2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2009-3014Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do ...
CVE-2009-3013Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP resp...
CVE-2009-3012Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location heade...
CVE-2009-3011Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in R...
CVE-2009-3010Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do ...
CVE-2009-3008K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show...
CVE-2009-3007Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar,...
CVE-2009-3006Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, ...
CVE-2009-3005Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show...
CVE-2009-3004Avant Browser 11.7 Builds 35 and 36 allows remote attackers to spoof the address bar, via window.open with a relative UR...
CVE-2009-3003Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relativ...
CVE-2009-3002The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows lo...
CVE-2009-3001The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain...
CVE-2009-3000The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator...
CVE-2009-2695The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory ...
CVE-2009-2978SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote at...
CVE-2009-2977The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in lo...
CVE-2009-2976Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, whi...
CVE-2009-2975Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, ...
CVE-2009-2974Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application ...
CVE-2009-2973Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1)...
CVE-2009-2972in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumpt...
CVE-2009-2935Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on readin...
CVE-2009-2861The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does ...
CVE-2009-2054Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 be...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now