2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0040The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other application...
CVE-2009-0659Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown ...
CVE-2009-0658HIGH7.8Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra...
CVE-2009-0657Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large ...
CVE-2009-0656Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image wit...
CVE-2009-0655Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of...
CVE-2009-0654Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit ro...
CVE-2009-0653OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows r...
CVE-2009-0652The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird...
CVE-2009-0577Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remo...
CVE-2009-0651Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Se...
CVE-2009-0650Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo...
CVE-2009-0649The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v...
CVE-2009-0643Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary...
CVE-2009-0642ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function...
CVE-2009-0641sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a metho...
CVE-2009-0640Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re...
CVE-2009-0648Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (...
CVE-2009-0647msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attack...
CVE-2009-0646Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm...
CVE-2009-0645Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v...
CVE-2009-0644The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it ea...
CVE-2009-0639PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar...
CVE-2009-0310Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors relate...
CVE-2009-0613Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Onl...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now