2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1638 | — | — | 2.6% | May 15, 2009 | Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b... |
| CVE-2009-1637 | — | — | 2.2% | May 15, 2009 | profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan... |
| CVE-2009-0688 | — | — | 8.2% | May 15, 2009 | Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary ... |
| CVE-2009-1632 | — | — | 2.0% | May 14, 2009 | Multiple memory leaks in Ipsec-tools before 0.7.2 allow remote attackers to cause a denial of service (memory consumptio... |
| CVE-2009-1631 | — | — | 0.4% | May 14, 2009 | The Mailer component in Evolution 2.26.1 and earlier uses world-readable permissions for the .evolution directory, and c... |
| CVE-2009-1630 | — | — | 0.5% | May 14, 2009 | The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, w... |
| CVE-2009-1629 | — | — | 2.3% | May 14, 2009 | ajaxterm.js in AjaxTerm 0.10 and earlier generates session IDs with predictable random numbers based on certain JavaScri... |
| CVE-2009-1581 | — | — | 1.7% | May 14, 2009 | functions/mime.php in SquirrelMail before 1.4.18 does not protect the application's content from Cascading Style Sheets ... |
| CVE-2009-1580 | — | — | 1.9% | May 14, 2009 | Session fixation vulnerability in SquirrelMail before 1.4.18 allows remote attackers to hijack web sessions via a crafte... |
| CVE-2009-1579 | — | — | 3.4% | May 14, 2009 | The map_yp_alias function in functions/imap_general.php in SquirrelMail before 1.4.18 and NaSMail before 1.7 allows remo... |
| CVE-2009-1578 | — | — | 2.0% | May 14, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.4.18 and NaSMail before 1.7 allow remote at... |
| CVE-2009-1466 | MEDIUM | 5.5 | 0.2% | May 14, 2009 | Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which al... |
| CVE-2009-1465 | — | — | 1.4% | May 14, 2009 | Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it eas... |
| CVE-2009-1464 | — | — | 0.7% | May 14, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allo... |
| CVE-2009-0714 | — | — | 51.6% | May 14, 2009 | Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express... |
| CVE-2009-0945 | — | — | 9.3% | May 13, 2009 | Array index error in the insertItemBefore method in WebKit, as used in Apple Safari before 3.2.3 and 4 Public Beta, iPho... |
| CVE-2009-0944 | — | — | 4.1% | May 13, 2009 | The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly ... |
| CVE-2009-0943 | — | — | 4.2% | May 13, 2009 | Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a regist... |
| CVE-2009-0942 | — | — | 4.2% | May 13, 2009 | Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) a... |
| CVE-2009-0162 | — | — | 5.4% | May 13, 2009 | Cross-site scripting (XSS) vulnerability in Safari before 3.2.3, and 4 Public Beta, on Apple Mac OS X 10.5 before 10.5.7... |
| CVE-2009-0161 | — | — | 2.3% | May 13, 2009 | The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as ... |
| CVE-2009-0160 | — | — | 4.1% | May 13, 2009 | QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or ... |
| CVE-2009-0158 | — | — | 4.7% | May 13, 2009 | Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execut... |
| CVE-2009-0157 | — | — | 2.8% | May 13, 2009 | Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitr... |
| CVE-2009-0156 | — | — | 3.1% | May 13, 2009 | Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (p... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now