2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2857 | MEDIUM | 5.5 | 0.3% | Aug 19, 2009 | The kernel in Sun Solaris 8, 9, and 10, and OpenSolaris before snv_103, does not properly handle interaction between the... |
| CVE-2009-2055 | MEDIUM | 5.9 | 3.3% | Aug 19, 2009 | Cisco IOS XR 3.4.0 through 3.8.1 allows remote attackers to cause a denial of service (session reset) via a BGP UPDATE m... |
| CVE-2009-2416 | MEDIUM | 6.5 | 1.8% | Aug 11, 2009 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow ... |
| CVE-2009-2408 | MEDIUM | 5.9 | 5.7% | Jul 30, 2009 | Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey... |
| CVE-2009-2495 | MEDIUM | 6.5 | 41.9% | Jul 29, 2009 | The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1... |
| CVE-2009-1388 | MEDIUM | 5.5 | 0.4% | Jul 5, 2009 | The ptrace_start function in kernel/ptrace.c in the Linux kernel 2.6.18 does not properly handle simultaneous execution ... |
| CVE-2009-2216 | MEDIUM | 6.1 | 1.5% | Jun 25, 2009 | Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to in... |
| CVE-2009-2213 | MEDIUM | 6.5 | 2.0% | Jun 25, 2009 | The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterpri... |
| CVE-2009-1961 | MEDIUM | 4.7 | 0.6% | Jun 8, 2009 | The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, ... |
| CVE-2009-0783 | MEDIUM | 4.2 | 0.8% | Jun 5, 2009 | Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace a... |
| CVE-2009-1466 | MEDIUM | 5.5 | 0.2% | May 14, 2009 | Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which al... |
| CVE-2009-1605 | MEDIUM | 5.4 | 3.4% | May 11, 2009 | Heap-based buffer overflow in the loadexponentialfunc function in mupdf/pdf_function.c in MuPDF in the mupdf-20090223-wi... |
| CVE-2009-1596 | MEDIUM | 6.5 | 1.2% | May 11, 2009 | Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console ... |
| CVE-2009-1243 | MEDIUM | 5.5 | 0.3% | Apr 6, 2009 | net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain incorrect circumstances, which ... |
| CVE-2009-1073 | MEDIUM | 5.5 | 0.9% | Mar 31, 2009 | nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obt... |
| CVE-2009-0935 | MEDIUM | 5.5 | 0.3% | Mar 18, 2009 | The inotify_read function in the Linux kernel 2.6.27 to 2.6.27.13, 2.6.28 to 2.6.28.2, and 2.6.29-rc3 allows local users... |
| CVE-2009-0141 | MEDIUM | 5.5 | 0.3% | Feb 13, 2009 | XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permis... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now