Skip to main content

Year archive

CVEs published in 2009

Archive summary

5,732 CVEs published in 2009 — 1,013 Critical, 1,736 High, 2,786 Medium, 197 Low, 0 Unrated.

CVE-2009-0181

Published Jan 20, 2009

Buffer overflow in VUPlayer allows user-assisted attackers to have an unknown impact via a long file, as demonstrated by a file composed entirely of 'A' characters.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0180

Published Jan 20, 2009

Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to by…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0179

Published Jan 20, 2009

libmikmod 3.1.11 through 3.2.0, as used by MikMod and possibly other products, allows user-assisted attackers to cause a denial of service (application crash) by loading an XM fil…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0178

Published Jan 20, 2009

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5915

Published Jan 20, 2009

An unspecified function in the JavaScript implementation in Google Chrome creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it e…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5914

Published Jan 20, 2009

An unspecified function in the JavaScript implementation in Apple Safari creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it ea…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5913

Published Jan 20, 2009

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5912

Published Jan 20, 2009

An unspecified function in the JavaScript implementation in Microsoft Internet Explorer creates and exposes a "temporary footprint" when there is a current login to a web site, wh…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-4388

Published Jan 20, 2009

The LaunchObj ActiveX control before 5.2.2.865 in launcher.dll in Symantec AppStream Client 5.2.x before 5.2.2 SP3 MP1 does not properly validate downloaded files, which allows re…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2368

Published Jan 20, 2009

Red Hat Certificate System 7.2 stores passwords in cleartext in the UserDirEnrollment log, the RA wizard installer log, and unspecified other debug log files, and uses weak permis…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2367

Published Jan 20, 2009

Red Hat Certificate System 7.2 uses world-readable permissions for password.conf and unspecified other configuration files, which allows local users to discover passwords by readi…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6720

Published Jan 20, 2009

libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer, and possibly other products, relies on the channel count of the last loaded song, rather than the currently playing so…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0175

Published Jan 20, 2009

Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0174

Published Jan 20, 2009

Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0173

Published Jan 16, 2009

Unspecified vulnerability in the server in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote authenticated users to cause a denial of service (trap) via a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0172

Published Jan 16, 2009

Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cause a denial of service (infinite loop) via a crafted CONNEC…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0171

Published Jan 16, 2009

The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root password, perform a root login to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0170

Published Jan 16, 2009

Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obtain unspecified other "access…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0169

Published Jan 16, 2009

Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin account in the sub-realm, and t…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0168

Published Jan 16, 2009

Unspecified vulnerability in ppdmgr in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to a…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0167

Published Jan 16, 2009

Unspecified vulnerability in lpadmin in Sun Solaris 10 and OpenSolaris snv_61 through snv_106 allows local users to cause a denial of service via unspecified vectors, related to e…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,501-5,525 of 5,732 CVEsPage 221 of 230