2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-4642gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce d...
CVE-2009-4641gnome-screensaver 2.28.0 does not resume adherence to its activation settings after an inhibiting application becomes un...
CVE-2009-3735The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda Activ...
CVE-2009-4640Array index error in vorbis_dec.c in FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execut...
CVE-2009-4639The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash...
CVE-2009-4638Integer overflow in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitra...
CVE-2009-4637FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown ...
CVE-2009-4636FFmpeg 0.5 allows remote attackers to cause a denial of service (hang) via a crafted file that triggers an infinite loop...
CVE-2009-4635FFmpeg 0.5 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted MOV co...
CVE-2009-4634Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbit...
CVE-2009-4633vorbis_dec.c in FFmpeg 0.5 uses an assignment operator when a comparison operator was intended, which might allow remote...
CVE-2009-4632oggparsevorbis.c in FFmpeg 0.5 does not properly perform certain pointer arithmetic, which might allow remote attackers ...
CVE-2009-4631Off-by-one error in the VP3 decoder (vp3.c) in FFmpeg 0.5 allows remote attackers to cause a denial of service and possi...
CVE-2009-4185Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allo...
CVE-2009-2752IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain...
CVE-2009-2751IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which ha...
CVE-2009-4016Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox befor...
CVE-2009-2750IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration propertie...
CVE-2009-3989Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files an...
CVE-2009-3387Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process ...
CVE-2009-4184Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.1...
CVE-2009-4015Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitra...
CVE-2009-4014Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 ...
CVE-2009-4013CRITICAL9.8Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before ...
CVE-2009-3035The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt S...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now