2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1439 | — | — | 4.3% | Apr 27, 2009 | Buffer overflow in fs/cifs/connect.c in CIFS in the Linux kernel 2.6.29 and earlier allows remote attackers to cause a d... |
| CVE-2009-1438 | — | — | 4.7% | Apr 27, 2009 | Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer... |
| CVE-2009-1437 | — | — | 14.0% | Apr 27, 2009 | Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem... |
| CVE-2009-1436 | — | — | 0.9% | Apr 27, 2009 | The db interface in libc in FreeBSD 6.3, 6.4, 7.0, 7.1, and 7.2-PRERELEASE does not properly initialize memory for Berke... |
| CVE-2009-1435 | — | — | 0.8% | Apr 27, 2009 | NTRtScan.exe in Trend Micro OfficeScan Client 8.0 SP1 and 8.0 SP1 Patch 1 allows local users to cause a denial of servic... |
| CVE-2009-1189 | — | — | 1.3% | Apr 27, 2009 | The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incor... |
| CVE-2009-1433 | — | — | 1.1% | Apr 24, 2009 | SQL injection vulnerability in File::find (filesystem/File.php) in SilverStripe before 2.3.1 allows remote attackers to ... |
| CVE-2009-1414 | — | — | 0.4% | Apr 24, 2009 | Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for ... |
| CVE-2009-1413 | — | — | 0.8% | Apr 24, 2009 | Google Chrome 1.0.x does not cancel timeouts upon a page transition, which makes it easier for attackers to conduct Univ... |
| CVE-2009-1412 | — | — | 1.2% | Apr 24, 2009 | Argument injection vulnerability in the chromehtml: protocol handler in Google Chrome before 1.0.154.59, when invoked by... |
| CVE-2009-1192 | — | — | 0.4% | Apr 24, 2009 | The (1) agp_generic_alloc_page and (2) agp_generic_alloc_pages functions in drivers/char/agp/generic.c in the agp subsys... |
| CVE-2009-0798 | — | — | 2.3% | Apr 24, 2009 | ACPI Event Daemon (acpid) before 1.0.10 allows remote attackers to cause a denial of service (CPU consumption and connec... |
| CVE-2009-0164 | — | — | 2.9% | Apr 24, 2009 | The web interface for CUPS before 1.3.10 does not validate the HTTP Host header in a client request, which makes it easi... |
| CVE-2009-0064 | — | — | 2.2% | Apr 24, 2009 | Multiple unspecified vulnerabilities in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 allow r... |
| CVE-2009-0063 | — | — | 1.3% | Apr 24, 2009 | Cross-site scripting (XSS) vulnerability in the Control Center in Symantec Brightmail Gateway Appliance before 8.0.1 all... |
| CVE-2009-1411 | — | — | 2.3% | Apr 24, 2009 | SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attacker... |
| CVE-2009-1410 | — | — | 1.0% | Apr 24, 2009 | SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands... |
| CVE-2009-1409 | — | — | 0.9% | Apr 24, 2009 | SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and m... |
| CVE-2009-1408 | — | — | 2.0% | Apr 24, 2009 | Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HT... |
| CVE-2009-1407 | — | — | 1.9% | Apr 24, 2009 | Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a ..... |
| CVE-2009-1406 | — | — | 1.9% | Apr 24, 2009 | Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute ... |
| CVE-2009-1405 | — | — | 1.9% | Apr 24, 2009 | Directory traversal vulnerability in index.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote atta... |
| CVE-2009-1404 | — | — | 0.9% | Apr 24, 2009 | SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers ... |
| CVE-2009-1403 | — | — | 1.0% | Apr 24, 2009 | SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL comma... |
| CVE-2009-1188 | — | — | 7.2% | Apr 23, 2009 | Integer overflow in the JBIG2 decoding feature in the SplashBitmap::SplashBitmap function in SplashBitmap.cc in Xpdf 3.x... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now