2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-3646——InterVations NaviCOPA Web Server 3.01 allows remote attackers to obtain the source code for a web page via an HTTP reque...
CVE-2009-3645——SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remo...
CVE-2009-3644——SQL injection vulnerability in the Soundset (com_soundset) component 1.0 for Joomla! allows remote attackers to execute ...
CVE-2009-3643——Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to th...
CVE-2009-3642——Multiple SQL injection vulnerabilities in the Call Logging feature in FrontRange HEAT 8.01 allow remote attackers to exe...
CVE-2009-3601——Cross-site scripting (XSS) vulnerability in demo_page.php in Scriptsez Ultimate Poll allows remote attackers to inject a...
CVE-2009-3600——HUBScript 1.0 allows remote attackers to obtain configuration information via a direct request to manage/phpinfo.php, wh...
CVE-2009-3599——Cross-site scripting (XSS) vulnerability in single_winner1.php in HUBScript 1.0 allows remote attackers to inject arbitr...
CVE-2009-3598——Cross-site scripting (XSS) vulnerability in survey_result.php in eCardMAX FormXP 2007 allows remote attackers to inject ...
CVE-2009-3597——Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access control, which allows rem...
CVE-2009-3596——JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypa...
CVE-2009-3595——SQL injection vulnerability in results.php in VS PANEL 7.5.5 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-3594——Cross-site scripting (XSS) vulnerability in bpost.php in BLOB Blog System before 1.2 allows remote attackers to inject a...
CVE-2009-3593——Multiple cross-site scripting (XSS) vulnerabilities in Freelancers 1.0 allow remote attackers to inject arbitrary web sc...
CVE-2009-3592——Cross-site scripting (XSS) vulnerability in customer/home.php in Qualiteam X-Cart allows remote attackers to inject arbi...
CVE-2009-3591——Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with ...
CVE-2009-3590——SQL injection vulnerability in showcat.php in VS PANEL 7.3.6 allows remote attackers to execute arbitrary SQL commands v...
CVE-2009-3589——incron 0.5.5 does not initialize supplementary groups when running a process from a user's incrontabs, which causes the ...
CVE-2009-2948——mount.cifs in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8 and 3.4 before 3.4.2, when mount.cifs is inst...
CVE-2009-2906——smbd in Samba 3.0 before 3.0.37, 3.2 before 3.2.15, 3.3 before 3.3.8, and 3.4 before 3.4.2 allows remote authenticated u...
CVE-2009-3579——Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 a...
CVE-2009-3575——Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to ...
CVE-2009-3527——Race condition in the Pipe (IPC) close function in FreeBSD 6.3 and 6.4 allows local users to cause a denial of service (...
CVE-2009-3574——Tuniac 090517c allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a lon...
CVE-2009-3573——Multiple insecure method vulnerabilities in the PDIControl.PDI.1 ActiveX control (PDIControl.dll) 2.2.3160.0 in EMC Capt...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now