2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3149 | — | — | 2.8% | Sep 10, 2009 | Directory traversal vulnerability in _css/js.php in Elgg 1.5, when magic_quotes_gpc is disabled, allows remote attackers... |
| CVE-2009-3148 | — | — | 0.9% | Sep 10, 2009 | Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL c... |
| CVE-2009-3147 | — | — | 1.1% | Sep 10, 2009 | Cross-site scripting (XSS) vulnerability in showproduct.php in ReviewPost Pro vB3 allows remote attackers to inject arbi... |
| CVE-2009-3146 | — | — | 1.0% | Sep 10, 2009 | Cross-site scripting (XSS) vulnerability in search_advance.php in ArticleFriend Script allows remote attackers to inject... |
| CVE-2009-3051 | — | — | 4.8% | Sep 10, 2009 | Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Tool... |
| CVE-2009-3124 | — | — | 2.7% | Sep 9, 2009 | Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a ... |
| CVE-2009-3123 | — | — | 2.7% | Sep 9, 2009 | Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitr... |
| CVE-2009-3122 | — | — | 1.4% | Sep 9, 2009 | The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary ... |
| CVE-2009-3121 | — | — | 1.2% | Sep 9, 2009 | Cross-site scripting (XSS) vulnerability in the Ajax Table module 5.x for Drupal allows remote attackers to inject arbit... |
| CVE-2009-3120 | — | — | 0.8% | Sep 9, 2009 | Cross-site scripting (XSS) vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to inject arb... |
| CVE-2009-3119 | — | — | 1.0% | Sep 9, 2009 | SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attacke... |
| CVE-2009-3118 | — | — | 1.2% | Sep 9, 2009 | SQL injection vulnerability in mod/poll/comment.php in the vote module in Danneo CMS 0.5.2 and earlier allows remote att... |
| CVE-2009-3117 | — | — | 1.0% | Sep 9, 2009 | SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary... |
| CVE-2009-3116 | — | — | 1.0% | Sep 9, 2009 | SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands... |
| CVE-2009-3115 | — | — | 10.7% | Sep 9, 2009 | SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a c... |
| CVE-2009-3114 | — | — | 2.2% | Sep 9, 2009 | The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows ... |
| CVE-2009-2205 | — | — | 2.3% | Sep 9, 2009 | Stack-based buffer overflow in the Java Web Start command launcher in Java for Mac OS X 10.5 before Update 5 allows atta... |
| CVE-2009-3113 | — | — | 0.9% | Sep 9, 2009 | Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allow... |
| CVE-2009-3112 | — | — | 2.0% | Sep 9, 2009 | Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.0 allows remote attac... |
| CVE-2009-3111 | — | — | 11.2% | Sep 9, 2009 | The rad_decode function in FreeRADIUS before 1.1.8 allows remote attackers to cause a denial of service (radiusd crash) ... |
| CVE-2009-2266 | — | — | 1.1% | Sep 9, 2009 | OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details... |
| CVE-2009-3110 | — | — | 1.5% | Sep 8, 2009 | Race condition in the file transfer functionality in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430... |
| CVE-2009-3109 | — | — | 3.8% | Sep 8, 2009 | Unspecified vulnerability in the AClient agent in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430, w... |
| CVE-2009-3108 | — | — | 0.4% | Sep 8, 2009 | The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with... |
| CVE-2009-3107 | — | — | 1.0% | Sep 8, 2009 | Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 does not properly restrict access to the listening p... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now