2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-3968——Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the...
CVE-2009-3967——SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrar...
CVE-2009-3966——Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a...
CVE-2009-3965——SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL comm...
CVE-2009-3964——SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers t...
CVE-2009-3963——Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.
CVE-2009-3962——The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5....
CVE-2009-3961——SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote atta...
CVE-2009-3892——Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and othe...
CVE-2009-3891——Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticate...
CVE-2009-3890——Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress befor...
CVE-2009-3841——Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows r...
CVE-2009-3950——Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web s...
CVE-2009-3949——cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewau...
CVE-2009-3948——JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and applicati...
CVE-2009-3947——Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces...
CVE-2009-3946——Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's versio...
CVE-2009-3945——Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote au...
CVE-2009-3944——Research In Motion (RIM) BlackBerry Browser on the BlackBerry 8800 allows remote attackers to cause a denial of service ...
CVE-2009-3943——Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a deni...
CVE-2009-3942——Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in ...
CVE-2009-3941——Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in t...
CVE-2009-3940——Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and ...
CVE-2009-3889——The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which all...
CVE-2009-3888——The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management uni...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now