2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-3282Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause ...
CVE-2009-3281The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allow...
CVE-2009-2874The TimesTenD process in Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4) allows remote attackers to...
CVE-2009-2734SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote at...
CVE-2009-2733Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary w...
CVE-2009-3699Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through ...
CVE-2009-3030Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and ear...
CVE-2009-3029Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1....
CVE-2009-3698An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of servic...
CVE-2009-3126Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2...
CVE-2009-2999The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application res...
CVE-2009-2532Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t...
CVE-2009-2531Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers...
CVE-2009-2530Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers...
CVE-2009-2529HIGH8.1Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified va...
CVE-2009-2528GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows r...
CVE-2009-2527Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (...
CVE-2009-2526Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets...
CVE-2009-2525Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Com...
CVE-2009-2524Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Micros...
CVE-2009-2518Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office docu...
CVE-2009-2517The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition ...
CVE-2009-2516HIGH7.1The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does...
CVE-2009-2515Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2...
CVE-2009-2511Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 S...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now