2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3494 | — | — | 0.9% | Sep 30, 2009 | Multiple SQL injection vulnerabilities in index.php in T-HTB Manager 0.5, when magic_quotes_gpc is disabled, allow remot... |
| CVE-2009-3493 | — | — | 1.6% | Sep 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject a... |
| CVE-2009-3492 | — | — | 2.1% | Sep 30, 2009 | Multiple PHP remote file inclusion vulnerabilities in Loggix Project 9.4.5 and earlier allow remote attackers to execute... |
| CVE-2009-3491 | — | — | 1.0% | Sep 30, 2009 | SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! all... |
| CVE-2009-3490 | — | — | 3.5% | Sep 30, 2009 | GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 cer... |
| CVE-2009-3488 | — | — | 0.8% | Sep 30, 2009 | Cross-site scripting (XSS) vulnerability in the Bibliography (aka Biblio) module 6.x-1.6 for Drupal allows remote authen... |
| CVE-2009-3487 | — | — | 1.2% | Sep 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authen... |
| CVE-2009-3486 | — | — | 1.2% | Sep 30, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the J-Web interface in Juniper JUNOS 8.5R1.14 allow remote authen... |
| CVE-2009-3485 | — | — | 1.5% | Sep 30, 2009 | Cross-site scripting (XSS) vulnerability in the J-Web interface in Juniper JUNOS 8.5R1.14 and 9.0R1.1 allows remote atta... |
| CVE-2009-3484 | — | — | 5.6% | Sep 30, 2009 | Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code v... |
| CVE-2009-3483 | — | — | 4.7% | Sep 30, 2009 | Heap-based buffer overflow in the Create New Site feature in GlobalSCAPE CuteFTP Professional, Home, and Lite 8.3.3 and ... |
| CVE-2009-3481 | — | — | 1.2% | Sep 30, 2009 | A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative aut... |
| CVE-2009-3480 | — | — | 1.1% | Sep 30, 2009 | SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to ... |
| CVE-2009-3479 | — | — | 1.1% | Sep 30, 2009 | Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module f... |
| CVE-2009-3478 | — | — | 1.3% | Sep 29, 2009 | Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocke... |
| CVE-2009-3477 | — | — | 0.6% | Sep 29, 2009 | The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.... |
| CVE-2009-3476 | — | — | 4.1% | Sep 29, 2009 | Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, a... |
| CVE-2009-3475 | — | — | 0.9% | Sep 29, 2009 | Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation... |
| CVE-2009-3474 | — | — | 1.5% | Sep 29, 2009 | OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2... |
| CVE-2009-3473 | — | — | 2.0% | Sep 29, 2009 | IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which ... |
| CVE-2009-3472 | — | — | 2.0% | Sep 29, 2009 | IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access re... |
| CVE-2009-3471 | — | — | 2.4% | Sep 29, 2009 | IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain... |
| CVE-2009-3470 | — | — | 2.2% | Sep 29, 2009 | IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows rem... |
| CVE-2009-3469 | — | — | 3.7% | Sep 29, 2009 | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote a... |
| CVE-2009-3468 | — | — | 0.4% | Sep 29, 2009 | Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is e... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now