2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4017 | — | — | 12.0% | Nov 24, 2009 | PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipa... |
| CVE-2009-3843 | — | — | 78.8% | Nov 24, 2009 | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all... |
| CVE-2009-4054 | — | — | — | Nov 23, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-3672. Reason: This candidate is a duplicate of... |
| CVE-2009-4053 | MEDIUM | 6.5 | 3.5% | Nov 23, 2009 | Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) creat... |
| CVE-2009-4052 | — | — | 2.0% | Nov 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Develo... |
| CVE-2009-4051 | — | — | 6.2% | Nov 23, 2009 | Home FTP Server 1.10.1.139 allows remote attackers to cause a denial of service (daemon outage) via multiple invalid SIT... |
| CVE-2009-4050 | — | — | 7.6% | Nov 23, 2009 | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files ... |
| CVE-2009-4049 | — | — | 1.1% | Nov 23, 2009 | Heap-based buffer overflow in aswRdr.sys (aka the TDI RDR driver) in avast! Home and Professional 4.8.1356.0 allows loca... |
| CVE-2009-4048 | — | — | 2.4% | Nov 23, 2009 | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage)... |
| CVE-2009-4047 | — | — | 1.9% | Nov 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in PHD Help Desk 1.43 allow remote attackers to inject arbitrary web... |
| CVE-2009-3559 | — | — | 2.7% | Nov 23, 2009 | main/streams/plain_wrapper.c in PHP 5.3.x before 5.3.1 does not recognize the safe_mode_include_dir directive, which all... |
| CVE-2009-3558 | — | — | 2.1% | Nov 23, 2009 | The posix_mkfifo function in ext/posix/posix.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent atta... |
| CVE-2009-3557 | — | — | 2.1% | Nov 23, 2009 | The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attacke... |
| CVE-2009-4046 | — | — | 1.1% | Nov 20, 2009 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) 2.2.x before 2.2 RC allow remote attackers to execute arb... |
| CVE-2009-4045 | — | — | 1.1% | Nov 20, 2009 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary ... |
| CVE-2009-4044 | — | — | 1.4% | Nov 20, 2009 | The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to ma... |
| CVE-2009-4043 | — | — | 1.3% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in the AddToAny module 5.x before 5.x-2.4 and 6.x before 6.x-2.4 for Drupal all... |
| CVE-2009-4042 | — | — | 1.3% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in the RootCandy theme 6.x before 6.x-1.5 for Drupal allows remote attackers to... |
| CVE-2009-4041 | — | — | 2.2% | Nov 20, 2009 | UseBB 1.0.9 before 1.0.10 allows remote attackers to cause a denial of service (infinite loop) via crafted BBCode tags. |
| CVE-2009-4040 | — | — | 1.0% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explo... |
| CVE-2009-4039 | — | — | 1.9% | Nov 20, 2009 | Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script o... |
| CVE-2009-4038 | — | — | 1.9% | Nov 20, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in NCH Software Axon Virtual PBX 2.10 and 2.11 allow remote attacker... |
| CVE-2009-4037 | — | — | 1.3% | Nov 20, 2009 | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attac... |
| CVE-2009-3895 | — | — | 5.1% | Nov 20, 2009 | Heap-based buffer overflow in the exif_entry_fix function (aka the tag fixup routine) in libexif/exif-entry.c in libexif... |
| CVE-2009-3842 | — | — | 3.6% | Nov 20, 2009 | Unspecified vulnerability on the HP Color LaserJet M3530 Multifunction Printer with firmware 05.058.4 and the Color Lase... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now