2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0040——The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other application...
CVE-2009-0659——Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown ...
CVE-2009-0658HIGH7.8Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra...
CVE-2009-0657——Toshiba Face Recognition 2.0.2.32 allows physically proximate attackers to obtain notebook access by presenting a large ...
CVE-2009-0656——Asus SmartLogon 1.0.0005 allows physically proximate attackers to bypass "security functions" by presenting an image wit...
CVE-2009-0655——Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of...
CVE-2009-0654——Tor 0.2.0.28, and probably 0.2.0.34 and earlier, allows remote attackers, with control of an entry router and an exit ro...
CVE-2009-0653——OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows r...
CVE-2009-0652——The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird...
CVE-2009-0577——Integer overflow in the WriteProlog function in texttops in CUPS 1.1.17 on Red Hat Enterprise Linux (RHEL) 3 allows remo...
CVE-2009-0651——Unspecified vulnerability in the Veritas network daemon (aka vnetd) in Symantec Veritas NetBackup Server / Enterprise Se...
CVE-2009-0650——Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo...
CVE-2009-0649——The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v...
CVE-2009-0643——Static code injection vulnerability in post.php in Simple PHP News 1.0 final allows remote attackers to inject arbitrary...
CVE-2009-0642——ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function...
CVE-2009-0641——sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a metho...
CVE-2009-0640——Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re...
CVE-2009-0648——Multiple cross-site request forgery (CSRF) vulnerabilities in the manage_users handler in admin/index.php in Falt4 CMS (...
CVE-2009-0647——msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attack...
CVE-2009-0646——Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm...
CVE-2009-0645——Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v...
CVE-2009-0644——The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it ea...
CVE-2009-0639——PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar...
CVE-2009-0310——Buffer overflow in SUSE blinux (aka sbl) in SUSE openSUSE 10.3 through 11.0 has unknown impact and attack vectors relate...
CVE-2009-0613——Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Onl...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now