2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3480 | — | — | 1.1% | Sep 30, 2009 | SQL injection vulnerability in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! allows remote attackers to ... |
| CVE-2009-3479 | — | — | 1.1% | Sep 30, 2009 | Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module f... |
| CVE-2009-3478 | — | — | 1.3% | Sep 29, 2009 | Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocke... |
| CVE-2009-3477 | — | — | 0.6% | Sep 29, 2009 | The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.... |
| CVE-2009-3476 | — | — | 4.1% | Sep 29, 2009 | Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, a... |
| CVE-2009-3475 | — | — | 0.9% | Sep 29, 2009 | Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation... |
| CVE-2009-3474 | — | — | 1.5% | Sep 29, 2009 | OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2... |
| CVE-2009-3473 | — | — | 2.0% | Sep 29, 2009 | IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which ... |
| CVE-2009-3472 | — | — | 2.0% | Sep 29, 2009 | IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access re... |
| CVE-2009-3471 | — | — | 2.4% | Sep 29, 2009 | IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP2 does not perform the expected drops of certain... |
| CVE-2009-3470 | — | — | 2.2% | Sep 29, 2009 | IBM Informix Dynamic Server (IDS) 10.00 before 10.00.xC11, 11.10 before 11.10.xC4, and 11.50 before 11.50.xC5 allows rem... |
| CVE-2009-3469 | — | — | 3.7% | Sep 29, 2009 | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote a... |
| CVE-2009-3468 | — | — | 0.4% | Sep 29, 2009 | Multiple unspecified vulnerabilities in Common Desktop Environment (CDE) in Sun Solaris 10, when Trusted Extensions is e... |
| CVE-2009-2905 | — | — | 0.5% | Sep 29, 2009 | Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of servi... |
| CVE-2009-3457 | — | — | 4.2% | Sep 29, 2009 | Cisco ACE XML Gateway (AXG) and ACE Web Application Firewall (WAF) before 6.1 allow remote attackers to obtain sensitive... |
| CVE-2009-3456 | — | — | 0.4% | Sep 29, 2009 | Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subjec... |
| CVE-2009-3455 | — | — | 0.6% | Sep 29, 2009 | Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subje... |
| CVE-2009-3454 | — | — | — | Sep 29, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-2510. Reason: This candidate is a duplicate of... |
| CVE-2009-3453 | — | — | 1.3% | Sep 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1.0 services for WebSphere Portal allow remote... |
| CVE-2009-2683 | — | — | 3.0% | Sep 29, 2009 | Unspecified vulnerability in the Sender module in HP Remote Graphics Software (RGS) 5.1.3 through 5.2.6 allows remote au... |
| CVE-2009-2681 | — | — | 0.3% | Sep 29, 2009 | Unspecified vulnerability in HP ProCurve Identity Driven Manager (IDM) A.02.x through A.02.03 and A.03.x through A.03.00... |
| CVE-2009-3452 | — | — | 1.3% | Sep 29, 2009 | WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via uns... |
| CVE-2009-3451 | — | — | 1.6% | Sep 29, 2009 | Directory traversal vulnerability in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to... |
| CVE-2009-3450 | — | — | 1.9% | Sep 29, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allow re... |
| CVE-2009-3449 | — | — | 1.9% | Sep 29, 2009 | MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u play... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now