2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1235XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space...
CVE-2009-1234Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon...
CVE-2009-1233Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an...
CVE-2009-1232Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption...
CVE-2009-1231Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack v...
CVE-2009-1230Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated admini...
CVE-2009-1229SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u...
CVE-2009-1228Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject ...
CVE-2009-1227NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI ...
CVE-2009-1226core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions...
CVE-2009-1225Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit...
CVE-2009-1224SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attac...
CVE-2009-1223aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allo...
CVE-2009-1222Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and m...
CVE-2009-1220Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA...
CVE-2009-1219Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-...
CVE-2009-1218Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an...
CVE-2009-1217Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers ...
CVE-2009-1216Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2...
CVE-2009-1215Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the...
CVE-2009-1214GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow loca...
CVE-2009-1213Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and ea...
CVE-2009-1212Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datam...
CVE-2009-1211Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endp...
CVE-2009-1210Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now