2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-0518——VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update...
CVE-2009-1242——The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before...
CVE-2009-1241——Unspecified vulnerability in ClamAV before 0.95 allows remote attackers to bypass detection of malware via a modified RA...
CVE-2009-1240——Unspecified vulnerability in the IBM Proventia engine 4.9.0.0.44 20081231, as used in IBM Proventia Network Mail Securit...
CVE-2009-1239——IBM DB2 9.1 before FP7 returns incorrect query results in certain situations related to the order of application of an I...
CVE-2009-1238——Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows ...
CVE-2009-1237——Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den...
CVE-2009-1236——Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e...
CVE-2009-1235——XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space...
CVE-2009-1234——Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon...
CVE-2009-1233——Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an...
CVE-2009-1232——Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption...
CVE-2009-1231——Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack v...
CVE-2009-1230——Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated admini...
CVE-2009-1229——SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u...
CVE-2009-1228——Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject ...
CVE-2009-1227——NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI ...
CVE-2009-1226——core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions...
CVE-2009-1225——Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit...
CVE-2009-1224——SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attac...
CVE-2009-1223——aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allo...
CVE-2009-1222——Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and m...
CVE-2009-1220——Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA...
CVE-2009-1219——Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-...
CVE-2009-1218——Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now