2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3968 | — | — | 0.9% | Nov 18, 2009 | Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the... |
| CVE-2009-3967 | — | — | 1.0% | Nov 18, 2009 | SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrar... |
| CVE-2009-3966 | — | — | 2.3% | Nov 18, 2009 | Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a... |
| CVE-2009-3965 | — | — | 1.1% | Nov 18, 2009 | SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL comm... |
| CVE-2009-3964 | — | — | 0.9% | Nov 18, 2009 | SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers t... |
| CVE-2009-3963 | — | — | 1.6% | Nov 17, 2009 | Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors. |
| CVE-2009-3962 | — | — | 3.0% | Nov 17, 2009 | The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5.... |
| CVE-2009-3961 | — | — | 1.1% | Nov 17, 2009 | SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote atta... |
| CVE-2009-3892 | — | — | 1.1% | Nov 17, 2009 | Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and othe... |
| CVE-2009-3891 | — | — | 2.1% | Nov 17, 2009 | Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticate... |
| CVE-2009-3890 | — | — | 8.4% | Nov 17, 2009 | Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress befor... |
| CVE-2009-3841 | — | — | 3.4% | Nov 17, 2009 | Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows r... |
| CVE-2009-3950 | — | — | 0.9% | Nov 16, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web s... |
| CVE-2009-3949 | — | — | 2.2% | Nov 16, 2009 | cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewau... |
| CVE-2009-3948 | — | — | 1.9% | Nov 16, 2009 | JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and applicati... |
| CVE-2009-3947 | — | — | 4.8% | Nov 16, 2009 | Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces... |
| CVE-2009-3946 | — | — | 1.2% | Nov 16, 2009 | Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's versio... |
| CVE-2009-3945 | — | — | 1.1% | Nov 16, 2009 | Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote au... |
| CVE-2009-3944 | — | — | 1.1% | Nov 16, 2009 | Research In Motion (RIM) BlackBerry Browser on the BlackBerry 8800 allows remote attackers to cause a denial of service ... |
| CVE-2009-3943 | — | — | 13.0% | Nov 16, 2009 | Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a deni... |
| CVE-2009-3942 | — | — | 1.1% | Nov 16, 2009 | Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in ... |
| CVE-2009-3941 | — | — | 0.9% | Nov 16, 2009 | Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in t... |
| CVE-2009-3940 | — | — | 0.4% | Nov 16, 2009 | Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and ... |
| CVE-2009-3889 | — | — | 0.5% | Nov 16, 2009 | The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which all... |
| CVE-2009-3888 | — | — | 0.7% | Nov 16, 2009 | The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management uni... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now