2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-3961SQL injection vulnerability in user.php in Super Serious Stats (aka superseriousstats) before 1.1.2p1 allows remote atta...
CVE-2009-3892Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and othe...
CVE-2009-3891Cross-site scripting (XSS) vulnerability in wp-admin/press-this.php in WordPress before 2.8.6 allows remote authenticate...
CVE-2009-3890Unrestricted file upload vulnerability in the wp_check_filetype function in wp-includes/functions.php in WordPress befor...
CVE-2009-3841Unspecified vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.60 on Windows allows r...
CVE-2009-3950Multiple cross-site scripting (XSS) vulnerabilities in Bractus SunTrack allow remote attackers to inject arbitrary web s...
CVE-2009-3949cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewau...
CVE-2009-3948JetAudio 7.5.3 COWON Media Center allows remote attackers to cause a denial of service (memory consumption and applicati...
CVE-2009-3947Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces...
CVE-2009-3946Joomla! before 1.5.15 allows remote attackers to read an extension's XML file, and thereby obtain the extension's versio...
CVE-2009-3945Unspecified vulnerability in the Front-End Editor in the com_content component in Joomla! before 1.5.15 allows remote au...
CVE-2009-3944Research In Motion (RIM) BlackBerry Browser on the BlackBerry 8800 allows remote attackers to cause a denial of service ...
CVE-2009-3943Microsoft Internet Explorer 6 through 6.0.2900.2180 and 7 through 7.0.6000.16711 allows remote attackers to cause a deni...
CVE-2009-3942Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in ...
CVE-2009-3941Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in t...
CVE-2009-3940Unspecified vulnerability in Guest Additions in Sun xVM VirtualBox 1.6.x and 2.0.x before 2.0.12, 2.1.x, and 2.2.x, and ...
CVE-2009-3939HIGH7.1The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permission...
CVE-2009-3889The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which all...
CVE-2009-3888The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management uni...
CVE-2009-2746Cross-site request forgery (CSRF) vulnerability in the administrative console in the Security component in IBM WebSphere...
CVE-2009-3938Buffer overflow in the ABWOutputDev::endWord function in poppler/ABWOutputDev.cc in Poppler (aka libpoppler) 0.10.6, 0.1...
CVE-2009-3937Memory leak in Solaris TCP sockets in Sun OpenSolaris snv_106 through snv_126 allows local users to cause a denial of se...
CVE-2009-3936Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-...
CVE-2009-3676The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-...
CVE-2009-3566McAfee IntruShield Network Security Manager (NSM) before 5.1.11.8.1 does not include the HTTPOnly flag in the Set-Cookie...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now