2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1157 | — | — | 2.7% | Apr 9, 2009 | Memory leak on Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.0 before 7.0(8)6, 7.1 ... |
| CVE-2009-1156 | — | — | 0.7% | Apr 9, 2009 | Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5500 Series devices 8.0 before 8.0(4)25 and 8.1 be... |
| CVE-2009-1155 | — | — | 1.9% | Apr 9, 2009 | Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2... |
| CVE-2009-1144 | — | — | 0.4% | Apr 9, 2009 | Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges v... |
| CVE-2009-0793 | — | — | 4.8% | Apr 9, 2009 | cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to ca... |
| CVE-2009-0197 | — | — | 4.8% | Apr 9, 2009 | Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or ca... |
| CVE-2009-1254 | — | — | 1.8% | Apr 9, 2009 | James Stone Tunapie 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a stream URL. |
| CVE-2009-1253 | — | — | 0.3% | Apr 9, 2009 | James Stone Tunapie 2.1 allows local users to overwrite arbitrary files via a symlink attack on an unspecified temporary... |
| CVE-2009-1251 | — | — | 6.4% | Apr 9, 2009 | Heap-based buffer overflow in the cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58 on U... |
| CVE-2009-1250 | — | — | 4.0% | Apr 9, 2009 | The cache manager in the client in OpenAFS 1.0 through 1.4.8 and 1.5.0 through 1.5.58, and IBM AFS 3.6 before Patch 19, ... |
| CVE-2009-0847 | — | — | 2.8% | Apr 9, 2009 | The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote ... |
| CVE-2009-0846 | — | — | 8.9% | Apr 9, 2009 | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerbero... |
| CVE-2009-0844 | — | — | 4.3% | Apr 9, 2009 | The get_input_token function in the SPNEGO implementation in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote a... |
| CVE-2009-1274 | — | — | 5.1% | Apr 8, 2009 | Integer overflow in the qt_error parse_trak_atom function in demuxers/demux_qt.c in xine-lib 1.1.16.2 and earlier allows... |
| CVE-2009-1273 | — | — | 1.3% | Apr 8, 2009 | pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages ... |
| CVE-2009-1272 | — | — | 2.0% | Apr 8, 2009 | The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cau... |
| CVE-2009-1271 | — | — | 2.4% | Apr 8, 2009 | The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of... |
| CVE-2009-1270 | — | — | 5.1% | Apr 8, 2009 | libclamav/untar.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (infinite loop) via a craft... |
| CVE-2009-1265 | — | — | 3.2% | Apr 8, 2009 | Integer overflow in rose_sendmsg (sys/net/af_rose.c) in the Linux kernel 2.6.24.4, and other versions before 2.6.30-rc1,... |
| CVE-2009-0795 | — | — | — | Apr 8, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-0796, CVE-2009-1265. Reason: this candidate wa... |
| CVE-2009-1264 | — | — | 1.2% | Apr 7, 2009 | Frontend User Registration (sr_feuser_register) extension 2.5.20 and earlier for TYPO3 does not properly verify access r... |
| CVE-2009-1263 | — | — | 1.0% | Apr 7, 2009 | SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allow... |
| CVE-2009-1262 | — | — | 0.5% | Apr 7, 2009 | Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitra... |
| CVE-2009-1261 | — | — | 1.2% | Apr 7, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote attackers ... |
| CVE-2009-1260 | — | — | 42.7% | Apr 7, 2009 | Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now