2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3662 | — | — | 2.7% | Oct 11, 2009 | FileCopa FTP Server 5.01 allows remote attackers to cause a denial of service (server hang) via a large number of crafte... |
| CVE-2009-3661 | — | — | 0.9% | Oct 11, 2009 | Multiple SQL injection vulnerabilities in the DJ-Catalog (com_djcatalog) component for Joomla! allow remote attackers to... |
| CVE-2009-3660 | — | — | 1.9% | Oct 11, 2009 | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is ... |
| CVE-2009-3659 | — | — | 0.9% | Oct 11, 2009 | SQL injection vulnerability in file/stats.php in BS Counter 2.5.3 allows remote attackers to execute arbitrary SQL comma... |
| CVE-2009-3657 | — | — | 1.1% | Oct 9, 2009 | Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web... |
| CVE-2009-3656 | — | — | 0.6% | Oct 9, 2009 | Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attack... |
| CVE-2009-3655 | — | — | 4.0% | Oct 9, 2009 | Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via un... |
| CVE-2009-3654 | — | — | 1.6% | Oct 9, 2009 | Unspecified vulnerability in Boost before 6.x-1.03, a module for Drupal, allows remote attackers to create new webroot d... |
| CVE-2009-3653 | — | — | 0.8% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in the additional links interface in XML Sitemap 5.x-1.6, a module for Drupal, ... |
| CVE-2009-3652 | — | — | 1.0% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) 5.x-7.x before 5.x-7.4, 5.x-8.x before 5.x-8.1, and 6.x-... |
| CVE-2009-3651 | — | — | 1.3% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in the "Monitor browsers' feature in Browscap before 5.x-1.1 and 6.x-1.1, a mod... |
| CVE-2009-3650 | — | — | 1.0% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in Dex 5.x-1.0 and earlier and 6.x-1.0-rc1 and earlier, a module for Drupal, al... |
| CVE-2009-3649 | — | — | 0.8% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in forums/index.php in Power Bulletin Board (PBBoard) 2.0.2 and possibly earlie... |
| CVE-2009-3648 | — | — | 1.4% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in Service Links 6.x-1.0, a module for Drupal, allows remote authenticated user... |
| CVE-2009-3647 | — | — | 1.2% | Oct 9, 2009 | Cross-site scripting (XSS) vulnerability in emaullinks.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 all... |
| CVE-2009-3646 | — | — | 5.9% | Oct 9, 2009 | InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP reque... |
| CVE-2009-3645 | — | — | 1.0% | Oct 9, 2009 | SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remo... |
| CVE-2009-3644 | — | — | 0.9% | Oct 9, 2009 | SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute ... |
| CVE-2009-3643 | — | — | 6.4% | Oct 9, 2009 | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to th... |
| CVE-2009-3642 | — | — | 1.0% | Oct 9, 2009 | Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to exe... |
| CVE-2009-3601 | — | — | 3.0% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject a... |
| CVE-2009-3600 | — | — | 1.4% | Oct 8, 2009 | HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, wh... |
| CVE-2009-3599 | — | — | 1.5% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitr... |
| CVE-2009-3598 | — | — | 1.5% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject ... |
| CVE-2009-3597 | — | — | 3.2% | Oct 8, 2009 | Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows rem... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now