2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-0947CRITICAL9.8Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.
CVE-2009-3721HIGH7.8Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parse...
CVE-2009-20001HIGH8.1An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is n...
CVE-2009-5106Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2009-5105Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2009-5104Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2009-5070Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2009-5069Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2009-5159MEDIUM6.1Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt at...
CVE-2009-5146Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2009-5140HIGH8.8The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid auth...
CVE-2009-5139HIGH7.5The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authenticati...
CVE-2009-4067MEDIUM6.8Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 all...
CVE-2009-5068HIGH7.2There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some confi...
CVE-2009-5025HIGH7.5A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a p...
CVE-2009-3724MEDIUM6.1python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.
CVE-2009-1120CRITICAL9.8EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists w...
CVE-2009-5047Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-4611. Reason: This candidate is a duplicate of C...
CVE-2009-5004MEDIUM6.5qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
CVE-2009-4011HIGH8.1dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX ...
CVE-2009-3614LOW3.3liboping 1.3.2 allows users reading arbitrary files upon the local system.
CVE-2009-3552LOW3.1In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterpris...
CVE-2009-2802MEDIUM6.1MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could l...
CVE-2009-0035MEDIUM5.5alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/b...
CVE-2009-5046MEDIUM6.1JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now