2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3212 | — | — | 1.0% | Sep 16, 2009 | SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote atta... |
| CVE-2009-3211 | — | — | 1.9% | Sep 16, 2009 | Directory traversal vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remot... |
| CVE-2009-3210 | — | — | 1.0% | Sep 16, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the Print (aka Printer, e-mail and PDF versions) module 5.x befor... |
| CVE-2009-3209 | — | — | 1.0% | Sep 16, 2009 | SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL co... |
| CVE-2009-3208 | — | — | 0.9% | Sep 16, 2009 | Multiple SQL injection vulnerabilities in phpfreeBB 1.0 allow remote attackers to execute arbitrary SQL commands via the... |
| CVE-2009-3207 | — | — | 1.5% | Sep 16, 2009 | The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file syste... |
| CVE-2009-3206 | — | — | 0.8% | Sep 16, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-b... |
| CVE-2009-3205 | — | — | 1.0% | Sep 16, 2009 | SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the... |
| CVE-2009-3204 | — | — | 1.1% | Sep 16, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Stiva Forum 1.0 allow remote attackers to inject arbitrary web sc... |
| CVE-2009-3203 | — | — | 1.0% | Sep 16, 2009 | SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL com... |
| CVE-2009-3202 | — | — | 1.5% | Sep 16, 2009 | Cross-site scripting (XSS) vulnerability in search.php in ULoKI PHP Forum 2.1 allows remote attackers to inject arbitrar... |
| CVE-2009-3201 | — | — | 1.9% | Sep 15, 2009 | Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (appli... |
| CVE-2009-3166 | — | — | 1.2% | Sep 15, 2009 | token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs im... |
| CVE-2009-3165 | — | — | 1.4% | Sep 15, 2009 | SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4,... |
| CVE-2009-3125 | — | — | 1.4% | Sep 15, 2009 | SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remot... |
| CVE-2009-2945 | — | — | 0.9% | Sep 15, 2009 | weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwo... |
| CVE-2009-2903 | — | — | 3.8% | Sep 15, 2009 | Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the app... |
| CVE-2009-2629 | — | — | 66.9% | Sep 15, 2009 | Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, a... |
| CVE-2009-2201 | — | — | 0.3% | Sep 15, 2009 | The screensharing feature in the Admin application in Apple Xsan before 2.2 places a cleartext username and password in ... |
| CVE-2009-3199 | — | — | 2.2% | Sep 15, 2009 | Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allow... |
| CVE-2009-3198 | — | — | 1.1% | Sep 15, 2009 | Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows re... |
| CVE-2009-3197 | — | — | 1.1% | Sep 15, 2009 | Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech PHP Calendars Script allows remote attackers to injec... |
| CVE-2009-3196 | — | — | 1.5% | Sep 15, 2009 | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arb... |
| CVE-2009-3195 | — | — | 1.5% | Sep 15, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to... |
| CVE-2009-3194 | — | — | 1.5% | Sep 15, 2009 | Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech SearchFeed Script allows remote attackers to inject ar... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now