2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-3278 | MEDIUM | 5.5 | 0.4% | Sep 21, 2009 | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to... |
| CVE-2009-3277 | — | — | 1.0% | Sep 21, 2009 | DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial o... |
| CVE-2009-3276 | — | — | 1.0% | Sep 21, 2009 | Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows con... |
| CVE-2009-3275 | — | — | 3.5% | Sep 21, 2009 | Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Libr... |
| CVE-2009-3274 | — | — | 0.3% | Sep 21, 2009 | Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux u... |
| CVE-2009-3273 | — | — | 0.9% | Sep 21, 2009 | iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-... |
| CVE-2009-3272 | — | — | 6.4% | Sep 21, 2009 | Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2,... |
| CVE-2009-3271 | — | — | 4.2% | Sep 21, 2009 | Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel:... |
| CVE-2009-3200 | — | — | 0.4% | Sep 21, 2009 | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery ... |
| CVE-2009-2939 | — | — | 0.5% | Sep 21, 2009 | The postfix.postinst script in the Debian GNU/Linux and Ubuntu postfix 2.5.5 package grants the postfix user write acces... |
| CVE-2009-2744 | — | — | 2.5% | Sep 21, 2009 | Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause... |
| CVE-2009-2743 | — | — | 0.4% | Sep 21, 2009 | IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exceptio... |
| CVE-2009-2742 | — | — | 1.6% | Sep 21, 2009 | Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 a... |
| CVE-2009-2140 | — | — | 5.7% | Sep 21, 2009 | Multiple heap-based buffer overflows in cppcanvas/source/mtfrenderer/emfplus.cxx in Go-oo 2.x and 3.x before 3.0.1, prev... |
| CVE-2009-3270 | — | — | 28.2% | Sep 18, 2009 | Microsoft Internet Explorer 7 through 7.0.6000.16711 allows remote attackers to cause a denial of service (unusable brow... |
| CVE-2009-3269 | — | — | 2.2% | Sep 18, 2009 | Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic ... |
| CVE-2009-3268 | — | — | 0.8% | Sep 18, 2009 | Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an autom... |
| CVE-2009-3267 | — | — | 15.9% | Sep 18, 2009 | Microsoft Internet Explorer 6 through 6.0.2900.2180, and 7.0.6000.16711, allows remote attackers to cause a denial of se... |
| CVE-2009-3266 | — | — | 2.7% | Sep 18, 2009 | Opera before 10.01 does not properly restrict HTML in a (1) RSS or (2) Atom feed, which allows remote attackers to condu... |
| CVE-2009-3265 | — | — | 1.7% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTM... |
| CVE-2009-3264 | — | — | 3.5% | Sep 18, 2009 | The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote we... |
| CVE-2009-3263 | — | — | 1.4% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in Google Chrome 2.x and 3.x before 3.0.195.21 allows remote attackers to injec... |
| CVE-2009-2793 | — | — | 0.5% | Sep 18, 2009 | The kernel in NetBSD, probably 5.0.1 and earlier, on x86 platforms does not properly handle a pre-commit failure of the ... |
| CVE-2009-2741 | — | — | 3.3% | Sep 18, 2009 | Unspecified vulnerability in the wberuntimeear application in the test servlet in IBM WebSphere Business Events 6.1 and ... |
| CVE-2009-3262 | — | — | 0.8% | Sep 18, 2009 | Cross-site scripting (XSS) vulnerability in the Self Service UI (SSUI) in IBM Tivoli Identity Manager (ITIM) 5.0.0.5 all... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now