2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3422 | — | — | 2.6% | Sep 25, 2009 | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and ... |
| CVE-2009-3420 | — | — | 1.2% | Sep 25, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote at... |
| CVE-2009-3419 | — | — | 0.9% | Sep 25, 2009 | SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbi... |
| CVE-2009-3418 | — | — | 0.8% | Sep 25, 2009 | Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL ... |
| CVE-2009-3417 | — | — | 1.8% | Sep 25, 2009 | SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to e... |
| CVE-2009-3390 | — | — | 0.4% | Sep 24, 2009 | Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris s... |
| CVE-2009-2817 | — | — | 8.9% | Sep 24, 2009 | Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of serv... |
| CVE-2009-2682 | — | — | 0.5% | Sep 24, 2009 | Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypa... |
| CVE-2009-3369 | — | — | 2.9% | Sep 24, 2009 | CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict u... |
| CVE-2009-3368 | — | — | 1.5% | Sep 24, 2009 | Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component fo... |
| CVE-2009-3367 | — | — | 1.4% | Sep 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary w... |
| CVE-2009-3366 | — | — | 2.7% | Sep 24, 2009 | Directory traversal vulnerability in navigation.php in An image gallery 1.0 allows remote attackers to list arbitrary di... |
| CVE-2009-3365 | — | — | 2.1% | Sep 24, 2009 | PHP remote file inclusion vulnerability in add-ons/modules/sysmanager/plugins/install.plugin.php in Aurora CMS 1.0.2 all... |
| CVE-2009-3364 | — | — | 5.4% | Sep 24, 2009 | Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long re... |
| CVE-2009-3363 | — | — | 1.1% | Sep 24, 2009 | Cross-site scripting (XSS) vulnerability in the BUEditor module 5.x before 5.x-1.2 and 6.x before 6.x-1.4, a module for ... |
| CVE-2009-3362 | — | — | 3.0% | Sep 24, 2009 | PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP... |
| CVE-2009-3361 | — | — | 0.9% | Sep 24, 2009 | SQL injection vulnerability in index.php in PHP-IPNMonitor allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2009-3360 | — | — | 1.8% | Sep 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Datemill 1.0 allow remote attackers to inject arbitrary web scrip... |
| CVE-2009-3359 | — | — | 1.6% | Sep 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary w... |
| CVE-2009-3358 | — | — | 0.9% | Sep 24, 2009 | SQL injection vulnerability in profile.php in Tourism Scripts Adult Portal escort listing allows remote attackers to exe... |
| CVE-2009-3357 | — | — | 1.0% | Sep 24, 2009 | Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component for ... |
| CVE-2009-3356 | — | — | 1.0% | Sep 24, 2009 | SQL injection vulnerability in index.php in Image voting 1.0 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2009-3355 | — | — | 1.5% | Sep 24, 2009 | Cross-site scripting (XSS) vulnerability in profile.php in Datetopia Buy Dating Site 1.0 allows remote attackers to inje... |
| CVE-2009-3354 | — | — | 1.2% | Sep 24, 2009 | Multiple unspecified vulnerabilities in the Rest API module for Drupal have unknown impact and attack vectors. |
| CVE-2009-3353 | — | — | 1.3% | Sep 24, 2009 | Multiple unspecified vulnerabilities in the Node2Node module for Drupal have unknown impact and attack vectors. |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now