2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3752 | — | — | 1.0% | Oct 22, 2009 | SQL injection vulnerability in home.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands via the g... |
| CVE-2009-3751 | — | — | 1.5% | Oct 22, 2009 | Cross-site scripting (XSS) vulnerability in home.php in Opial 1.0 allows remote attackers to inject arbitrary web script... |
| CVE-2009-3750 | — | — | 1.0% | Oct 22, 2009 | SQL injection vulnerability in read.php in ToyLog 0.1 allows remote attackers to execute arbitrary SQL commands via the ... |
| CVE-2009-3749 | — | — | 7.6% | Oct 22, 2009 | The Web Administrator service (STEMWADM.EXE) in Websense Personal Email Manager 7.1 before Hotfix 4 and Email Security 7... |
| CVE-2009-3748 | — | — | 3.5% | Oct 22, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the Web Administrator in Websense Personal Email Manager 7.1 befo... |
| CVE-2009-3747 | — | — | 1.5% | Oct 22, 2009 | Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web s... |
| CVE-2009-3746 | — | — | 0.3% | Oct 22, 2009 | XScreenSaver in Sun Solaris 10, when the accessibility feature is enabled, allows physically proximate attackers to obta... |
| CVE-2009-2943 | — | — | 2.2% | Oct 22, 2009 | The postgresql-ocaml bindings 1.5.4, 1.7.0, and 1.12.1 for PostgreSQL libpq do not properly support the PQescapeStringCo... |
| CVE-2009-2942 | — | — | 2.3% | Oct 22, 2009 | The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allo... |
| CVE-2009-2940 | — | — | 2.7% | Oct 22, 2009 | The pygresql module 3.8.1 and 4.0 for Python does not properly support the PQescapeStringConn function, which might allo... |
| CVE-2009-2911 | — | — | 0.5% | Oct 22, 2009 | SystemTap 1.0, when the --unprivileged option is used, does not properly restrict certain data sizes, which allows local... |
| CVE-2009-3745 | — | — | 1.3% | Oct 22, 2009 | Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows rem... |
| CVE-2009-3744 | — | — | 7.3% | Oct 22, 2009 | rep_serv.exe 6.3.1.3 in the server in EMC RepliStor allows remote attackers to cause a denial of service via a crafted p... |
| CVE-2009-3621 | MEDIUM | 5.5 | 1.0% | Oct 22, 2009 | net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang... |
| CVE-2009-3620 | HIGH | 7.8 | 0.4% | Oct 22, 2009 | The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command E... |
| CVE-2009-1479 | — | — | 2.4% | Oct 22, 2009 | Directory traversal vulnerability in client/desktop/default.htm in Boxalino before 09.05.25-0421 allows remote attackers... |
| CVE-2009-3609 | — | — | 4.5% | Oct 21, 2009 | Integer overflow in the ImageStream::ImageStream function in Stream.cc in Xpdf before 3.02pl4 and Poppler before 0.12.1,... |
| CVE-2009-3608 | — | — | 10.2% | Oct 21, 2009 | Integer overflow in the ObjectStream::ObjectStream function in XRef.cc in Xpdf 3.x before 3.02pl4 and Poppler before 0.1... |
| CVE-2009-3607 | — | — | 5.9% | Oct 21, 2009 | Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote... |
| CVE-2009-3606 | — | — | 8.6% | Oct 21, 2009 | Integer overflow in the PSOutputDev::doImageL1Sep function in Xpdf before 3.02pl4, and Poppler 0.x, as used in kdegraphi... |
| CVE-2009-3604 | — | — | 8.7% | Oct 21, 2009 | The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kde... |
| CVE-2009-3603 | — | — | 8.6% | Oct 21, 2009 | Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might a... |
| CVE-2009-3730 | — | — | 3.5% | Oct 20, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM R... |
| CVE-2009-3617 | — | — | 4.9% | Oct 20, 2009 | Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, wh... |
| CVE-2009-3615 | — | — | 2.7% | Oct 20, 2009 | The OSCAR protocol plugin in libpurple in Pidgin before 2.6.3 and Adium before 1.3.7 allows remote attackers to cause a ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now