Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-3586

Published Dec 8, 2009

Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3994

Published Dec 8, 2009

Stack-based buffer overflow in the GetUID function in src-IL/src/il_dicom.c in DevIL 1.7.8 allows remote attackers to cause a denial of service (application crash) or execute arbi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2843

Published Dec 8, 2009

Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers to execute arbitrary code via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4224

Published Dec 7, 2009

Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_dir parameter…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4223

Published Dec 7, 2009

PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DOCUMENT_ROOT paramet…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4222

Published Dec 7, 2009

phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to the admin control panel via a d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4221

Published Dec 7, 2009

SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter, a different vecto…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4220

Published Dec 7, 2009

PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4219

Published Dec 7, 2009

Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote attackers to execute arbitrary c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4218

Published Dec 7, 2009

Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attackers to execute arbitrary SQL commands via the (1) admin or (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4216

Published Dec 7, 2009

Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remote attackers to include and execute arbitrary local files vi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4214

Published Dec 7, 2009

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4211

Published Dec 4, 2009

The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary directories as root for filename…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4020

Published Dec 4, 2009

Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) file…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4209

Published Dec 4, 2009

Multiple cross-site scripting (XSS) vulnerabilities in admin/index.php in moziloCMS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) fi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4208

Published Dec 4, 2009

SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to index.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4207

Published Dec 4, 2009

Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.7 and 6.x before 6.x-2.7, a module for Drupal, allows remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4206

Published Dec 4, 2009

SQL injection vulnerability in admin.link.modify.php in Million Dollar Text Links 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4205

Published Dec 4, 2009

Directory traversal vulnerability in admin.php in Flashlight Free Edition allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4204

Published Dec 4, 2009

SQL injection vulnerability in read.php in Flashlight Free Edition allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4203

Published Dec 4, 2009

Multiple SQL injection vulnerabilities in admin/aclass/admin_func.php in Arab Portal 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) X-Forwarded-For or (2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 351-375 of 5,732 CVEsPage 15 of 230