2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-0261 | — | — | 13.2% | Jan 23, 2009 | Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary ... |
| CVE-2009-0260 | — | — | 5.4% | Jan 23, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attack... |
| CVE-2009-0259 | — | — | 7.5% | Jan 22, 2009 | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) an... |
| CVE-2009-0258 | — | — | 3.3% | Jan 22, 2009 | The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0... |
| CVE-2009-0257 | — | — | 1.6% | Jan 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through... |
| CVE-2009-0256 | — | — | 1.8% | Jan 22, 2009 | Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.... |
| CVE-2009-0255 | HIGH | 7.5 | 9.4% | Jan 22, 2009 | The System extension Install tool in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 creates the... |
| CVE-2009-0254 | — | — | 2.6% | Jan 22, 2009 | Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invali... |
| CVE-2009-0253 | — | — | 2.5% | Jan 22, 2009 | Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that ... |
| CVE-2009-0057 | — | — | 0.9% | Jan 22, 2009 | The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6... |
| CVE-2009-0008 | — | — | 4.0% | Jan 22, 2009 | Unspecified vulnerability in Apple QuickTime MPEG-2 Playback Component before 7.60.92.0 on Windows allows remote attacke... |
| CVE-2009-0252 | — | — | 1.0% | Jan 22, 2009 | Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arb... |
| CVE-2009-0251 | — | — | 5.6% | Jan 22, 2009 | Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to ... |
| CVE-2009-0250 | — | — | 6.3% | Jan 22, 2009 | Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows rem... |
| CVE-2009-0249 | — | — | 2.3% | Jan 22, 2009 | Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remot... |
| CVE-2009-0248 | — | — | 1.5% | Jan 22, 2009 | Cross-site scripting (XSS) vulnerability in rankup.asp in Katy Whitton RankEm allows remote attackers to inject arbitrar... |
| CVE-2009-0247 | — | — | 1.0% | Jan 22, 2009 | The server for 53KF Web IM 2009 Home, Professional, and Enterprise editions relies on client-side protection mechanisms ... |
| CVE-2009-0246 | — | — | 3.4% | Jan 22, 2009 | Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invali... |
| CVE-2009-0245 | — | — | 1.1% | Jan 22, 2009 | Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0.1 and earlier allows remote attackers to inject a... |
| CVE-2009-0244 | HIGH | 8.8 | 30.3% | Jan 21, 2009 | Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professio... |
| CVE-2009-0243 | — | — | 6.3% | Jan 21, 2009 | Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically ... |
| CVE-2009-0030 | — | — | 1.7% | Jan 21, 2009 | A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remot... |
| CVE-2009-0026 | — | — | 21.6% | Jan 21, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Apache Jackrabbit before 1.5.2 allow remote attackers to inject a... |
| CVE-2009-0007 | — | — | 7.7% | Jan 21, 2009 | Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (applicati... |
| CVE-2009-0006 | — | — | 8.2% | Jan 21, 2009 | Integer signedness error in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now