2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2734 | — | — | 1.3% | Oct 16, 2009 | SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote at... |
| CVE-2009-2733 | — | — | 2.3% | Oct 16, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary w... |
| CVE-2009-3699 | — | — | 62.1% | Oct 15, 2009 | Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through ... |
| CVE-2009-3030 | — | — | 1.3% | Oct 15, 2009 | Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and ear... |
| CVE-2009-3029 | — | — | 1.0% | Oct 15, 2009 | Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1.... |
| CVE-2009-3698 | — | — | 1.5% | Oct 14, 2009 | An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of servic... |
| CVE-2009-3126 | — | — | 23.5% | Oct 14, 2009 | Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2... |
| CVE-2009-2999 | — | — | 1.5% | Oct 14, 2009 | The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application res... |
| CVE-2009-2532 | — | — | 62.2% | Oct 14, 2009 | Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t... |
| CVE-2009-2531 | — | — | 22.9% | Oct 14, 2009 | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers... |
| CVE-2009-2530 | — | — | 22.9% | Oct 14, 2009 | Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers... |
| CVE-2009-2528 | — | — | 20.5% | Oct 14, 2009 | GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows r... |
| CVE-2009-2527 | — | — | 26.9% | Oct 14, 2009 | Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (... |
| CVE-2009-2526 | — | — | 81.9% | Oct 14, 2009 | Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets... |
| CVE-2009-2525 | — | — | 23.3% | Oct 14, 2009 | Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Com... |
| CVE-2009-2524 | — | — | 28.3% | Oct 14, 2009 | Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Micros... |
| CVE-2009-2518 | — | — | 22.6% | Oct 14, 2009 | Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office docu... |
| CVE-2009-2517 | — | — | 1.8% | Oct 14, 2009 | The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition ... |
| CVE-2009-2515 | — | — | 1.5% | Oct 14, 2009 | Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2... |
| CVE-2009-2511 | — | — | 13.0% | Oct 14, 2009 | Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 S... |
| CVE-2009-2510 | — | — | 5.3% | Oct 14, 2009 | The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Go... |
| CVE-2009-2507 | — | — | 19.3% | Oct 14, 2009 | A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 doe... |
| CVE-2009-2504 | — | — | 21.0% | Oct 14, 2009 | Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and S... |
| CVE-2009-2503 | — | — | 22.2% | Oct 14, 2009 | GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 S... |
| CVE-2009-2501 | — | — | 26.8% | Oct 14, 2009 | Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now