2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3809 | — | — | 2.3% | Oct 27, 2009 | Acoustica MP3 Audio Mixer 1.0 and possibly 2.471 allows remote attackers to cause a denial of service (crash) via a long... |
| CVE-2009-3808 | — | — | 4.5% | Oct 27, 2009 | MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute... |
| CVE-2009-3807 | — | — | 2.8% | Oct 27, 2009 | Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a lon... |
| CVE-2009-3806 | — | — | 2.6% | Oct 27, 2009 | SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands ... |
| CVE-2009-3805 | — | — | 1.4% | Oct 27, 2009 | gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (applic... |
| CVE-2009-3804 | — | — | 0.8% | Oct 27, 2009 | Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execu... |
| CVE-2009-3803 | — | — | 1.8% | Oct 27, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Amiro.CMS 5.4.0.0 and earlier allow remote attackers to inject ar... |
| CVE-2009-3802 | — | — | 2.6% | Oct 27, 2009 | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") t... |
| CVE-2009-3801 | — | — | 1.0% | Oct 27, 2009 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-3790 | — | — | 3.9% | Oct 26, 2009 | Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of se... |
| CVE-2009-3789 | — | — | 2.8% | Oct 26, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web s... |
| CVE-2009-3788 | — | — | 1.2% | Oct 26, 2009 | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-3787 | — | — | 6.6% | Oct 26, 2009 | files.php in Vivvo CMS 4.1.5.1 allows remote attackers to conduct directory traversal attacks and read arbitrary files v... |
| CVE-2009-3786 | — | — | 1.7% | Oct 26, 2009 | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a ... |
| CVE-2009-3785 | — | — | 0.6% | Oct 26, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in Simplenews Statistics 6.x before 6.x-2.0, a module for Dru... |
| CVE-2009-3784 | — | — | 0.6% | Oct 26, 2009 | Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to... |
| CVE-2009-3783 | — | — | 1.1% | Oct 26, 2009 | Cross-site scripting (XSS) vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote... |
| CVE-2009-3782 | — | — | 1.0% | Oct 26, 2009 | Unspecified vulnerability in Userpoints 6.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with ... |
| CVE-2009-3781 | — | — | 2.2% | Oct 26, 2009 | The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access perm... |
| CVE-2009-3780 | — | — | 1.2% | Oct 26, 2009 | Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1 and 6.x before 6.x-1.1-alpha1, a module for Drupal,... |
| CVE-2009-3779 | — | — | 1.3% | Oct 26, 2009 | Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows... |
| CVE-2009-3778 | — | — | 1.3% | Oct 26, 2009 | SQL injection vulnerability in Moodle Course List 6.x before 6.x-1.2, a module for Drupal, allows remote attackers to ex... |
| CVE-2009-3625 | — | — | 8.2% | Oct 26, 2009 | Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbi... |
| CVE-2009-3611 | HIGH | 7.1 | 0.3% | Oct 26, 2009 | common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the file... |
| CVE-2009-3767 | — | — | 3.1% | Oct 23, 2009 | libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now