2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1316——Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the...
CVE-2009-1315——Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web scri...
CVE-2009-1314——body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s...
CVE-2009-0946——Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors re...
CVE-2009-1301——Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers...
CVE-2009-1300——apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading secu...
CVE-2009-1294——Multiple cross-site scripting (XSS) vulnerabilities in web/guest/home in the Liferay 4.3.0 portal in Novell Teaming 1.0 ...
CVE-2009-1293——The web login functionality (c/portal/login) in Novell Teaming 1.0 through SP3 (1.0.3) generates different error message...
CVE-2009-1285——Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x be...
CVE-2009-0579——Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows loc...
CVE-2009-0196——Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (...
CVE-2009-1119——Multiple heap-based buffer overflows in EMC RepliStor 6.2 before SP5 and 6.3 before SP2 allow remote attackers to execut...
CVE-2009-1017——Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and ...
CVE-2009-1016——Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 S...
CVE-2009-1014——Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwa...
CVE-2009-1013——Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwa...
CVE-2009-1012——Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through ...
CVE-2009-1011——Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows loc...
CVE-2009-1010——Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows loc...
CVE-2009-1009——Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users t...
CVE-2009-1008——Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows loc...
CVE-2009-1006——Unspecified vulnerability in the JRockit component in BEA Product Suite R27.6.2 and earlier, with SDK/JRE 1.4.2, JRE/JDK...
CVE-2009-1005——Unspecified vulnerability in the Oracle Data Service Integrator (AquaLogic Data Services Platform) component in BEA Prod...
CVE-2009-1004——Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect c...
CVE-2009-1003——Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, and 9.0 al...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now