2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2587 | — | — | 2.3% | Jul 24, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web scrip... |
| CVE-2009-2586 | — | — | 1.5% | Jul 24, 2009 | Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitra... |
| CVE-2009-2585 | — | — | 1.0% | Jul 24, 2009 | SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a m... |
| CVE-2009-2584 | — | — | 0.5% | Jul 23, 2009 | Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux ke... |
| CVE-2009-2583 | — | — | 1.4% | Jul 23, 2009 | Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack... |
| CVE-2009-2582 | — | — | 3.3% | Jul 23, 2009 | Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remot... |
| CVE-2009-1862 | HIGH | 7.8 | 25.0% | Jul 23, 2009 | Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 an... |
| CVE-2009-2581 | — | — | 0.9% | Jul 23, 2009 | Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject ... |
| CVE-2009-2580 | — | — | — | Jul 23, 2009 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1862. Reason: This candidate is a duplicate of... |
| CVE-2009-2578 | — | — | 0.8% | Jul 22, 2009 | Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Un... |
| CVE-2009-2577 | — | — | 1.6% | Jul 22, 2009 | Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption, and application... |
| CVE-2009-2576 | — | — | 14.9% | Jul 22, 2009 | Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memo... |
| CVE-2009-2575 | — | — | 1.6% | Jul 22, 2009 | The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption an... |
| CVE-2009-2472 | — | — | 2.2% | Jul 22, 2009 | Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which ... |
| CVE-2009-2471 | — | — | 3.7% | Jul 22, 2009 | The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote... |
| CVE-2009-2469 | — | — | 5.6% | Jul 22, 2009 | Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an _... |
| CVE-2009-2468 | — | — | 6.3% | Jul 22, 2009 | Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4... |
| CVE-2009-2467 | — | — | 5.4% | Jul 22, 2009 | Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application cra... |
| CVE-2009-2466 | — | — | 6.6% | Jul 22, 2009 | The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of serv... |
| CVE-2009-2465 | — | — | 5.4% | Jul 22, 2009 | Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and... |
| CVE-2009-2464 | — | — | 13.2% | Jul 22, 2009 | The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and ... |
| CVE-2009-2463 | — | — | 6.4% | Jul 22, 2009 | Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c... |
| CVE-2009-2462 | — | — | 5.4% | Jul 22, 2009 | The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service... |
| CVE-2009-2574 | — | — | 1.9% | Jul 22, 2009 | index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via ... |
| CVE-2009-2573 | — | — | 0.8% | Jul 22, 2009 | Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenti... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now