2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-3646InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP reque...
CVE-2009-3645SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remo...
CVE-2009-3644SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute ...
CVE-2009-3643Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to th...
CVE-2009-3642Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to exe...
CVE-2009-3601Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject a...
CVE-2009-3600HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, wh...
CVE-2009-3599Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitr...
CVE-2009-3598Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject ...
CVE-2009-3597Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows rem...
CVE-2009-3596JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypa...
CVE-2009-3595SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-3594Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog System before 1.2 allows remote attackers to inject a...
CVE-2009-3593Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web sc...
CVE-2009-3592Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbi...
CVE-2009-3591Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with ...
CVE-2009-3590SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-3589incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the ...
CVE-2009-2948mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is inst...
CVE-2009-2906smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated u...
CVE-2009-3579Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 a...
CVE-2009-3575Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to ...
CVE-2009-3527Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (...
CVE-2009-3574Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a lon...
CVE-2009-3573Multiple insecure method vulnerabilities in the PDIControl.PDI.1 ActiveX control (PDIControl.dll) 2.2.3160.0 in EMC Capt...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now