2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4657 | — | — | 2.2% | Mar 3, 2010 | The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter applic... |
| CVE-2009-4656 | — | — | 31.7% | Mar 3, 2010 | Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-as... |
| CVE-2009-3297 | — | — | — | Mar 2, 2010 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-0787, CVE-2010-0788, CVE-2010-0789. Reason: th... |
| CVE-2009-4655 | — | — | 49.9% | Feb 26, 2010 | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote att... |
| CVE-2009-4654 | — | — | 6.8% | Feb 26, 2010 | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated use... |
| CVE-2009-4653 | — | — | 12.7% | Feb 26, 2010 | Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated use... |
| CVE-2009-4652 | — | — | 1.6% | Feb 26, 2010 | The (1) Conn_GetCipherInfo and (2) Conn_UsesSSL functions in src/ngircd/conn.c in ngIRCd 13 and 14, when SSL/TLS support... |
| CVE-2009-3036 | — | — | 2.3% | Feb 23, 2010 | Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote a... |
| CVE-2009-4651 | — | — | 1.2% | Feb 22, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2... |
| CVE-2009-4650 | — | — | 1.0% | Feb 22, 2010 | SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows re... |
| CVE-2009-4649 | — | — | 1.1% | Feb 22, 2010 | Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web scr... |
| CVE-2009-3988 | — | — | 2.1% | Feb 22, 2010 | Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read ... |
| CVE-2009-1571 | — | — | 6.4% | Feb 22, 2010 | Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbi... |
| CVE-2009-4648 | — | — | 0.8% | Feb 19, 2010 | Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and argu... |
| CVE-2009-4647 | — | — | 1.1% | Feb 19, 2010 | Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attack... |
| CVE-2009-4646 | — | — | 1.7% | Feb 19, 2010 | Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allo... |
| CVE-2009-4645 | — | — | 2.8% | Feb 19, 2010 | Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_1... |
| CVE-2009-4644 | — | — | 2.4% | Feb 19, 2010 | Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restric... |
| CVE-2009-3302 | — | — | 11.7% | Feb 16, 2010 | filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (applicat... |
| CVE-2009-3301 | — | — | 12.1% | Feb 16, 2010 | Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial... |
| CVE-2009-2950 | — | — | 13.4% | Feb 16, 2010 | Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenO... |
| CVE-2009-2949 | — | — | 14.1% | Feb 16, 2010 | Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.... |
| CVE-2009-4643 | — | — | 3.8% | Feb 15, 2010 | Stack-based buffer overflow in dsInstallerService.dll in the Juniper Installer Service, as used in Juniper Odyssey Acces... |
| CVE-2009-3960 | MEDIUM | 6.5 | 90.0% | Feb 15, 2010 | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service... |
| CVE-2009-4274 | — | — | 4.2% | Feb 12, 2010 | Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now