2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-2066Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-m...
CVE-2009-2065Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level fra...
CVE-2009-2064Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-le...
CVE-2009-2063Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-i...
CVE-2009-2062Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-t...
CVE-2009-2061Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-...
CVE-2009-2060src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the c...
CVE-2009-2059Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (...
CVE-2009-2058Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) ...
CVE-2009-2057Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) ...
CVE-2009-2044Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via...
CVE-2009-2043nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL poi...
CVE-2009-1841js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey ...
CVE-2009-1840Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into ...
CVE-2009-1839Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, whic...
CVE-2009-1838The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey befor...
CVE-2009-1837HIGH7.5Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozill...
CVE-2009-1836Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to dete...
CVE-2009-1835Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located a...
CVE-2009-1834Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey befor...
CVE-2009-1833The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows ...
CVE-2009-1832Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause ...
CVE-2009-1392The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows r...
CVE-2009-2042libpng before 1.2.37 does not properly parse 1-bit interlaced images with width values that are not divisible by 8, whic...
CVE-2009-2041Cross-site scripting (XSS) vulnerability in A51 D.O.O. activeCollab 0.7.1 allows remote attackers to inject arbitrary we...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now