2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2009-20008HIGH8.6Green Dam Youth Escort version 3.17 is vulnerable to a stack-based buffer overflow when processing overly long URLs. The...
CVE-2009-20004HIGH8.4gAlan 0.2.1, a modular audio processing environment for Windows, is vulnerable to a stack-based buffer overflow when par...
CVE-2009-20003HIGH8.4Xenorate versions up to and including 2.50, a Windows-based multimedia player, is vulnerable to a stack-based buffer ove...
CVE-2009-20002HIGH8.4Millenium MP3 Studio versions up to and including 2.0 is vulnerable to a stack-based buffer overflow when parsing .pls p...
CVE-2009-10005HIGH8.7ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 expose the mimencode binary via...
CVE-2009-4123HIGH7.5The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
CVE-2009-1143HIGH7An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can bypass intended access restrictions on mount...
CVE-2009-3721HIGH7.8Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parse...
CVE-2009-20001HIGH8.1An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is n...
CVE-2009-5140HIGH8.8The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid auth...
CVE-2009-5139HIGH7.5The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authenticati...
CVE-2009-5068HIGH7.2There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some confi...
CVE-2009-5025HIGH7.5A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a p...
CVE-2009-4011HIGH8.1dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX ...
CVE-2009-5045HIGH7.5Dump Servlet information leak in jetty before 6.1.22.
CVE-2009-5050HIGH7.5konversation before 1.2.3 allows attackers to cause a denial of service.
CVE-2009-3723HIGH7.5asterisk allows calls on prohibited networks
CVE-2009-4272HIGH7.5A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remo...
CVE-2009-3953HIGH8.8The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor...
CVE-2009-3791HIGH7.5Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to cause a denial of service (...
CVE-2009-4324HIGH7.8Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before ...
CVE-2009-3671HIGH8.1Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit...
CVE-2009-4194HIGH8.1Directory traversal vulnerability in Golden FTP Server 4.30 Free and Professional, 4.50, and possibly other versions all...
CVE-2009-4004HIGH7.8Buffer overflow in the kvm_vcpu_ioctl_x86_setup_mce function in arch/x86/kvm/x86.c in the KVM subsystem in the Linux ker...
CVE-2009-3553HIGH7.5Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in schedul...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now