2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1546 | — | — | 22.5% | Aug 12, 2009 | Integer overflow in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows allows remote att... |
| CVE-2009-1545 | — | — | 28.6% | Aug 12, 2009 | Unspecified vulnerability in Avifil32.dll in the Windows Media file handling functionality in Microsoft Windows 2000 SP4... |
| CVE-2009-1544 | HIGH | 8.8 | 20.6% | Aug 12, 2009 | Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain priv... |
| CVE-2009-1536 | — | — | 51.3% | Aug 12, 2009 | ASP.NET in Microsoft .NET Framework 2.0 SP1 and SP2 and 3.5 Gold and SP1, when ASP 2.0 is used in integrated mode on IIS... |
| CVE-2009-1534 | — | — | 51.6% | Aug 12, 2009 | Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3,... |
| CVE-2009-1133 | — | — | 30.5% | Aug 12, 2009 | Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 th... |
| CVE-2009-0562 | — | — | 25.7% | Aug 12, 2009 | The Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Off... |
| CVE-2009-2730 | — | — | 2.2% | Aug 12, 2009 | libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common ... |
| CVE-2009-2726 | — | — | 6.5% | Aug 12, 2009 | The SIP channel driver in Asterisk Open Source 1.2.x before 1.2.34, 1.4.x before 1.4.26.1, 1.6.0.x before 1.6.0.12, and ... |
| CVE-2009-1427 | — | — | 0.5% | Aug 12, 2009 | Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown ve... |
| CVE-2009-2739 | — | — | 1.0% | Aug 11, 2009 | Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script... |
| CVE-2009-2738 | — | — | 1.1% | Aug 11, 2009 | Cross-site request forgery (CSRF) vulnerability in the WebGUI in FreeNAS before 0.7RC1 allows remote attackers to hijack... |
| CVE-2009-2416 | MEDIUM | 6.5 | 1.8% | Aug 11, 2009 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow ... |
| CVE-2009-2414 | — | — | 3.1% | Aug 11, 2009 | Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context... |
| CVE-2009-1885 | — | — | 5.3% | Aug 11, 2009 | Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dep... |
| CVE-2009-2737 | — | — | 2.3% | Aug 11, 2009 | The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions... |
| CVE-2009-2736 | — | — | 4.8% | Aug 11, 2009 | Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators t... |
| CVE-2009-2735 | — | — | 1.0% | Aug 11, 2009 | SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote at... |
| CVE-2009-2705 | — | — | 4.0% | Aug 11, 2009 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque... |
| CVE-2009-2704 | — | — | 3.9% | Aug 11, 2009 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque... |
| CVE-2009-0687 | — | — | 9.5% | Aug 11, 2009 | The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO... |
| CVE-2009-2727 | — | — | 26.7% | Aug 10, 2009 | Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.... |
| CVE-2009-2724 | — | — | 1.6% | Aug 10, 2009 | Race condition in the java.lang package in Sun Java SE 5.0 before Update 20 has unknown impact and attack vectors, relat... |
| CVE-2009-2723 | — | — | 2.7% | Aug 10, 2009 | Unspecified vulnerability in deserialization in the Provider class in Sun Java SE 5.0 before Update 20 has unknown impac... |
| CVE-2009-2722 | — | — | 2.8% | Aug 10, 2009 | Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and a... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now