2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3646 | — | — | 5.9% | Oct 9, 2009 | InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP reque... |
| CVE-2009-3645 | — | — | 1.0% | Oct 9, 2009 | SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remo... |
| CVE-2009-3644 | — | — | 0.9% | Oct 9, 2009 | SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute ... |
| CVE-2009-3643 | — | — | 6.4% | Oct 9, 2009 | Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to th... |
| CVE-2009-3642 | — | — | 1.0% | Oct 9, 2009 | Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to exe... |
| CVE-2009-3601 | — | — | 3.0% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject a... |
| CVE-2009-3600 | — | — | 1.4% | Oct 8, 2009 | HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, wh... |
| CVE-2009-3599 | — | — | 1.5% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitr... |
| CVE-2009-3598 | — | — | 1.5% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject ... |
| CVE-2009-3597 | — | — | 3.2% | Oct 8, 2009 | Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows rem... |
| CVE-2009-3596 | — | — | 2.3% | Oct 8, 2009 | JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypa... |
| CVE-2009-3595 | — | — | 1.0% | Oct 8, 2009 | SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-3594 | — | — | 1.0% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog System before 1.2 allows remote attackers to inject a... |
| CVE-2009-3593 | — | — | 1.5% | Oct 8, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web sc... |
| CVE-2009-3592 | — | — | 1.5% | Oct 8, 2009 | Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbi... |
| CVE-2009-3591 | — | — | 52.8% | Oct 8, 2009 | Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with ... |
| CVE-2009-3590 | — | — | 1.0% | Oct 8, 2009 | SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-3589 | — | — | 0.3% | Oct 8, 2009 | incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the ... |
| CVE-2009-2948 | — | — | 0.5% | Oct 7, 2009 | mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is inst... |
| CVE-2009-2906 | — | — | 4.2% | Oct 7, 2009 | smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated u... |
| CVE-2009-3579 | — | — | 1.1% | Oct 7, 2009 | Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 a... |
| CVE-2009-3575 | — | — | 5.8% | Oct 7, 2009 | Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to ... |
| CVE-2009-3527 | — | — | 0.6% | Oct 6, 2009 | Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (... |
| CVE-2009-3574 | — | — | 4.8% | Oct 6, 2009 | Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a lon... |
| CVE-2009-3573 | — | — | 5.7% | Oct 6, 2009 | Multiple insecure method vulnerabilities in the PDIControl.PDI.1 ActiveX control (PDIControl.dll) 2.2.3160.0 in EMC Capt... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now