2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1500 | — | — | 0.9% | May 1, 2009 | SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL command... |
| CVE-2009-1365 | — | — | 3.3% | May 1, 2009 | Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.4 and 3.5.x before 3.5.2, as used in Flash Media ... |
| CVE-2009-1364 | — | — | 3.5% | May 1, 2009 | Use-after-free vulnerability in the embedded GD library in libwmf 0.2.8.4 allows context-dependent attackers to cause a ... |
| CVE-2009-1499 | — | — | 1.8% | May 1, 2009 | SQL injection vulnerability in the MailTo (aka com_mailto) component in Joomla! allows remote attackers to execute arbit... |
| CVE-2009-1498 | — | — | 1.9% | May 1, 2009 | Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp... |
| CVE-2009-1497 | — | — | 6.8% | May 1, 2009 | Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attacke... |
| CVE-2009-1496 | — | — | 7.2% | May 1, 2009 | Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote at... |
| CVE-2009-1495 | — | — | 2.3% | May 1, 2009 | Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem... |
| CVE-2009-1313 | — | — | 8.4% | Apr 30, 2009 | The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote at... |
| CVE-2009-1494 | — | — | 1.5% | Apr 30, 2009 | The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc comman... |
| CVE-2009-1493 | — | — | 21.8% | Apr 30, 2009 | The customDictionaryOpen spell method in the JavaScript API in Adobe Reader 9.1, 8.1.4, 7.1.1, and earlier on Linux and ... |
| CVE-2009-1492 | — | — | 25.5% | Apr 30, 2009 | The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote ... |
| CVE-2009-1434 | — | — | 0.7% | Apr 30, 2009 | Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentica... |
| CVE-2009-1432 | — | — | 4.2% | Apr 30, 2009 | Symantec Reporting Server, as used in Symantec AntiVirus (SAV) Corporate Edition 10.1 before 10.1 MR8 and 10.2 before 10... |
| CVE-2009-1417 | — | — | 1.4% | Apr 30, 2009 | gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allow... |
| CVE-2009-1416 | — | — | 3.9% | Apr 30, 2009 | lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the i... |
| CVE-2009-1415 | — | — | 7.9% | Apr 30, 2009 | lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows rem... |
| CVE-2009-1348 | — | — | 2.8% | Apr 30, 2009 | The AV engine before DAT 5600 in McAfee VirusScan, Total Protection, Internet Security, SecurityShield for Microsoft ISA... |
| CVE-2009-1341 | — | — | 2.0% | Apr 30, 2009 | Memory leak in the dequote_bytea function in quote.c in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module before 2.0.0 f... |
| CVE-2009-1339 | — | — | 0.7% | Apr 30, 2009 | Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the au... |
| CVE-2009-1295 | — | — | 0.4% | Apr 30, 2009 | Apport before 0.108.4 on Ubuntu 8.04 LTS, before 0.119.2 on Ubuntu 8.10, and before 1.0-0ubuntu5.2 on Ubuntu 9.04 does n... |
| CVE-2009-1291 | — | — | 6.4% | Apr 30, 2009 | Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, ... |
| CVE-2009-1255 | — | — | 2.3% | Apr 30, 2009 | The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/sel... |
| CVE-2009-0663 | — | — | 4.3% | Apr 30, 2009 | Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-depend... |
| CVE-2009-1489 | — | — | 2.5% | Apr 29, 2009 | includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by set... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now