2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-5026 | — | — | 7.8% | Aug 17, 2012 | The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave confi... |
| CVE-2009-5066 | — | — | 0.4% | Aug 13, 2012 | twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local use... |
| CVE-2009-5031 | — | — | 2.9% | Jul 22, 2012 | ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attacke... |
| CVE-2009-5030 | — | — | 4.1% | Jul 18, 2012 | The tcd_free_encode function in tcd.c in OpenJPEG 1.3 through 1.5 allows remote attackers to cause a denial of service (... |
| CVE-2009-0695 | — | — | 69.6% | Jun 19, 2012 | hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker... |
| CVE-2009-0693 | — | — | 13.1% | Jun 19, 2012 | Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) th... |
| CVE-2009-5114 | — | — | 13.7% | Mar 19, 2012 | Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbit... |
| CVE-2009-5113 | — | — | 1.0% | Mar 19, 2012 | Cross-site scripting (XSS) vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to inj... |
| CVE-2009-5112 | — | — | 5.4% | Mar 19, 2012 | wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted requ... |
| CVE-2009-5111 | — | — | 1.2% | Dec 27, 2011 | GoAhead WebServer allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as dem... |
| CVE-2009-5110 | — | — | 1.3% | Dec 27, 2011 | dhttpd allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated b... |
| CVE-2009-5109 | — | — | 32.9% | Dec 25, 2011 | Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e... |
| CVE-2009-5028 | — | — | 4.5% | Nov 30, 2011 | Stack-based buffer overflow in Namazu before 2.0.20 allows remote attackers to cause a denial of service (daemon crash) ... |
| CVE-2009-0905 | — | — | 0.2% | Oct 30, 2011 | IBM WebSphere MQ 6.0 before 6.0.2.8 and 7.0 before 7.0.1.0 does not properly handle long group names, which might allow ... |
| CVE-2009-0900 | — | — | 0.3% | Oct 30, 2011 | Heap-based buffer overflow in the client in IBM WebSphere MQ 6.0 before 6.0.2.7 and 7.0 before 7.0.1.0 allows local user... |
| CVE-2009-2748 | — | — | 1.7% | Oct 30, 2011 | Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.1 bef... |
| CVE-2009-2747 | — | — | 1.9% | Oct 30, 2011 | The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2... |
| CVE-2009-5103 | — | — | 2.6% | Oct 21, 2011 | Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web sc... |
| CVE-2009-5102 | — | — | 2.0% | Oct 21, 2011 | SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL... |
| CVE-2009-5101 | — | — | 1.1% | Sep 13, 2011 | Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obta... |
| CVE-2009-5100 | — | — | 0.4% | Sep 13, 2011 | Pentaho BI Server 1.7.0.1062 and earlier does not set the autocomplete tag to off on web pages using a password field, w... |
| CVE-2009-5099 | — | — | 1.1% | Sep 13, 2011 | Cross-site scripting (XSS) vulnerability in ViewAction in Pentaho BI Server 1.7.0.1062 and earlier allows remote attacke... |
| CVE-2009-5098 | — | — | 4.0% | Sep 13, 2011 | The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote at... |
| CVE-2009-5097 | — | — | 1.9% | Sep 13, 2011 | Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrar... |
| CVE-2009-5096 | — | — | 1.3% | Sep 13, 2011 | Cross-site scripting (XSS) vulnerability in the Flag Content module 5.x-2.x before 5.x-2.10 for Drupal allows remote att... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now