2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2865 | — | — | 5.5% | Sep 28, 2009 | Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Expr... |
| CVE-2009-2864 | — | — | 2.9% | Sep 28, 2009 | Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x befor... |
| CVE-2009-2863 | — | — | 2.5% | Sep 28, 2009 | Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to by... |
| CVE-2009-2862 | — | — | 2.3% | Sep 28, 2009 | The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ,... |
| CVE-2009-3431 | — | — | 21.4% | Sep 25, 2009 | Stack consumption vulnerability in Adobe Reader and Acrobat 9.1.3, 9.1.2, 9.1.1, and earlier 9.x versions; 8.1.6 and ear... |
| CVE-2009-3430 | — | — | 1.0% | Sep 25, 2009 | SQL injection vulnerability in login.php in Allomani Mobile 2.5 allows remote attackers to execute arbitrary SQL command... |
| CVE-2009-3429 | — | — | 35.0% | Sep 25, 2009 | Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code ... |
| CVE-2009-3428 | — | — | 6.1% | Sep 25, 2009 | Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted... |
| CVE-2009-3427 | — | — | 1.1% | Sep 25, 2009 | Cross-site scripting (XSS) vulnerability in Kayako SupportSuite 3.50.06 allows remote attackers to inject arbitrary web ... |
| CVE-2009-3426 | — | — | 1.9% | Sep 25, 2009 | PHP remote file inclusion vulnerability in includes/file_manager/special.php in MaxCMS 3.11.20b allows remote attackers ... |
| CVE-2009-3425 | — | — | 2.9% | Sep 25, 2009 | Directory traversal vulnerability in includes/inc.thcms_admin_dirtree.php in MaxCMS 3.11.20b allows remote attackers to ... |
| CVE-2009-3424 | — | — | 1.9% | Sep 25, 2009 | Multiple PHP remote file inclusion vulnerabilities in MaxCMS 3.11.20b, when register_globals is enabled, allow remote at... |
| CVE-2009-3423 | — | — | 2.6% | Sep 25, 2009 | login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and g... |
| CVE-2009-3422 | — | — | 2.6% | Sep 25, 2009 | login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and ... |
| CVE-2009-3421 | CRITICAL | 9.8 | 5.0% | Sep 25, 2009 | login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authent... |
| CVE-2009-3420 | — | — | 1.2% | Sep 25, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote at... |
| CVE-2009-3419 | — | — | 0.9% | Sep 25, 2009 | SQL injection vulnerability in index.php in the Publisher module 2.0 for Miniweb allows remote attackers to execute arbi... |
| CVE-2009-3418 | — | — | 0.8% | Sep 25, 2009 | Multiple SQL injection vulnerabilities in Plume CMS 1.2.3 allow (1) remote authenticated users to execute arbitrary SQL ... |
| CVE-2009-3417 | — | — | 1.8% | Sep 25, 2009 | SQL injection vulnerability in the IDoBlog (com_idoblog) component 1.1 build 30 for Joomla! allows remote attackers to e... |
| CVE-2009-3390 | — | — | 0.4% | Sep 24, 2009 | Multiple unspecified vulnerabilities in the (1) iscsiadm and (2) iscsitadm programs in Sun Solaris 10, and OpenSolaris s... |
| CVE-2009-2817 | — | — | 8.9% | Sep 24, 2009 | Buffer overflow in Apple iTunes before 9.0.1 allows remote attackers to execute arbitrary code or cause a denial of serv... |
| CVE-2009-2682 | — | — | 0.5% | Sep 24, 2009 | Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypa... |
| CVE-2009-3369 | — | — | 2.9% | Sep 24, 2009 | CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict u... |
| CVE-2009-3368 | — | — | 1.5% | Sep 24, 2009 | Cross-site scripting (XSS) vulnerability in the Hotel Booking Reservation System (aka HBS or com_hbssearch) component fo... |
| CVE-2009-3367 | — | — | 1.4% | Sep 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in An image gallery 1.0 allow remote attackers to inject arbitrary w... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now