2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3317 | — | — | 2.5% | Sep 23, 2009 | PHP remote file inclusion vulnerability in pages/pageHeader.php in OpenSiteAdmin 0.9.7 BETA allows remote attackers to e... |
| CVE-2009-3316 | — | — | 1.0% | Sep 23, 2009 | SQL injection vulnerability in the JReservation (com_jreservation) component 1.0 and 1.5 for Joomla! allows remote attac... |
| CVE-2009-3315 | — | — | 1.0% | Sep 23, 2009 | SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attacke... |
| CVE-2009-3314 | — | — | 1.0% | Sep 23, 2009 | SQL injection vulnerability in ladders.php in Elite Gaming Ladders 3.2 allows remote attackers to execute arbitrary SQL ... |
| CVE-2009-3313 | — | — | 1.1% | Sep 23, 2009 | Multiple SQL injection vulnerabilities in FMyClone 2.3 allow remote attackers to execute arbitrary SQL commands via the ... |
| CVE-2009-3312 | — | — | 4.2% | Sep 23, 2009 | PHP remote file inclusion vulnerability in php/init.poll.php in phpPollScript 1.3 and earlier, when register_globals is ... |
| CVE-2009-3311 | — | — | 1.5% | Sep 23, 2009 | Cross-site scripting (XSS) vulnerability in index.php in RSSMediaScript allows remote attackers to inject arbitrary web ... |
| CVE-2009-3310 | — | — | 1.0% | Sep 23, 2009 | SQL injection vulnerability in index.php in Zainu 1.0 allows remote attackers to execute arbitrary SQL commands via the ... |
| CVE-2009-3309 | — | — | 1.0% | Sep 23, 2009 | SQL injection vulnerability in index.cfm in CF ShopKart 5.4 beta allows remote attackers to execute arbitrary SQL comman... |
| CVE-2009-3308 | — | — | 1.0% | Sep 23, 2009 | SQL injection vulnerability in show-cat.php in FanUpdate 2.2.1 allows remote attackers to execute arbitrary SQL commands... |
| CVE-2009-3307 | — | — | 4.9% | Sep 23, 2009 | Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code v... |
| CVE-2009-3306 | — | — | 6.1% | Sep 23, 2009 | PHP remote file inclusion vulnerability in include/header.php in ClearSite 4.50 allows remote attackers to execute arbit... |
| CVE-2009-3294 | — | — | 2.7% | Sep 22, 2009 | The popen API function in TSRM/tsrm_win32.c in PHP before 5.2.11 and 5.3.x before 5.3.1, when running on certain Windows... |
| CVE-2009-3293 | — | — | 2.7% | Sep 22, 2009 | Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vecto... |
| CVE-2009-3292 | — | — | 2.8% | Sep 22, 2009 | Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to... |
| CVE-2009-3291 | — | — | 2.9% | Sep 22, 2009 | The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation... |
| CVE-2009-3290 | — | — | 0.4% | Sep 22, 2009 | The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions befor... |
| CVE-2009-3289 | HIGH | 7.8 | 0.4% | Sep 22, 2009 | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), ... |
| CVE-2009-3288 | — | — | 0.4% | Sep 22, 2009 | The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect vari... |
| CVE-2009-3287 | — | — | 1.4% | Sep 22, 2009 | lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address ... |
| CVE-2009-3286 | — | — | 0.5% | Sep 22, 2009 | NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create... |
| CVE-2009-3284 | — | — | 1.5% | Sep 22, 2009 | Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder,... |
| CVE-2009-3283 | — | — | 1.0% | Sep 22, 2009 | Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_B... |
| CVE-2009-3280 | — | — | 3.2% | Sep 21, 2009 | Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel be... |
| CVE-2009-3279 | — | — | 0.4% | Sep 21, 2009 | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now