2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-5095 | — | — | 1.9% | Sep 12, 2011 | PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute ar... |
| CVE-2009-5094 | — | — | 2.1% | Sep 12, 2011 | SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c... |
| CVE-2009-5093 | — | — | 2.9% | Sep 12, 2011 | Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary... |
| CVE-2009-5092 | — | — | 12.8% | Sep 12, 2011 | Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remo... |
| CVE-2009-5091 | — | — | 1.0% | Sep 12, 2011 | SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL comma... |
| CVE-2009-5090 | — | — | 2.0% | Sep 12, 2011 | SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows rem... |
| CVE-2009-5089 | — | — | 2.3% | Sep 12, 2011 | Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file... |
| CVE-2009-5088 | — | — | 1.0% | Sep 12, 2011 | SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman... |
| CVE-2009-5087 | — | — | 3.5% | Sep 12, 2011 | Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta... |
| CVE-2009-5086 | — | — | 1.0% | Sep 2, 2011 | Cross-site scripting (XSS) vulnerability in Appliance Configuration Manager (ACM) in Juniper IDP 4.1 before 4.1r3 and 4.... |
| CVE-2009-5063 | — | — | 1.5% | Aug 31, 2011 | Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent att... |
| CVE-2009-5085 | — | — | 1.1% | Aug 12, 2011 | IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID provider, does not delet... |
| CVE-2009-5084 | — | — | 0.3% | Aug 12, 2011 | IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTS... |
| CVE-2009-5083 | — | — | 1.2% | Aug 12, 2011 | IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not ... |
| CVE-2009-5082 | — | — | 0.3% | Jun 30, 2011 | The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) imprope... |
| CVE-2009-5081 | — | — | 0.3% | Jun 30, 2011 | The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (a... |
| CVE-2009-5080 | — | — | 0.4% | Jun 30, 2011 | The (1) contrib/eqn2graph/eqn2graph.sh, (2) contrib/grap2graph/grap2graph.sh, and (3) contrib/pic2graph/pic2graph.sh scr... |
| CVE-2009-5079 | — | — | 0.3% | Jun 30, 2011 | The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 a... |
| CVE-2009-5078 | — | — | 2.3% | Jun 30, 2011 | contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER opt... |
| CVE-2009-5044 | — | — | 0.4% | Jun 24, 2011 | contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a sy... |
| CVE-2009-5077 | — | — | 1.5% | Jun 8, 2011 | CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors ... |
| CVE-2009-5076 | — | — | 1.4% | Jun 8, 2011 | CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and... |
| CVE-2009-4008 | — | — | 2.7% | Jun 2, 2011 | Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remot... |
| CVE-2009-5024 | — | — | 2.6% | May 23, 2011 | ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently condu... |
| CVE-2009-5075 | — | — | 1.0% | May 20, 2011 | Monkey's Audio before 4.02 allows remote attackers to cause a denial of service (application crash) via a malformed APE ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now