2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2818 | — | — | 1.9% | Nov 10, 2009 | Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, whic... |
| CVE-2009-2810 | — | — | 2.9% | Nov 10, 2009 | Launch Services in Apple Mac OS X 10.6.x before 10.6.2 recursively clears quarantine information upon opening a quaranti... |
| CVE-2009-2808 | — | — | 0.6% | Nov 10, 2009 | Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web s... |
| CVE-2009-3727 | — | — | 4.2% | Nov 10, 2009 | Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Bu... |
| CVE-2009-3924 | — | — | 4.0% | Nov 10, 2009 | Buffer overflow in pbsv.dll, as used in Soldier of Fortune II and possibly other applications when Even Balance PunkBust... |
| CVE-2009-3619 | — | — | 1.8% | Nov 10, 2009 | Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors r... |
| CVE-2009-3618 | — | — | 1.6% | Nov 10, 2009 | Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote atta... |
| CVE-2009-3610 | — | — | — | Nov 10, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-3695. Reason: This candidate is a duplicate of... |
| CVE-2009-3923 | — | — | 2.4% | Nov 10, 2009 | The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authenticat... |
| CVE-2009-3886 | — | — | 1.7% | Nov 9, 2009 | The Java Web Start implementation in Sun Java SE 6 before Update 17 does not properly handle the interaction between a s... |
| CVE-2009-3885 | — | — | 2.2% | Nov 9, 2009 | Sun Java SE 5.0 before Update 22 and 6 before Update 17 on Windows allows remote attackers to cause a denial of service ... |
| CVE-2009-3884 | — | — | 3.0% | Nov 9, 2009 | The TimeZone.getTimeZone method in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, allows remote a... |
| CVE-2009-3883 | — | — | 2.0% | Nov 9, 2009 | Multiple unspecified vulnerabilities in the Windows Pluggable Look and Feel (PL&F) feature in the Swing implementation i... |
| CVE-2009-3882 | — | — | 2.0% | Nov 9, 2009 | Multiple unspecified vulnerabilities in the Swing implementation in Sun Java SE 5.0 before Update 22 and 6 before Update... |
| CVE-2009-3881 | — | — | 2.7% | Nov 9, 2009 | Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not prevent the existence of children of a re... |
| CVE-2009-3880 | — | — | 1.8% | Nov 9, 2009 | The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Upd... |
| CVE-2009-3879 | — | — | 2.3% | Nov 9, 2009 | Multiple unspecified vulnerabilities in the (1) X11 and (2) Win32GraphicsDevice subsystems in Sun Java SE 5.0 before Upd... |
| CVE-2009-3729 | — | — | 2.5% | Nov 9, 2009 | Unspecified vulnerability in the TrueType font parsing functionality in Sun Java SE 5.0 before Update 22 and 6 before Up... |
| CVE-2009-3728 | — | — | 3.8% | Nov 9, 2009 | Directory traversal vulnerability in the ICC_Profile.getInstance method in Java Runtime Environment (JRE) in Sun Java SE... |
| CVE-2009-3726 | — | — | 12.0% | Nov 9, 2009 | The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote... |
| CVE-2009-3922 | — | — | 0.7% | Nov 9, 2009 | Multiple cross-site request forgery (CSRF) vulnerabilities in the User Protect module 5.x before 5.x-1.4 and 6.x before ... |
| CVE-2009-3921 | — | — | 1.2% | Nov 9, 2009 | The Smartqueue_og module 5.x before 5.x-1.3 and 6.x before 6.x-1.0-rc3, a module for Drupal, does not verify group-node ... |
| CVE-2009-3920 | — | — | 1.4% | Nov 9, 2009 | An administration page in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal does not perform th... |
| CVE-2009-3919 | — | — | 1.2% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal a... |
| CVE-2009-3918 | — | — | 1.3% | Nov 9, 2009 | Cross-site scripting (XSS) vulnerability in the Zoomify module 5.x before 5.x-2.2 and 6.x before 6.x-1.4, a module for D... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now