-4021 | — | — | 0.4% | Nov 25, 2009 | The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow at... |
| CVE-2009-3033 | — | — | 40.0% | Nov 25, 2009 | Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilitie... |
| CVE-2009-4073 | — | — | 19.6% | Nov 24, 2009 | The printing functionality in Microsoft Internet Explorer 8 allows remote attackers to discover a local pathname, and po... |
| CVE-2009-4072 | — | — | 2.4% | Nov 24, 2009 | Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe i... |
| CVE-2009-4071 | — | — | 2.2% | Nov 24, 2009 | Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variabl... |
| CVE-2009-4070 | — | — | 1.7% | Nov 24, 2009 | SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbi... |
| CVE-2009-4069 | — | — | 1.7% | Nov 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote at... |
| CVE-2009-3898 | — | — | 15.9% | Nov 24, 2009 | Directory traversal vulnerability in src/http/modules/ngx_http_dav_module.c in nginx (aka Engine X) before 0.7.63, and 0... |
| CVE-2009-3896 | — | — | 10.2% | Nov 24, 2009 | src/http/ngx_http_parse.c in nginx (aka Engine X) 0.1.0 through 0.4.14, 0.5.x before 0.5.38, 0.6.x before 0.6.39, 0.7.x ... |
| CVE-2009-3578 | — | — | 4.4% | Nov 24, 2009 | Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbi... |
| CVE-2009-3577 | — | — | 5.1% | Nov 24, 2009 | Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via ... |
| CVE-2009-3576 | — | — | 3.2% | Nov 24, 2009 | Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac... |
| CVE-2009-3303 | — | — | 1.7% | Nov 24, 2009 | Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote atta... |
| CVE-2009-4066 | — | — | 0.7% | Nov 24, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in the "My Account" feature in PHPList Integration module 5 b... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now