2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-5039 | — | — | 1.3% | Jan 7, 2011 | Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows r... |
| CVE-2009-5038 | — | — | 3.2% | Jan 7, 2011 | Cisco IOS before 15.0(1)XA does not properly handle IRC traffic during a specific time period after an initial reload, w... |
| CVE-2009-5037 | — | — | 2.2% | Jan 7, 2011 | Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) allow remote attackers to cause... |
| CVE-2009-2189 | — | — | 0.8% | Dec 22, 2010 | The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with... |
| CVE-2009-5036 | — | — | 1.1% | Dec 16, 2010 | traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of servi... |
| CVE-2009-5035 | — | — | 1.0% | Dec 16, 2010 | The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages b... |
| CVE-2009-5034 | — | — | 1.1% | Dec 16, 2010 | IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumpti... |
| CVE-2009-5033 | — | — | 1.0% | Dec 16, 2010 | IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, w... |
| CVE-2009-5032 | — | — | 1.1% | Dec 16, 2010 | The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is u... |
| CVE-2009-5021 | — | — | 1.0% | Dec 9, 2010 | Cobbler before 1.6.1 does not properly determine whether an installation has the default password, which makes it easier... |
| CVE-2009-5020 | — | — | 3.5% | Dec 2, 2010 | Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary ... |
| CVE-2009-5019 | — | — | 2.8% | Dec 1, 2010 | Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote at... |
| CVE-2009-5017 | — | — | 1.9% | Nov 12, 2010 | Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote att... |
| CVE-2009-5016 | — | — | 2.7% | Nov 12, 2010 | Integer overflow in the xml_utf8_decode function in ext/xml/xml.c in PHP before 5.2.11 makes it easier for remote attack... |
| CVE-2009-5015 | — | — | 1.1% | Nov 6, 2010 | The URL dispatch mechanism in TurboGears2 (aka tg2) before 2.0.2 exposes controller methods even when an @expose decorat... |
| CVE-2009-5014 | — | — | 1.4% | Nov 6, 2010 | The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier... |
| CVE-2009-5013 | — | — | 1.2% | Oct 19, 2010 | Memory leak in the on_dtp_close function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to ... |
| CVE-2009-5012 | — | — | 1.0% | Oct 19, 2010 | ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authe... |
| CVE-2009-5011 | — | — | 0.9% | Oct 19, 2010 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a deni... |
| CVE-2009-5010 | — | — | 1.4% | Oct 19, 2010 | Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a deni... |
| CVE-2009-5006 | — | — | 4.1% | Oct 18, 2010 | The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker componen... |
| CVE-2009-5005 | — | — | 5.9% | Oct 18, 2010 | The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3... |
| CVE-2009-5009 | — | — | 1.0% | Oct 14, 2010 | Double free vulnerability in OpenConnect before 1.40 might allow remote AnyConnect SSL VPN servers to cause a denial of ... |
| CVE-2009-5008 | — | — | 0.4% | Oct 14, 2010 | Cisco Secure Desktop (CSD), when used in conjunction with an AnyConnect SSL VPN server, does not properly perform verifi... |
| CVE-2009-5007 | — | — | 0.3% | Oct 14, 2010 | The Cisco trial client on Linux for Cisco AnyConnect SSL VPN allows local users to overwrite arbitrary files via a symli... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now