2009 CVE Vulnerabilities
5,054 CVEs published in 2009.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2009-0662 | — | — | 1.0% | Apr 23, 2009 | The PlonePAS product 3.x before 3.9 and 3.2.x before 3.2.2, a product for Plone, does not properly handle the login form... |
| CVE-2009-0195 | — | — | 5.4% | Apr 23, 2009 | Heap-based buffer overflow in Xpdf 3.02pl2 and earlier, CUPS 1.3.9, and probably other products, allows remote attackers... |
| CVE-2009-0166 | — | — | 2.3% | Apr 23, 2009 | The JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products allows remote attackers to cau... |
| CVE-2009-0163 | — | — | 4.2% | Apr 23, 2009 | Integer overflow in the TIFF image decoding routines in CUPS 1.3.9 and earlier allows remote attackers to cause a denial... |
| CVE-2009-0147 | — | — | 2.6% | Apr 23, 2009 | Multiple integer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products ... |
| CVE-2009-0146 | — | — | 2.8% | Apr 23, 2009 | Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier, CUPS 1.3.9 and earlier, and other products a... |
| CVE-2009-1372 | — | — | 7.6% | Apr 23, 2009 | Stack-based buffer overflow in the cli_url_canon function in libclamav/phishcheck.c in ClamAV before 0.95.1 allows remot... |
| CVE-2009-1371 | — | — | 3.4% | Apr 23, 2009 | The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of ser... |
| CVE-2009-1370 | — | — | 5.9% | Apr 22, 2009 | Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote att... |
| CVE-2009-1369 | — | — | 2.4% | Apr 22, 2009 | moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) p... |
| CVE-2009-1368 | — | — | 6.2% | Apr 22, 2009 | Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .... |
| CVE-2009-1367 | — | — | 1.5% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in index.php in moziloCMS 1.11 allows remote attackers to inject arbitrary web ... |
| CVE-2009-1366 | — | — | 1.0% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows r... |
| CVE-2009-1362 | — | — | 0.8% | Apr 22, 2009 | SQL injection vulnerability in administration/index.php in chCounter 3.1.3 allows remote attackers to execute arbitrary ... |
| CVE-2009-1361 | — | — | 3.9% | Apr 22, 2009 | dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ... |
| CVE-2009-1312 | — | — | 5.6% | Apr 22, 2009 | Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, wh... |
| CVE-2009-1311 | — | — | 2.3% | Apr 22, 2009 | Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive inform... |
| CVE-2009-1310 | — | — | 1.5% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in the MozSearch plugin implementation in Mozilla Firefox before 3.0.9 allows u... |
| CVE-2009-1309 | — | — | 1.4% | Apr 22, 2009 | Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHtt... |
| CVE-2009-1308 | — | — | 2.3% | Apr 22, 2009 | Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey allows remote attac... |
| CVE-2009-1307 | — | — | 2.2% | Apr 22, 2009 | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implem... |
| CVE-2009-1306 | — | — | 1.3% | Apr 22, 2009 | The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disp... |
| CVE-2009-1305 | — | — | 1.9% | Apr 22, 2009 | The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows r... |
| CVE-2009-1304 | — | — | 2.1% | Apr 22, 2009 | The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allo... |
| CVE-2009-1303 | — | — | 1.8% | Apr 22, 2009 | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remo... |
Check if your code is affected by 2009 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now