2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4043 | — | — | 1.3% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal all... |
| CVE-2009-4042 | — | — | 1.3% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to... |
| CVE-2009-4041 | — | — | 2.2% | Nov 20, 2009 | UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags. |
| CVE-2009-4040 | — | — | 1.0% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explo... |
| CVE-2009-4039 | — | — | 1.9% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script o... |
| CVE-2009-4038 | — | — | 1.9% | Nov 20, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attacker... |
| CVE-2009-4037 | — | — | 1.3% | Nov 20, 2009 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attac... |
| CVE-2009-3895 | — | — | 5.1% | Nov 20, 2009 | Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif... |
| CVE-2009-3842 | — | — | 3.6% | Nov 20, 2009 | Unspecified vulnerability on the HP Color LaserJet M3530 Multifunction Printer with firmware 05.058.4 and the Color Lase... |
| CVE-2009-3386 | — | — | 1.7% | Nov 20, 2009 | Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a pri... |
| CVE-2009-3080 | — | — | 0.4% | Nov 20, 2009 | Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows lo... |
| CVE-2009-4006 | — | — | 82.9% | Nov 20, 2009 | Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other ver... |
| CVE-2009-4005 | — | — | 0.4% | Nov 20, 2009 | The collect_rx_frame function in drivers/isdn/hisax/hfc_usb.c in the Linux kernel before 2.6.32-rc7 allows attackers to ... |
| CVE-2009-3978 | — | — | 1.8% | Nov 19, 2009 | The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows... |
| CVE-2009-3977 | — | — | 2.3% | Nov 19, 2009 | Multiple buffer overflows in a certain ActiveX control in ActiveDom.ocx in HP OpenView Network Node Manager (OV NNM) 7.5... |
| CVE-2009-3909 | — | — | 8.7% | Nov 19, 2009 | Integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP 2.6.7 might allow remote atta... |
| CVE-2009-3840 | — | — | 9.3% | Nov 19, 2009 | The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows... |
| CVE-2009-3976 | — | — | 28.3% | Nov 18, 2009 | Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execu... |
| CVE-2009-3975 | — | — | 0.9% | Nov 18, 2009 | SQL injection vulnerability in index.php in Moa Gallery 1.1.0 and 1.2.0 allows remote attackers to execute arbitrary SQL... |
| CVE-2009-3974 | — | — | 1.0% | Nov 18, 2009 | Multiple SQL injection vulnerabilities in Invision Power Board (IPB or IP.Board) 3.0.0, 3.0.1, and 3.0.2 allow remote at... |
| CVE-2009-3973 | — | — | 1.0% | Nov 18, 2009 | SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma... |
| CVE-2009-3972 | — | — | 1.0% | Nov 18, 2009 | SQL injection vulnerability in the Q-Proje Siirler Bileseni (com_siirler) component 1.2 RC for Joomla! allows remote att... |
| CVE-2009-3971 | — | — | 1.0% | Nov 18, 2009 | SQL injection vulnerability in the jTips (com_jtips) component 1.0.7 and 1.0.9 for Joomla! allows remote attackers to ex... |
| CVE-2009-3970 | — | — | 0.9% | Nov 18, 2009 | SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote auth... |
| CVE-2009-3969 | — | — | 6.2% | Nov 18, 2009 | Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash)... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now