2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2009-10004MEDIUM6.1A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the ...
CVE-2009-10003MEDIUM6.1A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an ...
CVE-2009-10002MEDIUM6.1A vulnerability, which was classified as problematic, has been found in dpup fittr-flickr. This issue affects some unkno...
CVE-2009-10001MEDIUM6.1A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects...
CVE-2009-1142MEDIUM6.7An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp...
CVE-2009-5159MEDIUM6.1Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt at...
CVE-2009-4067MEDIUM6.8Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 all...
CVE-2009-3724MEDIUM6.1python-markdown2 before 1.0.1.14 has multiple cross-site scripting (XSS) issues.
CVE-2009-5004MEDIUM6.5qpid-cpp 1.0 crashes when a large message is sent and the Digest-MD5 mechanism with a security layer is in use .
CVE-2009-2802MEDIUM6.1MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could l...
CVE-2009-0035MEDIUM5.5alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/b...
CVE-2009-5046MEDIUM6.1JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.
CVE-2009-5049MEDIUM6.1WebApp JSP Snoop page XSS in jetty though 6.1.21.
CVE-2009-5048MEDIUM6.1Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.
CVE-2009-4900MEDIUM6.1pixelpost 1.7.1 has XSS
CVE-2009-4139MEDIUM6.8A flaw was found in Spacewalk Java site packages. This cross-site request forgery (CSRF) vulnerability allows a remote a...
CVE-2009-4895MEDIUM4.7Race condition in the tty_fasync function in drivers/char/tty_io.c in the Linux kernel before 2.6.32.6 allows local user...
CVE-2009-3960MEDIUM6.5Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service...
CVE-2009-4449MEDIUM6.5Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the...
CVE-2009-3897MEDIUM5.5Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allo...
CVE-2009-4053MEDIUM6.5Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) creat...
CVE-2009-3621MEDIUM5.5net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang...
CVE-2009-3278MEDIUM5.5The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to...
CVE-2009-3238MEDIUM5.5The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random nu...
CVE-2009-3022MEDIUM6.5Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authe...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now