2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1209 | — | — | 12.4% | Apr 1, 2009 | Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script... |
| CVE-2009-1208 | — | — | 2.0% | Apr 1, 2009 | SQL injection vulnerability in auth2db 0.2.5, and possibly other versions before 0.2.7, uses the addslashes function ins... |
| CVE-2009-1207 | — | — | 0.3% | Apr 1, 2009 | Race condition in the dircmp script in Sun Solaris 8 through 10, and OpenSolaris snv_01 through snv_111, allows local us... |
| CVE-2009-1206 | — | — | 1.7% | Apr 1, 2009 | Unspecified vulnerability in futomi's CGI Cafe Access Analyzer CGI Professional Version 4.11.5 and earlier allows remote... |
| CVE-2009-1205 | — | — | — | Apr 1, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-4475. Reason: This candidate is a duplicate of... |
| CVE-2009-0790 | — | — | 3.2% | Apr 1, 2009 | The pluto IKE daemon in Openswan and Strongswan IPsec 2.6 before 2.6.21 and 2.4 before 2.4.14, and Strongswan 4.2 before... |
| CVE-2009-0686 | — | — | 0.8% | Apr 1, 2009 | The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Securit... |
| CVE-2009-1204 | — | — | 4.5% | Apr 1, 2009 | Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar... |
| CVE-2009-1178 | — | — | 1.8% | Mar 31, 2009 | Unspecified vulnerability in the server in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.2 and 6.x before 6.1 has un... |
| CVE-2009-1177 | — | — | 2.9% | Mar 31, 2009 | Multiple stack-based buffer overflows in maptemplate.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 ha... |
| CVE-2009-1176 | — | — | 4.1% | Mar 31, 2009 | mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id ... |
| CVE-2009-1073 | MEDIUM | 5.5 | 0.9% | Mar 31, 2009 | nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obt... |
| CVE-2009-0843 | — | — | 3.1% | Mar 31, 2009 | The msLoadQuery function in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to deter... |
| CVE-2009-0842 | — | — | 2.6% | Mar 31, 2009 | mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to read arbitrary invalid .map files... |
| CVE-2009-0841 | — | — | 5.3% | Mar 31, 2009 | Directory traversal vulnerability in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when runn... |
| CVE-2009-0840 | — | — | 5.3% | Mar 31, 2009 | Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x ... |
| CVE-2009-0839 | — | — | 9.0% | Mar 31, 2009 | Stack-based buffer overflow in mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2, when the server... |
| CVE-2009-1175 | — | — | 0.9% | Mar 31, 2009 | Cross-site scripting (XSS) vulnerability in apps/web/vs_diag.cgi in the DAAP extension in Banshee 1.4.2 allows remote at... |
| CVE-2009-1174 | — | — | 2.4% | Mar 31, 2009 | The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0... |
| CVE-2009-1173 | — | — | 0.3% | Mar 31, 2009 | IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.3 uses weak permissions (777) for files associated with unspecif... |
| CVE-2009-1172 | — | — | 1.8% | Mar 31, 2009 | The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 bef... |
| CVE-2009-0892 | — | — | 1.3% | Mar 31, 2009 | The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows a... |
| CVE-2009-1171 | — | — | 6.2% | Mar 30, 2009 | The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist... |
| CVE-2009-1170 | — | — | 0.4% | Mar 30, 2009 | Unspecified vulnerability in Sun OpenSolaris snv_100 through snv_101 allows local users, with privileges in a non-global... |
| CVE-2009-0115 | HIGH | 7.8 | 0.5% | Mar 30, 2009 | The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now