2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-0947 | CRITICAL | 9.8 | 1.1% | Jun 2, 2021 | Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02. |
| CVE-2009-3721 | HIGH | 7.8 | 1.6% | May 26, 2021 | Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parse... |
| CVE-2009-20001 | HIGH | 8.1 | 0.9% | Mar 7, 2021 | An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is n... |
| CVE-2009-5106 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2009-5105 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2009-5104 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2009-5070 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2009-5069 | — | — | — | Nov 5, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No... |
| CVE-2009-5159 | MEDIUM | 6.1 | 3.4% | Mar 13, 2020 | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt at... |
| CVE-2009-5146 | — | — | — | Feb 18, 2020 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2009-5140 | HIGH | 8.8 | 1.4% | Feb 12, 2020 | The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid auth... |
| CVE-2009-5139 | HIGH | 7.5 | 0.4% | Feb 12, 2020 | The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authenticati... |
| CVE-2009-4067 | MEDIUM | 6.8 | 2.1% | Feb 11, 2020 | Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 all... |
| CVE-2009-5068 | HIGH | 7.2 | 1.7% | Jan 15, 2020 | There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some confi... |
| CVE-2009-5025 | HIGH | 7.5 | 1.8% | Jan 15, 2020 | A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a p... |
| CVE-2009-3724 | MEDIUM | 6.1 | 0.8% | Jan 15, 2020 | python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues. |
| CVE-2009-1120 | CRITICAL | 9.8 | 7.4% | Jan 15, 2020 | EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists w... |
| CVE-2009-5047 | — | — | — | Nov 15, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-4611. Reason: This candidate is a duplicate of C... |
| CVE-2009-5004 | MEDIUM | 6.5 | 2.6% | Nov 9, 2019 | qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . |
| CVE-2009-4011 | HIGH | 8.1 | 1.0% | Nov 9, 2019 | dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX ... |
| CVE-2009-3614 | LOW | 3.3 | 0.3% | Nov 9, 2019 | liboping 1.3.2 allows users reading arbitrary files upon the local system. |
| CVE-2009-3552 | LOW | 3.1 | 0.4% | Nov 9, 2019 | In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterpris... |
| CVE-2009-2802 | MEDIUM | 6.1 | 0.9% | Nov 9, 2019 | MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could l... |
| CVE-2009-0035 | MEDIUM | 5.5 | 0.5% | Nov 9, 2019 | alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/b... |
| CVE-2009-5046 | MEDIUM | 6.1 | 1.6% | Nov 6, 2019 | JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now