2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1235 | — | — | 1.0% | Apr 2, 2009 | XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space... |
| CVE-2009-1234 | — | — | 7.2% | Apr 2, 2009 | Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon... |
| CVE-2009-1233 | — | — | 4.4% | Apr 2, 2009 | Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an... |
| CVE-2009-1232 | — | — | 5.5% | Apr 2, 2009 | Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption... |
| CVE-2009-1231 | — | — | 1.5% | Apr 2, 2009 | Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack v... |
| CVE-2009-1230 | — | — | 1.8% | Apr 2, 2009 | Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated admini... |
| CVE-2009-1229 | — | — | 1.0% | Apr 2, 2009 | SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u... |
| CVE-2009-1228 | — | — | 1.5% | Apr 2, 2009 | Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject ... |
| CVE-2009-1227 | — | — | 7.2% | Apr 2, 2009 | NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI ... |
| CVE-2009-1226 | — | — | 2.3% | Apr 2, 2009 | core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions... |
| CVE-2009-1225 | — | — | 1.2% | Apr 2, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit... |
| CVE-2009-1224 | — | — | 0.9% | Apr 2, 2009 | SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attac... |
| CVE-2009-1223 | — | — | 1.1% | Apr 2, 2009 | aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allo... |
| CVE-2009-1222 | — | — | 2.0% | Apr 2, 2009 | Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and m... |
| CVE-2009-1220 | — | — | 9.0% | Apr 1, 2009 | Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA... |
| CVE-2009-1219 | — | — | 8.7% | Apr 1, 2009 | Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-... |
| CVE-2009-1218 | — | — | 4.4% | Apr 1, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an... |
| CVE-2009-1217 | — | — | 16.3% | Apr 1, 2009 | Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers ... |
| CVE-2009-1216 | — | — | 24.5% | Apr 1, 2009 | Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2... |
| CVE-2009-1215 | — | — | 0.2% | Apr 1, 2009 | Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the... |
| CVE-2009-1214 | — | — | 0.3% | Apr 1, 2009 | GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow loca... |
| CVE-2009-1213 | — | — | 0.7% | Apr 1, 2009 | Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and ea... |
| CVE-2009-1212 | — | — | 5.7% | Apr 1, 2009 | Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datam... |
| CVE-2009-1211 | — | — | 1.4% | Apr 1, 2009 | Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endp... |
| CVE-2009-1210 | — | — | 15.2% | Apr 1, 2009 | Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now