2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-4640——Array index error in vorbis_dec.c in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execut...
CVE-2009-4639——The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash...
CVE-2009-4638——Integer overflow in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra...
CVE-2009-4637——FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown ...
CVE-2009-4636——FFmpeg 0.5 allows remote attackers to cause a denial of service (hang) via a crafted file that triggers an infinite loop...
CVE-2009-4635——FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted MOV co...
CVE-2009-4634——Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbit...
CVE-2009-4633——vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote...
CVE-2009-4632——oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers ...
CVE-2009-4631——Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possi...
CVE-2009-4185——Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allo...
CVE-2009-2752——IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain...
CVE-2009-2751——IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which ha...
CVE-2009-4016——Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox befor...
CVE-2009-2750——IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration propertie...
CVE-2009-3989——Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files an...
CVE-2009-3387——Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process ...
CVE-2009-4184——Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.1...
CVE-2009-4015——Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitra...
CVE-2009-4014——Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 ...
CVE-2009-3035——The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt S...
CVE-2009-4630——Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained...
CVE-2009-4629——Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the a...
CVE-2009-2624——The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which ...
CVE-2009-4183——Unspecified vulnerability in HP OpenView Storage Data Protector 6.00 and 6.10 allows local users to obtain unspecified "...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now