2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2958 | — | — | 10.4% | Sep 2, 2009 | The tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, allows remote attackers to cause... |
| CVE-2009-2957 | — | — | 12.7% | Sep 2, 2009 | Heap-based buffer overflow in the tftp_request function in tftp.c in dnsmasq before 2.50, when --enable-tftp is used, mi... |
| CVE-2009-3042 | — | — | 3.0% | Sep 1, 2009 | SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attacke... |
| CVE-2009-3041 | — | — | 6.6% | Sep 1, 2009 | SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2... |
| CVE-2009-3040 | — | — | 1.4% | Sep 1, 2009 | Multiple SQL injection vulnerabilities in Open Computer and Software (OCS) Inventory NG 1.02 for Unix allow remote attac... |
| CVE-2009-3038 | — | — | 3.5% | Sep 1, 2009 | A certain ActiveX control in lnresobject.dll 7.1.1.119 in the Research In Motion (RIM) Lotus Notes connector for BlackBe... |
| CVE-2009-3037 | — | — | 5.7% | Sep 1, 2009 | Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes ... |
| CVE-2009-3026 | — | — | 1.3% | Aug 31, 2009 | protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL"... |
| CVE-2009-3025 | — | — | 1.9% | Aug 31, 2009 | Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Y... |
| CVE-2009-3024 | — | — | 1.0% | Aug 31, 2009 | The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through... |
| CVE-2009-3023 | — | — | 90.9% | Aug 31, 2009 | Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen... |
| CVE-2009-3022 | MEDIUM | 6.5 | 1.0% | Aug 31, 2009 | Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authe... |
| CVE-2009-3021 | — | — | 1.1% | Aug 31, 2009 | Cross-site scripting (XSS) vulnerability in Site Calendar 'mycaljp' plugin 2.0.0 through 2.0.6, as used in the Japanese ... |
| CVE-2009-2944 | — | — | 1.8% | Aug 31, 2009 | Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context... |
| CVE-2009-3020 | — | — | 16.7% | Aug 31, 2009 | win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by r... |
| CVE-2009-3019 | — | — | 17.4% | Aug 31, 2009 | Microsoft Internet Explorer 6 on Windows XP SP2 and SP3, and Internet Explorer 7 on Vista, allows remote attackers to ca... |
| CVE-2009-3018 | — | — | 1.1% | Aug 31, 2009 | Maxthon Browser 3.0.0.145 Alpha with Ultramode does not properly block javascript: and data: URIs in Refresh headers in ... |
| CVE-2009-3017 | — | — | 1.1% | Aug 31, 2009 | Orca Browser 1.2 build 5 does not properly block data: URIs in Refresh and Location headers in HTTP responses, which all... |
| CVE-2009-3016 | — | — | 1.1% | Aug 31, 2009 | Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows... |
| CVE-2009-3015 | — | — | 0.9% | Aug 31, 2009 | QtWeb 3.0 Builds 001 and 003 does not properly block javascript: and data: URIs in Refresh and Location headers in HTTP ... |
| CVE-2009-3014 | — | — | 1.0% | Aug 31, 2009 | Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do ... |
| CVE-2009-3013 | — | — | 1.7% | Aug 31, 2009 | Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP resp... |
| CVE-2009-3012 | — | — | 0.8% | Aug 31, 2009 | Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location heade... |
| CVE-2009-3011 | — | — | 0.9% | Aug 31, 2009 | Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in R... |
| CVE-2009-3010 | — | — | 1.9% | Aug 31, 2009 | Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now