2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1235——XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space...
CVE-2009-1234——Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a lon...
CVE-2009-1233——Apple Safari 3.2.2 and 4 Beta on Windows allows remote attackers to cause a denial of service (application crash) via an...
CVE-2009-1232——Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption...
CVE-2009-1231——Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack v...
CVE-2009-1230——Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated admini...
CVE-2009-1229——SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u...
CVE-2009-1228——Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject ...
CVE-2009-1227——NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI ...
CVE-2009-1226——core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions...
CVE-2009-1225——Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit...
CVE-2009-1224——SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attac...
CVE-2009-1223——aspWebCalendar Free Edition stores sensitive information under the web root with insufficient access control, which allo...
CVE-2009-1222——Directory traversal vulnerability in index.php in webEdition 6.0.0.4 and earlier, when register_globals is enabled and m...
CVE-2009-1220——Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA...
CVE-2009-1219——Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-...
CVE-2009-1218——Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an...
CVE-2009-1217——Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers ...
CVE-2009-1216——Multiple unspecified vulnerabilities in (1) unlzh.c and (2) unpack.c in the gzip libraries in Microsoft Windows Server 2...
CVE-2009-1215——Race condition in GNU screen 4.0.3 allows local users to create or overwrite arbitrary files via a symlink attack on the...
CVE-2009-1214——GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow loca...
CVE-2009-1213——Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and ea...
CVE-2009-1212——Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datam...
CVE-2009-1211——Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endp...
CVE-2009-1210——Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now