2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-3282——Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause ...
CVE-2009-3281——The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allow...
CVE-2009-2874——The TimesTenD process in Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4) allows remote attackers to...
CVE-2009-2734——SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote at...
CVE-2009-2733——Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary w...
CVE-2009-3699——Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through ...
CVE-2009-3030——Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and ear...
CVE-2009-3029——Cross-site scripting (XSS) vulnerability in the console in Symantec SecurityExpressions Audit and Compliance Server 4.1....
CVE-2009-3698——An unspecified function in the Dalvik API in Android 1.5 and earlier allows remote attackers to cause a denial of servic...
CVE-2009-3126——Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2...
CVE-2009-2999——The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application res...
CVE-2009-2532——Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t...
CVE-2009-2531——Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers...
CVE-2009-2530——Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers...
CVE-2009-2529HIGH8.1Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified va...
CVE-2009-2528——GDI+ in Microsoft Office XP SP3 does not properly handle malformed objects in Office Art Property Tables, which allows r...
CVE-2009-2527——Heap-based buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via (...
CVE-2009-2526——Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets...
CVE-2009-2525——Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Com...
CVE-2009-2524——Integer underflow in the NTLM authentication feature in the Local Security Authority Subsystem Service (LSASS) in Micros...
CVE-2009-2518——Integer overflow in GDI+ in Microsoft Office XP SP3 allows remote attackers to execute arbitrary code via an Office docu...
CVE-2009-2517——The kernel in Microsoft Windows Server 2003 SP2 does not properly handle unspecified exceptions when an error condition ...
CVE-2009-2516HIGH7.1The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does...
CVE-2009-2515——Integer underflow in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2...
CVE-2009-2511——Integer overflow in the CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 S...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now