2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1936 | CRITICAL | 9.8 | 42.2% | Jun 5, 2009 | _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called direc... |
| CVE-2009-1934 | — | — | 2.2% | Jun 5, 2009 | Cross-site scripting (XSS) vulnerability in the Reverse Proxy Plug-in in Sun Java System Web Server 6.1 before SP11 allo... |
| CVE-2009-1933 | — | — | 0.3% | Jun 5, 2009 | Kerberos in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_117, does not properly manage credential caches, which ... |
| CVE-2009-1717 | — | — | 3.0% | Jun 5, 2009 | Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or c... |
| CVE-2009-1162 | — | — | 1.2% | Jun 5, 2009 | Cross-site scripting (XSS) vulnerability in the Spam Quarantine login page in Cisco IronPort AsyncOS before 6.5.2 on Ser... |
| CVE-2009-0783 | MEDIUM | 4.2 | 0.8% | Jun 5, 2009 | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace a... |
| CVE-2009-0580 | — | — | 94.4% | Jun 5, 2009 | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al... |
| CVE-2009-0033 | — | — | 10.1% | Jun 5, 2009 | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_... |
| CVE-2009-1932 | — | — | 5.5% | Jun 4, 2009 | Multiple integer overflows in the (1) user_info_callback, (2) user_endrow_callback, and (3) gst_pngdec_task functions (e... |
| CVE-2009-1916 | — | — | 10.3% | Jun 4, 2009 | dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ... |
| CVE-2009-1915 | — | — | 5.0% | Jun 4, 2009 | Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial... |
| CVE-2009-1914 | — | — | 0.7% | Jun 4, 2009 | The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc6... |
| CVE-2009-1913 | — | — | 1.0% | Jun 4, 2009 | SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authenticatio... |
| CVE-2009-1912 | — | — | 3.2% | Jun 4, 2009 | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to inc... |
| CVE-2009-1911 | — | — | 2.5% | Jun 4, 2009 | Directory traversal vulnerability in .include/init.php (aka admin/_include/init.php) in QuiXplorer 2.3.2 and earlier, as... |
| CVE-2009-1910 | — | — | 1.2% | Jun 4, 2009 | SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands... |
| CVE-2009-1909 | — | — | 1.3% | Jun 4, 2009 | SQL injection vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote attackers to... |
| CVE-2009-1908 | — | — | 1.2% | Jun 4, 2009 | Cross-site scripting (XSS) vulnerability in Skip 1.0.2 and earlier, and 1.1RC2 and earlier 1.1RC versions, allows remote... |
| CVE-2009-1907 | — | — | 1.8% | Jun 4, 2009 | Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to... |
| CVE-2009-1387 | — | — | 10.3% | Jun 4, 2009 | The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to... |
| CVE-2009-1386 | — | — | 80.1% | Jun 4, 2009 | ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and... |
| CVE-2009-1385 | — | — | 33.5% | Jun 4, 2009 | Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux ... |
| CVE-2009-1906 | — | — | 2.0% | Jun 3, 2009 | The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of se... |
| CVE-2009-1905 | — | — | 1.8% | Jun 3, 2009 | The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP securit... |
| CVE-2009-1903 | — | — | 3.0% | Jun 3, 2009 | The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now