2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4239 | — | — | 1.3% | Dec 9, 2009 | Cross-site scripting (XSS) vulnerability in the Web console in IBM InfoSphere Information Server 8.1 before FP1 allows r... |
| CVE-2009-4149 | — | — | 0.8% | Dec 9, 2009 | Cross-site scripting (XSS) vulnerability in the web interface in CA Service Desk 12.1 allows remote attackers to inject ... |
| CVE-2009-3677 | — | — | 21.8% | Dec 9, 2009 | The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and... |
| CVE-2009-3675 | — | — | 24.7% | Dec 9, 2009 | LSASS.exe in the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and S... |
| CVE-2009-3674 | — | — | 26.3% | Dec 9, 2009 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit... |
| CVE-2009-3673 | — | — | 25.4% | Dec 9, 2009 | Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute... |
| CVE-2009-3671 | HIGH | 8.1 | 21.0% | Dec 9, 2009 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit... |
| CVE-2009-3563 | — | — | 32.3% | Dec 9, 2009 | ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and ba... |
| CVE-2009-2509 | — | — | 17.1% | Dec 9, 2009 | Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not p... |
| CVE-2009-2508 | — | — | 1.3% | Dec 9, 2009 | The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 an... |
| CVE-2009-2506 | — | — | 31.2% | Dec 9, 2009 | Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack... |
| CVE-2009-2505 | — | — | 31.6% | Dec 9, 2009 | The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate ... |
| CVE-2009-0102 | — | — | 23.5% | Dec 9, 2009 | Microsoft Project 2000 SR1 and 2002 SP1, and Office Project 2003 SP3, does not properly handle memory allocation for Pro... |
| CVE-2009-4236 | — | — | 1.5% | Dec 8, 2009 | The process function in data/class/pages/admin/customer/LC_Page_Admin_Customer_SearchCustomer.php in EC-CUBE Ver2 2.4.0 ... |
| CVE-2009-3844 | — | — | 74.1% | Dec 8, 2009 | Stack-based buffer overflow in the OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and ... |
| CVE-2009-1569 | — | — | 37.5% | Dec 8, 2009 | Multiple stack-based buffer overflows in Novell iPrint Client 4.38, 5.30, and possibly other versions before 5.32 allow ... |
| CVE-2009-1568 | — | — | 32.2% | Dec 8, 2009 | Stack-based buffer overflow in ienipp.ocx in Novell iPrint Client 5.30, and possibly other versions before 5.32, allows ... |
| CVE-2009-1298 | — | — | 3.9% | Dec 8, 2009 | The ip_frag_reasm function in net/ipv4/ip_fragment.c in the Linux kernel 2.6.32-rc8, and 2.6.29 and later versions befor... |
| CVE-2009-4235 | — | — | 0.3% | Dec 8, 2009 | acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, a... |
| CVE-2009-4234 | — | — | 1.3% | Dec 8, 2009 | Cross-site scripting (XSS) vulnerability in loginpages/error_user.shtml on the Micronet Network Access Controller SP1910... |
| CVE-2009-4233 | — | — | 1.0% | Dec 8, 2009 | Cross-site scripting (XSS) vulnerability in modules/mod_yj_whois.php in the YJ Whois component 1.0x and 1.5.x for Joomla... |
| CVE-2009-4232 | — | — | 1.0% | Dec 8, 2009 | The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote a... |
| CVE-2009-4231 | — | — | 2.3% | Dec 8, 2009 | Directory traversal vulnerability in as/lib/plugins.php in SweetRice 0.5.3 and earlier allows remote attackers to includ... |
| CVE-2009-4230 | — | — | 2.9% | Dec 8, 2009 | Multiple stack-based buffer overflows in src/Task.cc in the FastCGI program in IIPImage Server before 0.9.8 might allow ... |
| CVE-2009-4229 | — | — | 0.9% | Dec 8, 2009 | Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now