2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2009-10007CRITICAL9.1Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst...
CVE-2009-20007CRITICAL9.3Talkative IRC v0.4.4.16 is vulnerable to a stack-based buffer overflow when processing specially crafted response string...
CVE-2009-20006CRITICAL9.3osCommerce versions up to and including 2.2 RC2a contain a vulnerability in its administrative file manager utility (adm...
CVE-2009-20005CRITICAL9.3A stack-based buffer overflow exists in the UtilConfigHome.csp endpoint of InterSystems Caché 2009.1. The vulnerability ...
CVE-2009-20011CRITICAL10ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote comman...
CVE-2009-20010CRITICAL9.3Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail su...
CVE-2009-20009CRITICAL9.3Belkin Bulldog Plus version 4.0.2 build 1219 contains a stack-based buffer overflow vulnerability in its web service aut...
CVE-2009-10006CRITICAL9.3UFO: Alien Invasion versions up to and including 2.2.1 contain a buffer overflow vulnerability in its built-in IRC clien...
CVE-2009-0948CRITICAL9.8Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in fil...
CVE-2009-0947CRITICAL9.8Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.
CVE-2009-1120CRITICAL9.8EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists w...
CVE-2009-5043CRITICAL9.8burn allows file names to escape via mishandled quotation marks
CVE-2009-5042CRITICAL9.1python-docutils allows insecure usage of temporary files
CVE-2009-5041CRITICAL9.8overkill has buffer overflow via long player names that can corrupt data on the server machine
CVE-2009-3887CRITICAL9.8ytnef has directory traversal
CVE-2009-4899CRITICAL9.8pixelpost 1.7.1 has SQL injection
CVE-2009-4013CRITICAL9.8Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before ...
CVE-2009-4491CRITICAL9.8thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers ...
CVE-2009-4488CRITICAL9.8Varnish 2.0.6 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers ...
CVE-2009-4581CRITICAL9.8Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is dis...
CVE-2009-2512CRITICAL9.8The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not prope...
CVE-2009-3555CRITICAL9.8The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS...
CVE-2009-3616CRITICAL9.9Multiple use-after-free vulnerabilities in vnc.c in the VNC server in QEMU 0.10.6 and earlier might allow guest OS users...
CVE-2009-3421CRITICAL9.8login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authent...
CVE-2009-1048CRITICAL9.8The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before ...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now