2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2009-3939HIGH7.1The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permission...
CVE-2009-3129HIGH7.8Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv...
CVE-2009-3547HIGH7Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of servi...
CVE-2009-3611HIGH7.1common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the file...
CVE-2009-3759HIGH8.8Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCen...
CVE-2009-3620HIGH7.8The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command E...
CVE-2009-2529HIGH8.1Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified va...
CVE-2009-2516HIGH7.1The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does...
CVE-2009-2502HIGH8.1Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 20...
CVE-2009-1547HIGH8.8Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute ar...
CVE-2009-3459HIGH8.8Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem...
CVE-2009-2699HIGH7.5The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library b...
CVE-2009-3658HIGH8.8Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remo...
CVE-2009-3520HIGH8.8Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hij...
CVE-2009-3489HIGH7.8Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, whi...
CVE-2009-3482HIGH7.8TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) fo...
CVE-2009-3289HIGH7.8The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), ...
CVE-2009-3168HIGH7.2Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/use...
CVE-2009-3046HIGH7.5Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote S...
CVE-2009-2698HIGH7.8The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel befo...
CVE-2009-2768HIGH7.8The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 al...
CVE-2009-2692HIGH7.8The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke...
CVE-2009-1544HIGH8.8Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain priv...
CVE-2009-2493HIGH8.8The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1...
CVE-2009-0901HIGH8.8The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Vi...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now