Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-3800

Published Dec 10, 2009

Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibl…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3799

Published Dec 10, 2009

Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3798

Published Dec 10, 2009

Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3797

Published Dec 10, 2009

Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3796

Published Dec 10, 2009

Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3794

Published Dec 10, 2009

Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4266

Published Dec 10, 2009

Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4265

Published Dec 10, 2009

Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary code via a long Computer value in an .ipj…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4264

Published Dec 10, 2009

PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4263

Published Dec 10, 2009

SQL injection vulnerability in main_forum.php in PTCPay GeN3 forum 1.3 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4262

Published Dec 10, 2009

Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to obtain access to the admin control panel via a direct request to admin.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4256

Published Dec 10, 2009

Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) cont_id and (2) courc_id parame…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4255

Published Dec 10, 2009

Cross-site scripting (XSS) vulnerability in the You!Hostit! template 1.0.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the created_by_alias para…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4254

Published Dec 10, 2009

PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (2) foot.inc.php, (3) get_csscolors.inc.php, (4) head.inc.ph…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4253

Published Dec 10, 2009

Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the edit parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4252

Published Dec 10, 2009

Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4251

Published Dec 10, 2009

Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: t…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4250

Published Dec 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote attackers to inject arbitrary web script or HTML via (1) th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4249

Published Dec 10, 2009

Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magic_quotes_gpc is disabled, allow remote attackers to inject…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4240

Published Dec 9, 2009

Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Server 8.1 before FP1 have unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4239

Published Dec 9, 2009

Cross-site scripting (XSS) vulnerability in the Web console in IBM InfoSphere Information Server 8.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4149

Published Dec 9, 2009

Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 5,732 CVEsPage 13 of 230