Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2008-5935

Published Jan 21, 2009

Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5934

Published Jan 21, 2009

SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via the id_sezione parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5933

Published Jan 21, 2009

Multiple cross-site scripting (XSS) vulnerabilities in index.php in CMS ISWEB 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the strcerca parameter (aka…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5932

Published Jan 21, 2009

CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5931

Published Jan 21, 2009

The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5930

Published Jan 21, 2009

SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute arbitrary SQL commands via the BlogID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5929

Published Jan 21, 2009

VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database containing the p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5928

Published Jan 21, 2009

SQL injection vulnerability in redir.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5927

Published Jan 21, 2009

Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arbitrary SQL commands via the (1) checkuser parameter (aka us…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5926

Published Jan 21, 2009

Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute arbitrary SQL commands via the (1) login parameter (aka use…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5925

Published Jan 21, 2009

ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5924

Published Jan 21, 2009

SQL injection vulnerability in diary_viewC.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5923

Published Jan 21, 2009

SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL commands the cat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5922

Published Jan 21, 2009

Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 allow remote attackers to execute arbitrary PHP code via a URL…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5921

Published Jan 21, 2009

SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0241

Published Jan 21, 2009

Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmet…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0240

Published Jan 21, 2009

listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0031

Published Jan 21, 2009

Memory leak in the keyctl_join_session_keyring function (security/keys/keyctl.c) in Linux kernel 2.6.29-rc2 and earlier allows local users to cause a denial of service (kernel mem…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5920

Published Jan 21, 2009

The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5919

Published Jan 21, 2009

Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to overwrite arbitrary files via directory trave…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5918

Published Jan 21, 2009

Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier allows remote attackers to inject arbitrary web script or H…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5916

Published Jan 21, 2009

gitweb/gitweb.perl in gitweb in Git 1.6.x before 1.6.0.6, 1.5.6.x before 1.5.6.6, 1.5.5.x before 1.5.5.6, 1.5.4.x before 1.5.4.7, and other versions after 1.4.3 allows local repos…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0182

Published Jan 20, 2009

Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in a File line in a .pls file, as demonstrated by an http URL…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 5,476-5,500 of 5,732 CVEsPage 220 of 230