2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-5045HIGH7.5Dump Servlet information leak in jetty before 6.1.22.
CVE-2009-5050HIGH7.5konversation before 1.2.3 allows attackers to cause a denial of service.
CVE-2009-5049MEDIUM6.1WebApp JSP Snoop page XSS in jetty though 6.1.21.
CVE-2009-5048MEDIUM6.1Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
CVE-2009-5043CRITICAL9.8burn allows file names to escape via mishandled quotation marks
CVE-2009-5042CRITICAL9.1python-docutils allows insecure usage of temporary files
CVE-2009-5041CRITICAL9.8overkill has buffer overflow via long player names that can corrupt data on the server machine
CVE-2009-3887CRITICAL9.8ytnef has directory traversal
CVE-2009-3723HIGH7.5asterisk allows calls on prohibited networks
CVE-2009-4900MEDIUM6.1pixelpost 1.7.1 has XSS
CVE-2009-4899CRITICAL9.8pixelpost 1.7.1 has SQL injection
CVE-2009-5158The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API te...
CVE-2009-5157On Linksys WAG54G2 1.00.10 devices, there is authenticated command injection via shell metacharacters in the setup.cgi c...
CVE-2009-5156An issue was discovered on ASMAX AR-804gu 66.34.1 devices. There is Command Injection via the cgi-bin/script query strin...
CVE-2009-5155In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which al...
CVE-2009-5154An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of meinsm for the admin account...
CVE-2009-5153In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon...
CVE-2009-5152Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the D...
CVE-2009-5151The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requir...
CVE-2009-5150Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allow...
CVE-2009-2413Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2009-4267The console in Apache jUDDI 3.0.0 does not properly escape line feeds, which allows remote authenticated users to spoof ...
CVE-2009-5144mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which ...
CVE-2009-1193Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ...
CVE-2009-1198Cross-site scripting (XSS) vulnerability in Apache jUDDI before 2.0 allows remote attackers to inject arbitrary web scri...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now