2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3921 | — | — | 1.2% | Nov 9, 2009 | The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node ... |
| CVE-2009-3920 | — | — | 1.4% | Nov 9, 2009 | An administration page in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal does not perform th... |
| CVE-2009-3919 | — | — | 1.2% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal a... |
| CVE-2009-3918 | — | — | 1.3% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for D... |
| CVE-2009-3917 | — | — | 1.1% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows r... |
| CVE-2009-3916 | — | — | 1.3% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the Node Hierarchy module 5.x before 5.x-1.3 and 6.x before 6.x-1.3, a modul... |
| CVE-2009-3915 | — | — | 1.3% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the "Separate title and URL" formatter in the Link module 5.x before 5.x-2.6... |
| CVE-2009-3914 | — | — | 1.2% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the Temporary Invitation module 5.x before 5.x-2.3 for Drupal allows remote ... |
| CVE-2009-3913 | — | — | 2.7% | Nov 9, 2009 | SQL injection vulnerability in summary.php in Xerox Fiery Webtools allows remote attackers to execute arbitrary SQL comm... |
| CVE-2009-3912 | — | — | 2.7% | Nov 9, 2009 | Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a ... |
| CVE-2009-3911 | — | — | 1.5% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in settings.php in TFTgallery 0.13 allows remote attackers to inject arbitrary ... |
| CVE-2009-3905 | — | — | 1.3% | Nov 6, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web scri... |
| CVE-2009-3904 | — | — | 8.7% | Nov 6, 2009 | classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, whi... |
| CVE-2009-3903 | — | — | 1.6% | Nov 6, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in jspui/index.jsp in ManageEngine Netflow Analyzer 7.5 build 7500 a... |
| CVE-2009-3902 | — | — | 3.5% | Nov 6, 2009 | Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read a... |
| CVE-2009-3901 | — | — | 1.3% | Nov 6, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web scri... |
| CVE-2009-3900 | — | — | 2.6% | Nov 6, 2009 | Unspecified vulnerability in the Cluster Management component in IBM PowerHA 5.4, 5.4.1, 5.5, and 6.1 on AIX allows remo... |
| CVE-2009-3899 | — | — | 2.9% | Nov 6, 2009 | Memory leak in the Sockets Direct Protocol (SDP) driver in Sun Solaris 10, and OpenSolaris snv_57 through snv_94, allows... |
| CVE-2009-3850 | — | — | 9.4% | Nov 6, 2009 | Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains P... |
| CVE-2009-3725 | — | — | 0.6% | Nov 6, 2009 | The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain intera... |
| CVE-2009-3300 | — | — | 1.7% | Nov 6, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the Identity Provider (IdP) 1.3.x before 1.3.4 and 2.x before 2.1... |
| CVE-2009-2685 | — | — | 76.7% | Nov 6, 2009 | Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers t... |
| CVE-2009-3878 | — | — | 2.5% | Nov 5, 2009 | Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstr... |
| CVE-2009-3877 | — | — | 4.8% | Nov 5, 2009 | Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JR... |
| CVE-2009-3876 | — | — | 3.4% | Nov 5, 2009 | Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JR... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now