2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3261 | — | — | 1.4% | Sep 18, 2009 | update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote att... |
| CVE-2009-3260 | — | — | 1.3% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2009-3259 | — | — | 1.1% | Sep 18, 2009 | Multiple SQL injection vulnerabilities in RASH Quote Management System (RQMS) 1.2.2 allow remote attackers to execute ar... |
| CVE-2009-3258 | — | — | 1.7% | Sep 18, 2009 | vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) ... |
| CVE-2009-3257 | — | — | 0.9% | Sep 18, 2009 | vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address a... |
| CVE-2009-3256 | — | — | 1.3% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in include/ajax/blogInfo.php in LiveStreet 0.2 allows remote attackers to injec... |
| CVE-2009-3255 | — | — | 1.1% | Sep 18, 2009 | SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled,... |
| CVE-2009-3254 | — | — | 4.8% | Sep 18, 2009 | Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via ... |
| CVE-2009-3253 | — | — | 4.9% | Sep 18, 2009 | Stack-based buffer overflow in TriceraSoft Swift Ultralite 1.032 allows remote attackers to cause a denial of service (c... |
| CVE-2009-3252 | — | — | 1.0% | Sep 18, 2009 | Multiple SQL injection vulnerabilities in news.php in Rock Band CMS 0.10 allow remote attackers to execute arbitrary SQL... |
| CVE-2009-3251 | — | — | 1.0% | Sep 18, 2009 | include/utils/ListViewUtils.php in vtiger CRM before 5.1.0 allows remote authenticated users to bypass intended access r... |
| CVE-2009-3250 | — | — | 10.9% | Sep 18, 2009 | The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated u... |
| CVE-2009-3249 | — | — | 9.6% | Sep 18, 2009 | Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary... |
| CVE-2009-3248 | — | — | 1.3% | Sep 18, 2009 | Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack ... |
| CVE-2009-3247 | — | — | 3.5% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject ... |
| CVE-2009-3246 | — | — | 1.0% | Sep 18, 2009 | SQL injection vulnerability in spnews.php in MyBuxScript PTC-BUX allows remote attackers to execute arbitrary SQL comman... |
| CVE-2009-3244 | — | — | 20.4% | Sep 18, 2009 | Heap-based buffer overflow in the SwDir.dll ActiveX control in Adobe Shockwave Player 11.5.1.601 and earlier allows remo... |
| CVE-2009-3243 | — | — | 7.2% | Sep 18, 2009 | Unspecified vulnerability in the TLS dissector in Wireshark 1.2.0 and 1.2.1, when running on Windows, allows remote atta... |
| CVE-2009-3242 | — | — | 7.8% | Sep 18, 2009 | Unspecified vulnerability in packet.c in the GSM A RR dissector in Wireshark 1.2.0 and 1.2.1 allows remote attackers to ... |
| CVE-2009-3241 | — | — | 9.7% | Sep 18, 2009 | Unspecified vulnerability in the OpcUa (OPC UA) dissector in Wireshark 0.99.6 through 1.0.8 and 1.2.0 through 1.2.1 allo... |
| CVE-2009-3240 | — | — | 1.6% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in the Happy Linux XF-Section module 1.12a for XOOPS allows remote attackers to... |
| CVE-2009-3239 | — | — | — | Sep 18, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2139, CVE-2009-2140. Reason: This candidate is... |
| CVE-2009-3238 | MEDIUM | 5.5 | 1.6% | Sep 18, 2009 | The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random nu... |
| CVE-2009-2937 | — | — | 4.5% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web ... |
| CVE-2009-2707 | — | — | 0.4% | Sep 18, 2009 | Unspecified vulnerability in ia32el (aka the IA 32 emulation functionality) before 7042_7022-0.4.2 in SUSE Linux Enterpr... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now