2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1638Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b...
CVE-2009-1637profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan...
CVE-2009-0688Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary ...
CVE-2009-1632Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumptio...
CVE-2009-1631The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and c...
CVE-2009-1630The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, w...
CVE-2009-1629ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScri...
CVE-2009-1581functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets ...
CVE-2009-1580Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafte...
CVE-2009-1579The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remo...
CVE-2009-1578Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote at...
CVE-2009-1466MEDIUM5.5Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which al...
CVE-2009-1465Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it eas...
CVE-2009-1464Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allo...
CVE-2009-0714Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express...
CVE-2009-0945Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPho...
CVE-2009-0944The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly ...
CVE-2009-0943Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a regist...
CVE-2009-0942Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) a...
CVE-2009-0162Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7...
CVE-2009-0161The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as ...
CVE-2009-0160QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or ...
CVE-2009-0158Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execut...
CVE-2009-0157Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitr...
CVE-2009-0156Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (p...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now