Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-4109

Published Nov 29, 2009

The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4108

Published Nov 29, 2009

XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or creating a large number of files or directories, then perf…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4107

Published Nov 29, 2009

Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4106

Published Nov 29, 2009

Unrestricted file upload vulnerability in admintools/editpage-2.php in Agoko CMS 0.4 and earlier allows remote attackers to inject and execute arbitrary PHP code via the filename…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4105

Published Nov 29, 2009

TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (append) command immediately followed by a DELE (delete) command…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4104

Published Nov 29, 2009

SQL injection vulnerability in Lyften Designs LyftenBloggie (com_lyftenbloggie) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the autho…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4103

Published Nov 29, 2009

Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote FTP servers to cause a denial of service and possibly execute arbitrary code via unspecified FTP ser…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4102

Published Nov 29, 2009

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-doma…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4101

Published Nov 29, 2009

infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4100

Published Nov 29, 2009

Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4099

Published Nov 29, 2009

SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlier versions for Joomla! allows remote attackers to execute a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4098

Published Nov 29, 2009

Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute ar…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4097

Published Nov 29, 2009

Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote attackers to execute arbitrary code via a long URL in an M3U fi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4096

Published Nov 29, 2009

RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct req…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4111

Published Nov 29, 2009

Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4081

Published Nov 29, 2009

Untrusted search path vulnerability in dstat before r3199 allows local users to gain privileges via a Trojan horse Python module in the current working directory, a different vuln…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4080

Published Nov 29, 2009

Multiple unspecified vulnerabilities in ldap_cachemgr (aka the LDAP client configuration cache daemon) in Sun Solaris 9 and 10, and OpenSolaris before snv_78, allow local users to…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-3894

Published Nov 29, 2009

Multiple untrusted search path vulnerabilities in dstat before 0.7.0 allow local users to gain privileges via a Trojan horse Python module in (1) the current working directory or…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3736

Published Nov 29, 2009

ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4025

Published Nov 29, 2009

Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary she…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4024

Published Nov 29, 2009

Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4023

Published Nov 29, 2009

Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4095

Published Nov 29, 2009

myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4094

Published Nov 29, 2009

PHP remote file inclusion vulnerability in class/php/d4m_ajax_pagenav.php in the D4J eZine (com_ezine) component 2.1 for Joomla! allows remote attackers to execute arbitrary PHP c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4093

Published Nov 29, 2009

Multiple cross-site scripting (XSS) vulnerabilities in comments.php in Simplog 0.9.3.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 5,732 CVEsPage 19 of 230