2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4236 | — | — | 1.5% | Dec 8, 2009 | The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 ... |
| CVE-2009-3844 | — | — | 74.1% | Dec 8, 2009 | Stack-based buffer overflow in the OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and ... |
| CVE-2009-1569 | — | — | 37.5% | Dec 8, 2009 | Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow ... |
| CVE-2009-1568 | — | — | 32.2% | Dec 8, 2009 | Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows ... |
| CVE-2009-1298 | — | — | 3.9% | Dec 8, 2009 | The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions befor... |
| CVE-2009-4235 | — | — | 0.3% | Dec 8, 2009 | acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, a... |
| CVE-2009-4234 | — | — | 1.3% | Dec 8, 2009 | Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910... |
| CVE-2009-4233 | — | — | 1.0% | Dec 8, 2009 | Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla... |
| CVE-2009-4232 | — | — | 1.0% | Dec 8, 2009 | The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote a... |
| CVE-2009-4231 | — | — | 2.3% | Dec 8, 2009 | Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to includ... |
| CVE-2009-4230 | — | — | 2.9% | Dec 8, 2009 | Multiple stack-based buffer overflows in src/Task.cc in the FastCGI program in IIPImage Server before 0.9.8 might allow ... |
| CVE-2009-4229 | — | — | 0.9% | Dec 8, 2009 | Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL... |
| CVE-2009-4033 | — | — | 0.3% | Dec 8, 2009 | A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, wh... |
| CVE-2009-4228 | — | — | 1.7% | Dec 8, 2009 | Stack consumption vulnerability in u_bound.c in Xfig 3.2.5b and earlier allows remote attackers to cause a denial of ser... |
| CVE-2009-4227 | — | — | 10.6% | Dec 8, 2009 | Stack-based buffer overflow in the read_1_3_textobject function in f_readold.c in Xfig 3.2.5b and earlier, and in the re... |
| CVE-2009-4226 | — | — | 1.8% | Dec 8, 2009 | Race condition in the IP module in the kernel in Sun OpenSolaris snv_106 through snv_124 allows remote attackers to caus... |
| CVE-2009-4225 | — | — | 30.6% | Dec 8, 2009 | Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote ... |
| CVE-2009-3586 | — | — | 6.4% | Dec 8, 2009 | Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or p... |
| CVE-2009-3994 | — | — | 7.0% | Dec 8, 2009 | Stack-based buffer overflow in the GetUID function in src-IL/src/il_dicom.c in DevIL 1.7.8 allows remote attackers to ca... |
| CVE-2009-2843 | — | — | 2.1% | Dec 8, 2009 | Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it... |
| CVE-2009-2749 | — | — | 1.1% | Dec 8, 2009 | Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 u... |
| CVE-2009-4224 | — | — | 2.6% | Dec 7, 2009 | Multiple PHP remote file inclusion vulnerabilities in SweetRice 0.5.4, 0.5.3, and earlier allow remote attackers to exec... |
| CVE-2009-4223 | — | — | 55.5% | Dec 7, 2009 | PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execut... |
| CVE-2009-4222 | — | — | 2.2% | Dec 7, 2009 | phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote at... |
| CVE-2009-4221 | — | — | 1.0% | Dec 7, 2009 | SQL injection vulnerability in classified.php in phpBazar 2.1.1fix and earlier allows remote attackers to execute arbitr... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now