Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-4151

Published Dec 2, 2009

Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4027

Published Dec 2, 2009

Race condition in the mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (system crash) via a Delete Block…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4026

Published Dec 2, 2009

The mac80211 subsystem in the Linux kernel before 2.6.32-rc8-next-20091201 allows remote attackers to cause a denial of service (panic) via a crafted Delete Block ACK (aka DELBA)…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3585

Published Dec 2, 2009

Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows remote attackers to hijack web…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2686

Published Dec 2, 2009

Unspecified vulnerability in HP NonStop G06.12.00 through G06.32.00, H06.08.00 through H06.18.01, and J06.04.00 through J06.07.01 allows local users to gain privileges, cause a de…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4150

Published Dec 2, 2009

dasauto in IBM DB2 8 before FP18, 9.1 before FP8, 9.5 before FP4, and 9.7 before FP1 permits execution by unprivileged user accounts, which has unspecified impact and local attack…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4055

Published Dec 2, 2009

rtp.c in Asterisk Open Source 1.2.x before 1.2.37, 1.4.x before 1.4.27.1, 1.6.0.x before 1.6.0.19, and 1.6.1.x before 1.6.1.11; Business Edition B.x.x before B.2.5.13, C.2.x.x bef…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4128

Published Dec 1, 2009

GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for physically proximate attackers to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-2626

Published Dec 1, 2009

The zend_restore_ini_entry_cb function in zend_ini.c in PHP 5.3.0, 5.2.10, and earlier versions allows context-specific attackers to obtain sensitive information (memory contents)…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4120

Published Dec 1, 2009

Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authentication of the administrator for requests that (1) delete…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4118

Published Dec 1, 2009

The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0100 does not properly handle an ERROR_FAILED_SERVICE_CONTRO…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4117

Published Dec 1, 2009

Multiple stack-based buffer overflows in pdf_shade4.c in MuPDF before commit 20091125231942, as used in SumatraPDF before 1.0.1, allow remote attackers to cause a denial of servic…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4116

Published Nov 30, 2009

Multiple directory traversal vulnerabilities in CutePHP CuteNews 1.4.6, when magic_quotes_gpc is disabled, allow remote authenticated users with editor or administrative applicati…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4115

Published Nov 30, 2009

Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to in…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4114

Published Nov 30, 2009

kl1.sys in Kaspersky Anti-Virus 2010 9.0.0.463, and possibly other versions before 9.0.0.736, does not properly validate input to IOCTL 0x0022c008, which allows local users to cau…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4113

Published Nov 30, 2009

Static code injection vulnerability in the Categories module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote authenticated users with application administrati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4112

Published Nov 30, 2009

Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memory Usage" setting to contain a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4030

Published Nov 30, 2009

MySQL 5.1.x before 5.1.41 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY a…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4028

Published Nov 30, 2009

The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 ce…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4019

Published Nov 30, 2009

mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) pre…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7247

Published Nov 30, 2009

sql/sql_table.cc in MySQL 5.0.x through 5.0.88, 5.1.x through 5.1.41, and 6.0 before 6.0.9-alpha, when the data home directory contains a symlink to a different filesystem, allows…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4110

Published Nov 29, 2009

Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search term…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 5,732 CVEsPage 18 of 230