2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4357 | — | — | 1.1% | Dec 18, 2009 | CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for au... |
| CVE-2009-4356 | — | — | 5.0% | Dec 18, 2009 | Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute a... |
| CVE-2009-3996 | — | — | 6.5% | Dec 18, 2009 | Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, m... |
| CVE-2009-3703 | — | — | 2.6% | Dec 18, 2009 | Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute... |
| CVE-2009-2880 | — | — | 5.2% | Dec 18, 2009 | Buffer overflow in atrpui.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Wi... |
| CVE-2009-2879 | — | — | 5.1% | Dec 18, 2009 | Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Window... |
| CVE-2009-2878 | — | — | 5.1% | Dec 18, 2009 | Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Window... |
| CVE-2009-2877 | — | — | 5.1% | Dec 18, 2009 | Stack-based buffer overflow in ataudio.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 2... |
| CVE-2009-2876 | — | — | 5.1% | Dec 18, 2009 | Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Window... |
| CVE-2009-2875 | — | — | 5.1% | Dec 18, 2009 | Buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Wi... |
| CVE-2009-3997 | — | — | 5.7% | Dec 18, 2009 | Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to ex... |
| CVE-2009-3995 | — | — | 6.7% | Dec 18, 2009 | Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod... |
| CVE-2009-4354 | — | — | 1.1% | Dec 17, 2009 | TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie... |
| CVE-2009-4353 | — | — | 1.1% | Dec 17, 2009 | The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2... |
| CVE-2009-4352 | — | — | 1.1% | Dec 17, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and... |
| CVE-2009-4351 | — | — | 1.1% | Dec 17, 2009 | SQL injection vulnerability in ADMIN/loginaction.php in WSCreator 1.1, when magic_quotes_gpc is disabled, allows remote ... |
| CVE-2009-4350 | — | — | 1.2% | Dec 17, 2009 | SQL injection vulnerability in index.php in Arctic Issue Tracker 2.1.1 allows remote attackers to execute arbitrary SQL ... |
| CVE-2009-4349 | — | — | 1.2% | Dec 17, 2009 | Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote a... |
| CVE-2009-4348 | — | — | 0.9% | Dec 17, 2009 | Cross-site scripting (XSS) vulnerability in index.php in Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers ... |
| CVE-2009-4347 | — | — | 1.1% | Dec 17, 2009 | Cross-site scripting (XSS) vulnerability in daloradius-users/login.php in daloRADIUS 0.9-8 and earlier allows remote att... |
| CVE-2009-4346 | — | — | 0.8% | Dec 17, 2009 | Cross-site scripting (XSS) vulnerability in the Frontend news submitter with RTE (fe_rtenews) extension 1.4.1 and earlie... |
| CVE-2009-4345 | — | — | 1.0% | Dec 17, 2009 | Cross-site scripting (XSS) vulnerability in the vShoutbox (vshoutbox) extension 0.0.1 for TYPO3 allows remote attackers ... |
| CVE-2009-4344 | — | — | 1.0% | Dec 17, 2009 | Cross-site scripting (XSS) vulnerability in the ZID Linkliste (zid_linklist) extension 1.0.0 for TYPO3 allows remote att... |
| CVE-2009-4343 | — | — | 1.0% | Dec 17, 2009 | Cross-site scripting (XSS) vulnerability in the Training Company Database (trainincdb) extension 0.4.7 for TYPO3 allows ... |
| CVE-2009-4342 | — | — | 1.1% | Dec 17, 2009 | SQL injection vulnerability in the Job Exchange (jobexchange) extension 0.0.3 for TYPO3 allows remote attackers to execu... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now