2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4640 | — | — | 4.0% | Feb 10, 2010 | Array index error in vorbis_dec.c in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execut... |
| CVE-2009-4639 | — | — | 3.0% | Feb 10, 2010 | The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash... |
| CVE-2009-4638 | — | — | 3.9% | Feb 10, 2010 | Integer overflow in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra... |
| CVE-2009-4637 | — | — | 17.0% | Feb 10, 2010 | FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown ... |
| CVE-2009-4636 | — | — | 3.0% | Feb 10, 2010 | FFmpeg 0.5 allows remote attackers to cause a denial of service (hang) via a crafted file that triggers an infinite loop... |
| CVE-2009-4635 | — | — | 8.1% | Feb 10, 2010 | FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted MOV co... |
| CVE-2009-4634 | — | — | 7.2% | Feb 10, 2010 | Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbit... |
| CVE-2009-4633 | — | — | 7.9% | Feb 10, 2010 | vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote... |
| CVE-2009-4632 | — | — | 2.2% | Feb 10, 2010 | oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers ... |
| CVE-2009-4631 | — | — | 5.1% | Feb 10, 2010 | Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possi... |
| CVE-2009-4185 | — | — | 3.0% | Feb 5, 2010 | Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allo... |
| CVE-2009-2752 | — | — | 0.2% | Feb 5, 2010 | IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain... |
| CVE-2009-2751 | — | — | 0.5% | Feb 5, 2010 | IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which ha... |
| CVE-2009-4016 | — | — | 4.0% | Feb 4, 2010 | Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox befor... |
| CVE-2009-2750 | — | — | 1.0% | Feb 4, 2010 | IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration propertie... |
| CVE-2009-3989 | — | — | 1.5% | Feb 3, 2010 | Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files an... |
| CVE-2009-3387 | — | — | 1.7% | Feb 3, 2010 | Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process ... |
| CVE-2009-4184 | — | — | 0.3% | Feb 3, 2010 | Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.1... |
| CVE-2009-4015 | — | — | 4.0% | Feb 2, 2010 | Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitra... |
| CVE-2009-4014 | — | — | 3.1% | Feb 2, 2010 | Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 ... |
| CVE-2009-3035 | — | — | 0.4% | Feb 2, 2010 | The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt S... |
| CVE-2009-4630 | — | — | 1.0% | Jan 29, 2010 | Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained... |
| CVE-2009-4629 | — | — | 0.9% | Jan 29, 2010 | Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the a... |
| CVE-2009-2624 | — | — | 4.2% | Jan 29, 2010 | The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which ... |
| CVE-2009-4183 | — | — | 0.5% | Jan 28, 2010 | Unspecified vulnerability in HP OpenView Storage Data Protector 6.00 and 6.10 allows local users to obtain unspecified "... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now