2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1281 | — | — | 1.5% | Apr 9, 2009 | Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script... |
| CVE-2009-1280 | — | — | 0.6% | Apr 9, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in the com_media component for Joomla! 1.5.x through 1.5.9 al... |
| CVE-2009-1279 | — | — | 1.2% | Apr 9, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Joomla! 1.5 through 1.5.9 allow remote attackers to inject arbitr... |
| CVE-2009-1278 | — | — | 2.3% | Apr 9, 2009 | Static code injection vulnerability in forms/ajax/configure.php in Gravity Board X (GBX) 2.0 BETA allows remote attacker... |
| CVE-2009-1277 | — | — | 1.0% | Apr 9, 2009 | SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary ... |
| CVE-2009-1276 | — | — | 0.4% | Apr 9, 2009 | XScreenSaver in Sun Solaris 10 and OpenSolaris before snv_109, and Solaris 8 and 9 with GNOME 2.0 or 2.0.2, allows physi... |
| CVE-2009-1275 | — | — | 2.8% | Apr 9, 2009 | Apache Tiles 2.1 before 2.1.2, as used in Apache Struts and other products, evaluates Expression Language (EL) expressio... |
| CVE-2009-1160 | — | — | 1.1% | Apr 9, 2009 | Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)1, 7.1 before 7.1(2)74... |
| CVE-2009-1159 | — | — | 1.9% | Apr 9, 2009 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.2 before... |
| CVE-2009-1158 | — | — | 1.9% | Apr 9, 2009 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 7.0 before 7.0(8)6, 7.1 before... |
| CVE-2009-1157 | — | — | 2.7% | Apr 9, 2009 | Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 ... |
| CVE-2009-1156 | — | — | 0.7% | Apr 9, 2009 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 8.0 before 8.0(4)25 and 8.1 be... |
| CVE-2009-1155 | — | — | 1.9% | Apr 9, 2009 | Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2... |
| CVE-2009-1144 | — | — | 0.4% | Apr 9, 2009 | Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges v... |
| CVE-2009-0793 | — | — | 4.8% | Apr 9, 2009 | cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to ca... |
| CVE-2009-0197 | — | — | 4.8% | Apr 9, 2009 | Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or ca... |
| CVE-2009-1254 | — | — | 1.8% | Apr 9, 2009 | James Stone Tunapie 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a stream URL. |
| CVE-2009-1253 | — | — | 0.3% | Apr 9, 2009 | James Stone Tunapie 2.1 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary... |
| CVE-2009-1251 | — | — | 6.4% | Apr 9, 2009 | Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on U... |
| CVE-2009-1250 | — | — | 4.0% | Apr 9, 2009 | The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, ... |
| CVE-2009-0847 | — | — | 2.8% | Apr 9, 2009 | The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote ... |
| CVE-2009-0846 | — | — | 8.9% | Apr 9, 2009 | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerbero... |
| CVE-2009-0844 | — | — | 4.3% | Apr 9, 2009 | The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote a... |
| CVE-2009-1274 | — | — | 5.1% | Apr 8, 2009 | Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows... |
| CVE-2009-1273 | — | — | 1.3% | Apr 8, 2009 | pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now