2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-0040 | — | — | 4.8% | Feb 22, 2009 | The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other application... |
| CVE-2009-0659 | — | — | 6.6% | Feb 20, 2009 | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown ... |
| CVE-2009-0658 | HIGH | 7.8 | 87.7% | Feb 20, 2009 | Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra... |
| CVE-2009-0657 | — | — | 0.4% | Feb 20, 2009 | Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large ... |
| CVE-2009-0656 | — | — | 0.4% | Feb 20, 2009 | Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image wit... |
| CVE-2009-0655 | — | — | 0.4% | Feb 20, 2009 | Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of... |
| CVE-2009-0654 | — | — | 2.1% | Feb 20, 2009 | Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit ro... |
| CVE-2009-0653 | — | — | 1.1% | Feb 20, 2009 | OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows r... |
| CVE-2009-0652 | — | — | 1.5% | Feb 20, 2009 | The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird... |
| CVE-2009-0577 | — | — | 3.6% | Feb 20, 2009 | Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remo... |
| CVE-2009-0651 | — | — | 3.4% | Feb 20, 2009 | Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Se... |
| CVE-2009-0650 | — | — | 12.8% | Feb 20, 2009 | Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo... |
| CVE-2009-0649 | — | — | 8.3% | Feb 20, 2009 | The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v... |
| CVE-2009-0643 | — | — | 4.8% | Feb 20, 2009 | Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary... |
| CVE-2009-0642 | — | — | 2.6% | Feb 20, 2009 | ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function... |
| CVE-2009-0641 | — | — | 9.4% | Feb 20, 2009 | sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a metho... |
| CVE-2009-0640 | — | — | 2.8% | Feb 20, 2009 | Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re... |
| CVE-2009-0648 | — | — | 0.6% | Feb 19, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (... |
| CVE-2009-0647 | — | — | 17.4% | Feb 19, 2009 | msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attack... |
| CVE-2009-0646 | — | — | 3.6% | Feb 18, 2009 | Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm... |
| CVE-2009-0645 | — | — | 6.3% | Feb 18, 2009 | Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v... |
| CVE-2009-0644 | — | — | 1.2% | Feb 18, 2009 | The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it ea... |
| CVE-2009-0639 | — | — | 2.6% | Feb 18, 2009 | PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar... |
| CVE-2009-0310 | — | — | 0.4% | Feb 18, 2009 | Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors relate... |
| CVE-2009-0613 | — | — | 1.5% | Feb 17, 2009 | Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Onl... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now