2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4265 | — | — | 31.4% | Dec 10, 2009 | Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to ... |
| CVE-2009-4264 | — | — | 1.7% | Dec 10, 2009 | PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_global... |
| CVE-2009-4263 | — | — | 0.9% | Dec 10, 2009 | SQL injection vulnerability in main_forum.php in PTCPay GeN3 forum 1.3 allows remote attackers to execute arbitrary SQL ... |
| CVE-2009-4262 | — | — | 1.3% | Dec 10, 2009 | Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to obtain access to the admin control panel via a direct ... |
| CVE-2009-4256 | — | — | 1.0% | Dec 10, 2009 | Multiple SQL injection vulnerabilities in cource.php in AlefMentor 2.0 and 2.2 allow remote attackers to execute arbitra... |
| CVE-2009-4255 | — | — | 1.1% | Dec 10, 2009 | Cross-site scripting (XSS) vulnerability in the You!Hostit! template 1.0.1 for Joomla! allows remote attackers to inject... |
| CVE-2009-4254 | — | — | 1.1% | Dec 10, 2009 | PowerPhlogger 2.2.5 allows remote attackers to obtain sensitive information via a direct request to (1) edCss.inc.php, (... |
| CVE-2009-4253 | — | — | 1.5% | Dec 10, 2009 | Cross-site scripting (XSS) vulnerability in dspStats.php in PowerPhlogger 2.2.5 allows remote attackers to inject arbitr... |
| CVE-2009-4252 | — | — | 1.1% | Dec 10, 2009 | Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attack... |
| CVE-2009-4251 | — | — | 8.2% | Dec 10, 2009 | Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers... |
| CVE-2009-4250 | — | — | 2.0% | Dec 10, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote ... |
| CVE-2009-4249 | — | — | 1.9% | Dec 10, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magi... |
| CVE-2009-4240 | — | — | 2.1% | Dec 9, 2009 | Multiple buffer overflows in unspecified setuid executables in the DataStage subsystem in IBM InfoSphere Information Ser... |
| CVE-2009-4239 | — | — | 1.3% | Dec 9, 2009 | Cross-site scripting (XSS) vulnerability in the Web console in IBM InfoSphere Information Server 8.1 before FP1 allows r... |
| CVE-2009-4149 | — | — | 0.8% | Dec 9, 2009 | Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject ... |
| CVE-2009-3677 | — | — | 21.8% | Dec 9, 2009 | The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and... |
| CVE-2009-3675 | — | — | 24.7% | Dec 9, 2009 | LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and S... |
| CVE-2009-3674 | — | — | 26.3% | Dec 9, 2009 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit... |
| CVE-2009-3673 | — | — | 25.4% | Dec 9, 2009 | Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute... |
| CVE-2009-3563 | — | — | 32.3% | Dec 9, 2009 | ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and ba... |
| CVE-2009-2509 | — | — | 17.1% | Dec 9, 2009 | Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not p... |
| CVE-2009-2508 | — | — | 1.3% | Dec 9, 2009 | The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 an... |
| CVE-2009-2506 | — | — | 31.2% | Dec 9, 2009 | Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack... |
| CVE-2009-2505 | — | — | 31.6% | Dec 9, 2009 | The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate ... |
| CVE-2009-0102 | — | — | 23.5% | Dec 9, 2009 | Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Pro... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now