2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2587Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web scrip...
CVE-2009-2586Cross-site scripting (XSS) vulnerability in articles.php in EDGEPHP EZArticles allows remote attackers to inject arbitra...
CVE-2009-2585SQL injection vulnerability in index.php in Mlffat 2.2 allows remote attackers to execute arbitrary SQL commands via a m...
CVE-2009-2584Off-by-one error in the options_write function in drivers/misc/sgi-gru/gruprocfs.c in the SGI GRU driver in the Linux ke...
CVE-2009-2583Multiple session fixation vulnerabilities in IBM Tivoli Identity Manager (ITIM) 5.0.0.6 allow remote attackers to hijack...
CVE-2009-2582Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remot...
CVE-2009-1862HIGH7.8Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 an...
CVE-2009-2581Cross-site scripting (XSS) vulnerability in modifier.php in EditeurScripts EsNews 1.2 allows remote attackers to inject ...
CVE-2009-2580Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1862. Reason: This candidate is a duplicate of...
CVE-2009-2578Google Chrome 2.x through 2.0.172 allows remote attackers to cause a denial of service (application crash) via a long Un...
CVE-2009-2577Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption, and application...
CVE-2009-2576Microsoft Internet Explorer 6.0.2900.2180 and earlier allows remote attackers to cause a denial of service (CPU and memo...
CVE-2009-2575The Research In Motion (RIM) BlackBerry 8800 allows remote attackers to cause a denial of service (memory consumption an...
CVE-2009-2472Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which ...
CVE-2009-2471The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote...
CVE-2009-2469Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an _...
CVE-2009-2468Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4...
CVE-2009-2467Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application cra...
CVE-2009-2466The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of serv...
CVE-2009-2465Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and...
CVE-2009-2464The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and ...
CVE-2009-2463Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c...
CVE-2009-2462The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service...
CVE-2009-2574index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via ...
CVE-2009-2573Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenti...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now