2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-2071 | — | — | 1.0% | Jun 15, 2009 | Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by... |
| CVE-2009-2070 | — | — | 0.8% | Jun 15, 2009 | Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which all... |
| CVE-2009-2069 | — | — | 2.2% | Jun 15, 2009 | Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page return... |
| CVE-2009-2068 | — | — | 1.2% | Jun 15, 2009 | Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-... |
| CVE-2009-2067 | — | — | 1.4% | Jun 15, 2009 | Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle a... |
| CVE-2009-2066 | — | — | 1.0% | Jun 15, 2009 | Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-m... |
| CVE-2009-2065 | — | — | 0.9% | Jun 15, 2009 | Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level fra... |
| CVE-2009-2064 | — | — | 4.3% | Jun 15, 2009 | Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-le... |
| CVE-2009-2063 | — | — | 1.4% | Jun 15, 2009 | Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-i... |
| CVE-2009-2062 | — | — | 1.0% | Jun 15, 2009 | Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-t... |
| CVE-2009-2061 | — | — | 1.2% | Jun 15, 2009 | Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-... |
| CVE-2009-2060 | — | — | 1.1% | Jun 15, 2009 | src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the c... |
| CVE-2009-2059 | — | — | 1.3% | Jun 15, 2009 | Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (... |
| CVE-2009-2058 | — | — | 1.0% | Jun 15, 2009 | Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) ... |
| CVE-2009-2057 | — | — | 3.0% | Jun 15, 2009 | Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) ... |
| CVE-2009-2044 | — | — | 5.9% | Jun 12, 2009 | Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via... |
| CVE-2009-2043 | — | — | 4.4% | Jun 12, 2009 | nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL poi... |
| CVE-2009-1841 | — | — | 4.8% | Jun 12, 2009 | js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey ... |
| CVE-2009-1840 | — | — | 2.2% | Jun 12, 2009 | Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into ... |
| CVE-2009-1839 | — | — | 7.1% | Jun 12, 2009 | Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, whic... |
| CVE-2009-1838 | — | — | 4.8% | Jun 12, 2009 | The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey befor... |
| CVE-2009-1836 | — | — | 2.0% | Jun 12, 2009 | Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to dete... |
| CVE-2009-1835 | — | — | 2.3% | Jun 12, 2009 | Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located a... |
| CVE-2009-1834 | — | — | 3.2% | Jun 12, 2009 | Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey befor... |
| CVE-2009-1833 | — | — | 9.2% | Jun 12, 2009 | The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows ... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now