2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3939 | HIGH | 7.1 | 0.4% | Nov 16, 2009 | The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permission... |
| CVE-2009-3129 | HIGH | 7.8 | 85.7% | Nov 11, 2009 | Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv... |
| CVE-2009-3547 | HIGH | 7 | 4.9% | Nov 4, 2009 | Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of servi... |
| CVE-2009-3611 | HIGH | 7.1 | 0.3% | Oct 26, 2009 | common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the file... |
| CVE-2009-3759 | HIGH | 8.8 | 2.3% | Oct 22, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCen... |
| CVE-2009-3620 | HIGH | 7.8 | 0.4% | Oct 22, 2009 | The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command E... |
| CVE-2009-2529 | HIGH | 8.1 | 19.5% | Oct 14, 2009 | Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified va... |
| CVE-2009-2516 | HIGH | 7.1 | 1.3% | Oct 14, 2009 | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does... |
| CVE-2009-2502 | HIGH | 8.1 | 22.0% | Oct 14, 2009 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 20... |
| CVE-2009-1547 | HIGH | 8.8 | 37.4% | Oct 14, 2009 | Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute ar... |
| CVE-2009-3459 | HIGH | 8.8 | 86.5% | Oct 13, 2009 | Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem... |
| CVE-2009-2699 | HIGH | 7.5 | 14.2% | Oct 13, 2009 | The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library b... |
| CVE-2009-3658 | HIGH | 8.8 | 8.9% | Oct 9, 2009 | Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remo... |
| CVE-2009-3520 | HIGH | 8.8 | 0.6% | Oct 1, 2009 | Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hij... |
| CVE-2009-3489 | HIGH | 7.8 | 2.0% | Sep 30, 2009 | Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, whi... |
| CVE-2009-3482 | HIGH | 7.8 | 0.3% | Sep 30, 2009 | TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) fo... |
| CVE-2009-3289 | HIGH | 7.8 | 0.4% | Sep 22, 2009 | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), ... |
| CVE-2009-3168 | HIGH | 7.2 | 2.6% | Sep 11, 2009 | Mevin Productions Basic PHP Events Lister 2.0 does not properly restrict access to (1) admin/reset.php and (2) admin/use... |
| CVE-2009-3046 | HIGH | 7.5 | 1.1% | Sep 2, 2009 | Opera before 10.00 does not check all intermediate X.509 certificates for revocation, which makes it easier for remote S... |
| CVE-2009-2698 | HIGH | 7.8 | 7.2% | Aug 27, 2009 | The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel befo... |
| CVE-2009-2768 | HIGH | 7.8 | 0.4% | Aug 14, 2009 | The load_flat_shared_library function in fs/binfmt_flat.c in the flat subsystem in the Linux kernel before 2.6.31-rc6 al... |
| CVE-2009-2692 | HIGH | 7.8 | 14.7% | Aug 14, 2009 | The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke... |
| CVE-2009-1544 | HIGH | 8.8 | 20.6% | Aug 12, 2009 | Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain priv... |
| CVE-2009-2493 | HIGH | 8.8 | 43.4% | Jul 29, 2009 | The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1... |
| CVE-2009-0901 | HIGH | 8.8 | 42.0% | Jul 29, 2009 | The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Vi... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now