2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-1599——Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form cont...
CVE-2009-1598——Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a f...
CVE-2009-1597——Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a...
CVE-2009-1194——Integer overflow in the pango_glyph_string_set_size function in pango/glyphstring.c in Pango before 1.24 allows context-...
CVE-2009-0194——The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garm...
CVE-2009-1596MEDIUM6.5Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console ...
CVE-2009-1595——The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authentic...
CVE-2009-1592——Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a ...
CVE-2009-1591——CRLF injection vulnerability in CGI RESCUE Web Mailer before 1.04 allows remote attackers to inject arbitrary HTTP heade...
CVE-2009-1590——Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipie...
CVE-2009-1589——Unspecified vulnerability in CGI RESCUE MiniBBS22 before 1.01 allows remote attackers to send email to arbitrary recipie...
CVE-2009-1588——Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 bef...
CVE-2009-1587——index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett...
CVE-2009-1586——Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to ex...
CVE-2009-1585——Multiple SQL injection vulnerabilities in TemaTres 1.031, when magic_quotes_gpc is disabled, allow remote attackers to e...
CVE-2009-1584——Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta...
CVE-2009-1583——Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitra...
CVE-2009-1582——Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote att...
CVE-2009-1577——Multiple stack-based buffer overflows in the putstring function in find.c in Cscope before 15.6 allow user-assisted remo...
CVE-2009-1442——Multiple integer overflows in Skia, as used in Google Chrome 1.x before 1.0.154.64 and 2.x, and possibly Android, might ...
CVE-2009-1441——Heap-based buffer overflow in the ParamTraits<SkBitmap>::Read function in Google Chrome before 1.0.154.64 allows attacke...
CVE-2009-1576——Unspecified vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17.0, allows user-...
CVE-2009-1575——Cross-site scripting (XSS) vulnerability in Drupal 5.x before 5.17 and 6.x before 6.11, as used in vbDrupal before 5.17....
CVE-2009-1574——racoon/isakmp_frag.c in ipsec-tools before 0.7.2 allows remote attackers to cause a denial of service (crash) via crafte...
CVE-2009-1573——xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOO...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now