2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2066——Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-m...
CVE-2009-2065——Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level fra...
CVE-2009-2064——Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-le...
CVE-2009-2063——Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-i...
CVE-2009-2062——Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-t...
CVE-2009-2061——Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-...
CVE-2009-2060——src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the c...
CVE-2009-2059——Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (...
CVE-2009-2058——Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) ...
CVE-2009-2057——Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) ...
CVE-2009-2044——Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via...
CVE-2009-2043——nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL poi...
CVE-2009-1841——js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey ...
CVE-2009-1840——Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into ...
CVE-2009-1839——Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, whic...
CVE-2009-1838——The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey befor...
CVE-2009-1837HIGH7.5Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozill...
CVE-2009-1836——Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to dete...
CVE-2009-1835——Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located a...
CVE-2009-1834——Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey befor...
CVE-2009-1833——The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows ...
CVE-2009-1832——Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause ...
CVE-2009-1392——The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows r...
CVE-2009-2042——libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, whic...
CVE-2009-2041——Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab 0.7.1 allows remote attackers to inject arbitrary we...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now