Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-4200

Published Dec 4, 2009

SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a View_semina…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4198

Published Dec 4, 2009

SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL commands via the orderid parameter in a status action.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4148

Published Dec 4, 2009

DAZ Studio 2.3.3.161, 2.3.3.163, and 3.0.1.135 allows remote attackers to execute arbitrary JavaScript code via a (1) .ds, (2) .dsa, (3) .dse, or (4) .dsb file, as demonstrated by…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3304

Published Dec 4, 2009

GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4196

Published Dec 4, 2009

Multiple cross-site scripting (XSS) vulnerabilities in multiple scripts in Forms/ in Huawei MT882 V100R002B020 ARG-T running firmware 3.7.9.98 allow remote attackers to inject arb…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4195

Published Dec 4, 2009

Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4194

Published Dec 3, 2009

Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions allows remote authenticated users to delete arbitrary files vi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4193

Published Dec 3, 2009

Merkaartor 0.14 allows local users to append data to arbitrary files via a symlink attack on the /tmp/merkaartor.log temporary file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4192

Published Dec 3, 2009

Directory traversal vulnerability in dialog/file_manager.php in Interspire Knowledge Manager 5 allows remote attackers to read arbitrary files via a .. (dot dot) in the p paramete…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1566

Published Dec 3, 2009

Integer overflow in Roxio Easy Media Creator 9.0.136, and Roxio Creator 2010 before SP1, might allow remote attackers to execute arbitrary code via an image with crafted dimension…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4191

Published Dec 3, 2009

Unspecified vulnerability in the kernel in Sun Solaris 10 and OpenSolaris 2009.06 on the x86-64 platform allows local users to gain privileges via unknown vectors, as demonstrated…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4190

Published Dec 3, 2009

Unspecified vulnerability in the kernel in Sun OpenSolaris 2009.06 allows remote attackers to cause a denial of service (panic) via unknown vectors, as demonstrated by the vd_sola…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4189

Published Dec 3, 2009

HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager rol…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4188

Published Dec 3, 2009

HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manage…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4187

Published Dec 3, 2009

Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4186

Published Dec 3, 2009

Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cas…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1567

Published Dec 3, 2009

Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a lon…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0895

Published Dec 3, 2009

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containin…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4175

Published Dec 2, 2009

CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an invalid date value in the from_date_day parameter to search.php,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4174

Published Dec 2, 2009

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access t…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 5,732 CVEsPage 16 of 230