2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-3968Multiple SQL injection vulnerabilities in ITechBids 8.0 allow remote attackers to execute arbitrary SQL commands via the...
CVE-2009-3967SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrar...
CVE-2009-3966Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a...
CVE-2009-3965SQL injection vulnerability in rating.php in New 5 star Rating 1.0 allows remote attackers to execute arbitrary SQL comm...
CVE-2009-3964SQL injection vulnerability in the NinjaMonials (com_ninjacentral) component 1.1.0 for Joomla! allows remote attackers t...
CVE-2009-3963Multiple unspecified vulnerabilities in XOOPS before 2.4.0 Final have unknown impact and attack vectors.
CVE-2009-3962The management interface on the 2wire Gateway 1700HG, 1701HG, 1800HW, 2071, 2700HG, and 2701HG-T with software before 5....
CVE-2009-3961SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote atta...
CVE-2009-3892Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and othe...
CVE-2009-3891Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticate...
CVE-2009-3890Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress befor...
CVE-2009-3841Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows r...
CVE-2009-3950Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web s...
CVE-2009-3949cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewau...
CVE-2009-3948JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and applicati...
CVE-2009-3947Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces...
CVE-2009-3946Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's versio...
CVE-2009-3945Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote au...
CVE-2009-3944Research In Motion (RIM) BlackBerry Browser on the BlackBerry 8800 allows remote attackers to cause a denial of service ...
CVE-2009-3943Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a deni...
CVE-2009-3942Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in ...
CVE-2009-3941Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in t...
CVE-2009-3940Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and ...
CVE-2009-3889The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which all...
CVE-2009-3888The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management uni...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now