2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3292 | — | — | 2.8% | Sep 22, 2009 | Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to... |
| CVE-2009-3291 | — | — | 2.9% | Sep 22, 2009 | The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation... |
| CVE-2009-3290 | — | — | 0.4% | Sep 22, 2009 | The kvm_emulate_hypercall function in arch/x86/kvm/x86.c in KVM in the Linux kernel 2.6.25-rc1, and other versions befor... |
| CVE-2009-3288 | — | — | 0.4% | Sep 22, 2009 | The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect vari... |
| CVE-2009-3287 | — | — | 1.4% | Sep 22, 2009 | lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address ... |
| CVE-2009-3286 | — | — | 0.5% | Sep 22, 2009 | NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create... |
| CVE-2009-3284 | — | — | 1.5% | Sep 22, 2009 | Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder,... |
| CVE-2009-3283 | — | — | 1.0% | Sep 22, 2009 | Cross-site scripting (XSS) vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_B... |
| CVE-2009-3280 | — | — | 3.2% | Sep 21, 2009 | Integer signedness error in the find_ie function in net/wireless/scan.c in the cfg80211 subsystem in the Linux kernel be... |
| CVE-2009-3279 | — | — | 0.4% | Sep 21, 2009 | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create a LUKS partition by using... |
| CVE-2009-3277 | — | — | 1.0% | Sep 21, 2009 | DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial o... |
| CVE-2009-3276 | — | — | 1.0% | Sep 21, 2009 | Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows con... |
| CVE-2009-3275 | — | — | 3.5% | Sep 21, 2009 | Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Libr... |
| CVE-2009-3274 | — | — | 0.3% | Sep 21, 2009 | Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux u... |
| CVE-2009-3273 | — | — | 0.9% | Sep 21, 2009 | iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-... |
| CVE-2009-3272 | — | — | 6.4% | Sep 21, 2009 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2,... |
| CVE-2009-3271 | — | — | 4.2% | Sep 21, 2009 | Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel:... |
| CVE-2009-3200 | — | — | 0.4% | Sep 21, 2009 | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery ... |
| CVE-2009-2939 | — | — | 0.5% | Sep 21, 2009 | The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write acces... |
| CVE-2009-2744 | — | — | 2.5% | Sep 21, 2009 | Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause... |
| CVE-2009-2743 | — | — | 0.4% | Sep 21, 2009 | IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exceptio... |
| CVE-2009-2742 | — | — | 1.6% | Sep 21, 2009 | Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 a... |
| CVE-2009-2140 | — | — | 5.7% | Sep 21, 2009 | Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, prev... |
| CVE-2009-3270 | — | — | 28.2% | Sep 18, 2009 | Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable brow... |
| CVE-2009-3269 | — | — | 2.2% | Sep 18, 2009 | Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now