2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-1536ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS...
CVE-2009-1534Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3,...
CVE-2009-1133Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 th...
CVE-2009-0562The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Off...
CVE-2009-2730libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common ...
CVE-2009-2726The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and ...
CVE-2009-1427Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown ve...
CVE-2009-2739Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script...
CVE-2009-2738Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack...
CVE-2009-2414Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context...
CVE-2009-1885Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dep...
CVE-2009-2737The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions...
CVE-2009-2736Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators t...
CVE-2009-2735SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote at...
CVE-2009-2705CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque...
CVE-2009-2704CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque...
CVE-2009-0687The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO...
CVE-2009-2727Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5....
CVE-2009-2724Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, relat...
CVE-2009-2723Unspecified vulnerability in deserialization in the Provider class in Sun Java SE 5.0 before Update 20 has unknown impac...
CVE-2009-2722Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and a...
CVE-2009-2721Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and a...
CVE-2009-2720Unspecified vulnerability in the javax.swing.plaf.synth.SynthContext.isSubregion method in the Swing implementation in S...
CVE-2009-2719The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial...
CVE-2009-2718The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on X11 does not impose the intended c...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now