2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-2734——SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote at...
CVE-2009-2733——Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary w...
CVE-2009-3699——Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through ...
CVE-2009-3030——Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and ear...
CVE-2009-3029——Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1....
CVE-2009-3698——An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of servic...
CVE-2009-3126——Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2...
CVE-2009-2999——The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application res...
CVE-2009-2532——Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t...
CVE-2009-2531——Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers...
CVE-2009-2530——Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers...
CVE-2009-2528——GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows r...
CVE-2009-2527——Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (...
CVE-2009-2526——Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets...
CVE-2009-2525——Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Com...
CVE-2009-2524——Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Micros...
CVE-2009-2518——Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office docu...
CVE-2009-2517——The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition ...
CVE-2009-2515——Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2...
CVE-2009-2511——Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 S...
CVE-2009-2510——The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Go...
CVE-2009-2507——A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 doe...
CVE-2009-2504——Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and S...
CVE-2009-2503——GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 S...
CVE-2009-2501——Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now