Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-4535

Published Dec 31, 2009

Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4534

Published Dec 31, 2009

Open redirect vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4533

Published Dec 31, 2009

The Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, does not prevent caching of a page that contains token placeholders for a default value, which a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4532

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform crea…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4531

Published Dec 31, 2009

httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4530

Published Dec 31, 2009

Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4529

Published Dec 31, 2009

InterVations NaviCOPA Web Server 3.0.1.2 and earlier allows remote attackers to obtain the source code for a web page via a trailing encoded space character in a URI, as demonstra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4528

Published Dec 31, 2009

The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restrictions, and create, modify, or re…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4527

Published Dec 31, 2009

The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4526

Published Dec 31, 2009

The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, does not properly enforce…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4525

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, allows remote a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4524

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (ak…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4523

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web script or HTML via the searchSongKeyword parameter in a SearchSo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4522

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrary web script or HTML via the search parameter to index.php.…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4521

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allow…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4519

Published Dec 31, 2009

Multiple unspecified vulnerabilities in Ortro before 1.3.4 have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4518

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in the Insert Node module 5.x before 5.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via an inserted nod…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4517

Published Dec 31, 2009

Cross-site request forgery (CSRF) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to hijack the authentication of arbi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4516

Published Dec 31, 2009

Cross-site scripting (XSS) vulnerability in the FAQ Ask module 5.x and 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4515

Published Dec 31, 2009

The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to read node titles via unspecifi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4513

Published Dec 31, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the Workflow module 5.x before 5.x-2.4 and 6.x before 6.x-1.2, a module for Drupal, allow remote authenticated users, with "…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4512

Published Dec 31, 2009

Directory traversal vulnerability in index.php in Oscailt 3.3, when Use Friendly URL's is disabled, allows remote attackers to include and execute arbitrary local files via a .. (…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4502

Published Dec 31, 2009

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 5,732 CVEsPage 1 of 230