2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-10004 | MEDIUM | 6.1 | 0.5% | Apr 10, 2023 | A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the ... |
| CVE-2009-10003 | MEDIUM | 6.1 | 0.5% | Jan 29, 2023 | A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an ... |
| CVE-2009-10002 | MEDIUM | 6.1 | 0.5% | Jan 13, 2023 | A vulnerability, which was classified as problematic, has been found in dpup fittr-flickr. This issue affects some unkno... |
| CVE-2009-10001 | MEDIUM | 6.1 | 0.7% | Jan 13, 2023 | A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects... |
| CVE-2009-1142 | MEDIUM | 6.7 | 0.3% | Nov 23, 2022 | An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp... |
| CVE-2009-5159 | MEDIUM | 6.1 | 3.4% | Mar 13, 2020 | Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt at... |
| CVE-2009-4067 | MEDIUM | 6.8 | 2.1% | Feb 11, 2020 | Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 all... |
| CVE-2009-3724 | MEDIUM | 6.1 | 0.8% | Jan 15, 2020 | python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues. |
| CVE-2009-5004 | MEDIUM | 6.5 | 2.6% | Nov 9, 2019 | qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use . |
| CVE-2009-2802 | MEDIUM | 6.1 | 0.9% | Nov 9, 2019 | MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could l... |
| CVE-2009-0035 | MEDIUM | 5.5 | 0.5% | Nov 9, 2019 | alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/b... |
| CVE-2009-5046 | MEDIUM | 6.1 | 1.6% | Nov 6, 2019 | JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22. |
| CVE-2009-5049 | MEDIUM | 6.1 | 1.6% | Nov 6, 2019 | WebApp JSP Snoop page XSS in jetty though 6.1.21. |
| CVE-2009-5048 | MEDIUM | 6.1 | 1.6% | Nov 6, 2019 | Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20. |
| CVE-2009-4900 | MEDIUM | 6.1 | 1.0% | Oct 28, 2019 | pixelpost 1.7.1 has XSS |
| CVE-2009-4139 | MEDIUM | 6.8 | 0.8% | Jul 27, 2011 | A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote a... |
| CVE-2009-4895 | MEDIUM | 4.7 | 0.3% | Sep 8, 2010 | Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local user... |
| CVE-2009-3960 | MEDIUM | 6.5 | 90.0% | Feb 15, 2010 | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service... |
| CVE-2009-4449 | MEDIUM | 6.5 | 2.7% | Dec 29, 2009 | Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the... |
| CVE-2009-3897 | MEDIUM | 5.5 | 0.4% | Nov 24, 2009 | Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allo... |
| CVE-2009-4053 | MEDIUM | 6.5 | 3.5% | Nov 23, 2009 | Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) creat... |
| CVE-2009-3621 | MEDIUM | 5.5 | 1.0% | Oct 22, 2009 | net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang... |
| CVE-2009-3278 | MEDIUM | 5.5 | 0.4% | Sep 21, 2009 | The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to... |
| CVE-2009-3238 | MEDIUM | 5.5 | 1.6% | Sep 18, 2009 | The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random nu... |
| CVE-2009-3022 | MEDIUM | 6.5 | 1.0% | Aug 31, 2009 | Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authe... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now