2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4270 | — | — | 6.9% | Dec 21, 2009 | Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote at... |
| CVE-2009-4261 | — | — | 3.3% | Dec 21, 2009 | Multiple directory traversal vulnerabilities in the iallocator framework in Ganeti 1.2.4 through 1.2.8, 2.0.0 through 2.... |
| CVE-2009-4143 | — | — | 2.9% | Dec 21, 2009 | PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) ... |
| CVE-2009-4142 | — | — | 6.5% | Dec 21, 2009 | The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Sh... |
| CVE-2009-3792 | — | — | 4.3% | Dec 21, 2009 | Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL ... |
| CVE-2009-3791 | HIGH | 7.5 | 2.6% | Dec 21, 2009 | Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (... |
| CVE-2009-3701 | — | — | 4.8% | Dec 21, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in Horde Application Framework befor... |
| CVE-2009-4360 | — | — | 1.0% | Dec 20, 2009 | SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to ... |
| CVE-2009-4359 | — | — | 1.5% | Dec 20, 2009 | Cross-site scripting (XSS) vulnerability in folder.php in the SmartMedia 0.85 Beta module for XOOPS allows remote attack... |
| CVE-2009-4358 | — | — | 0.3% | Dec 20, 2009 | freebsd-update in FreeBSD 8.0, 7.2, 7.1, 6.4, and 6.3 uses insecure permissions in its working directory (/var/db/freebs... |
| CVE-2009-4029 | — | — | 0.5% | Dec 20, 2009 | The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, ... |
| CVE-2009-4357 | — | — | 1.1% | Dec 18, 2009 | CQWeb (aka the web interface) in IBM Rational ClearQuest before 7.1.1 does not properly handle use of legacy URLs for au... |
| CVE-2009-4356 | — | — | 5.0% | Dec 18, 2009 | Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute a... |
| CVE-2009-3996 | — | — | 6.5% | Dec 18, 2009 | Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, m... |
| CVE-2009-3703 | — | — | 2.6% | Dec 18, 2009 | Multiple SQL injection vulnerabilities in the WP-Forum plugin before 2.4 for WordPress allow remote attackers to execute... |
| CVE-2009-2880 | — | — | 5.2% | Dec 18, 2009 | Buffer overflow in atrpui.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Wi... |
| CVE-2009-2879 | — | — | 5.1% | Dec 18, 2009 | Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Window... |
| CVE-2009-2878 | — | — | 5.1% | Dec 18, 2009 | Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Window... |
| CVE-2009-2877 | — | — | 5.1% | Dec 18, 2009 | Stack-based buffer overflow in ataudio.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 2... |
| CVE-2009-2876 | — | — | 5.1% | Dec 18, 2009 | Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Window... |
| CVE-2009-2875 | — | — | 5.1% | Dec 18, 2009 | Buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 for Windows, 27.x before 27.10.x for Wi... |
| CVE-2009-3997 | — | — | 5.7% | Dec 18, 2009 | Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to ex... |
| CVE-2009-3995 | — | — | 6.7% | Dec 18, 2009 | Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod... |
| CVE-2009-4354 | — | — | 1.1% | Dec 17, 2009 | TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie... |
| CVE-2009-4353 | — | — | 1.1% | Dec 17, 2009 | The Mobile Edition of TransWARE Active! mail 2003 build 2003.0139.0871 and earlier, and possibly other versions before 2... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now