2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-4186 | — | — | 6.5% | Dec 3, 2009 | Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (a... |
| CVE-2009-1567 | — | — | 4.8% | Dec 3, 2009 | Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6,... |
| CVE-2009-0895 | — | — | 6.8% | Dec 3, 2009 | Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to e... |
| CVE-2009-4175 | — | — | 2.8% | Dec 2, 2009 | CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an inval... |
| CVE-2009-4174 | — | — | 1.6% | Dec 2, 2009 | The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows re... |
| CVE-2009-4173 | — | — | 1.0% | Dec 2, 2009 | Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote att... |
| CVE-2009-4172 | — | — | 1.6% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_... |
| CVE-2009-4171 | — | — | 5.1% | Dec 2, 2009 | An ActiveX control in YahooBridgeLib.dll for Yahoo! Messenger 9.0.0.2162, and possibly other 9.0 versions, allows remote... |
| CVE-2009-4147 | — | — | 3.7% | Dec 2, 2009 | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear t... |
| CVE-2009-4127 | — | — | 4.1% | Dec 2, 2009 | Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attacker... |
| CVE-2009-4170 | — | — | 6.4% | Dec 2, 2009 | WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive informat... |
| CVE-2009-4169 | — | — | 1.8% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in wp-cumulus.php in the WP-Cumulus Plug-in before 1.22 for WordPress allows re... |
| CVE-2009-4168 | — | — | 5.5% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for Wor... |
| CVE-2009-4146 | — | — | 3.9% | Dec 2, 2009 | The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not c... |
| CVE-2009-4167 | — | — | 1.1% | Dec 2, 2009 | Unspecified vulnerability in the Automatic Base Tags for RealUrl (lt_basetag) extension 1.0.0 for TYPO3 allows remote at... |
| CVE-2009-4166 | — | — | 1.0% | Dec 2, 2009 | SQL injection vulnerability in the Trips (mchtrips) extension 2.0.0 for TYPO3 allows remote attackers to execute arbitra... |
| CVE-2009-4165 | — | — | 1.0% | Dec 2, 2009 | SQL injection vulnerability in the simple Glossar (simple_glossar) extension 1.0.3 and earlier for TYPO3 allows remote a... |
| CVE-2009-4164 | — | — | 0.9% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in the simple Glossar (simple_glossar) extension 1.0.3 and earlier for TYPO3 al... |
| CVE-2009-4163 | — | — | 1.0% | Dec 2, 2009 | SQL injection vulnerability in the TW Productfinder (tw_productfinder) extension 0.0.2 and earlier for TYPO3 allows remo... |
| CVE-2009-4162 | — | — | 0.3% | Dec 2, 2009 | Unspecified vulnerability in the DB Integration (wfqbe) extension 1.3.1 and earlier for TYPO3 allows local users to exec... |
| CVE-2009-4161 | — | — | 0.8% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in the [AN] Search it! (an_searchit) extension 2.4.1 and earlier for TYPO3 allo... |
| CVE-2009-4160 | — | — | 1.2% | Dec 2, 2009 | Unspecified vulnerability in the Simple download-system with counter and categories (kk_downloader) extension 1.2.1 and ... |
| CVE-2009-4159 | — | — | 0.8% | Dec 2, 2009 | Cross-site scripting (XSS) vulnerability in the newsletter configuration feature in the backend module in the Direct Mai... |
| CVE-2009-4158 | — | — | 1.1% | Dec 2, 2009 | SQL injection vulnerability in the Calendar Base (cal) extension before 1.2.1 for TYPO3 allows remote attackers to execu... |
| CVE-2009-4157 | — | — | 1.2% | Dec 2, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in the ProofReader (com_proofreader) component 1.0 RC9 ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now