2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-1362 | — | — | 0.8% | Apr 22, 2009 | SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary ... |
| CVE-2009-1361 | — | — | 3.9% | Apr 22, 2009 | dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ... |
| CVE-2009-1312 | — | — | 5.6% | Apr 22, 2009 | Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, wh... |
| CVE-2009-1311 | — | — | 2.3% | Apr 22, 2009 | Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive inform... |
| CVE-2009-1310 | — | — | 1.5% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows u... |
| CVE-2009-1309 | — | — | 1.4% | Apr 22, 2009 | Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHtt... |
| CVE-2009-1308 | — | — | 2.3% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attac... |
| CVE-2009-1307 | — | — | 2.2% | Apr 22, 2009 | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implem... |
| CVE-2009-1306 | — | — | 1.3% | Apr 22, 2009 | The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disp... |
| CVE-2009-1305 | — | — | 1.9% | Apr 22, 2009 | The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows r... |
| CVE-2009-1304 | — | — | 2.1% | Apr 22, 2009 | The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allo... |
| CVE-2009-1303 | — | — | 1.8% | Apr 22, 2009 | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remo... |
| CVE-2009-1302 | — | — | 2.9% | Apr 22, 2009 | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows ... |
| CVE-2009-0307 | — | — | 3.5% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in the "Customize Statistics Page" (admin/statistics/ConfigureStatistics) in th... |
| CVE-2009-1360 | — | — | 3.2% | Apr 22, 2009 | The __inet6_check_established function in net/ipv6/inet6_hashtables.c in the Linux kernel before 2.6.29, when Network Na... |
| CVE-2009-1359 | — | — | 0.3% | Apr 22, 2009 | Unspecified vulnerability in the SCTP sockets implementation in Sun OpenSolaris snv_106 through snv_107 allows local use... |
| CVE-2009-1338 | — | — | 0.4% | Apr 22, 2009 | The kill_something_info function in kernel/signal.c in the Linux kernel before 2.6.28 does not consider PID namespaces w... |
| CVE-2009-1337 | — | — | 1.3% | Apr 22, 2009 | The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the ... |
| CVE-2009-1336 | — | — | 0.4% | Apr 22, 2009 | fs/nfs/client.c in the Linux kernel before 2.6.23 does not properly initialize a certain structure member that stores th... |
| CVE-2009-1358 | — | — | 4.4% | Apr 21, 2009 | apt-get in apt before 0.7.21 does not check for the correct error code from gpgv, which causes apt to treat a repository... |
| CVE-2009-1356 | — | — | 4.8% | Apr 21, 2009 | Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi... |
| CVE-2009-1355 | — | — | 0.4% | Apr 21, 2009 | Stack-based buffer overflow in muxatmd in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long fil... |
| CVE-2009-1354 | — | — | 2.3% | Apr 21, 2009 | Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in ... |
| CVE-2009-1353 | — | — | 7.8% | Apr 21, 2009 | Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause ... |
| CVE-2009-1352 | — | — | 5.6% | Apr 21, 2009 | Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (applicatio... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now