2009 CVE Vulnerabilities

5,054 CVEs published in 2009.

CVE IDSeverityCVSSDescription
CVE-2009-3008K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show...
CVE-2009-3007Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar,...
CVE-2009-3006Maxthon Browser 2.5.3.80 UNICODE allows remote attackers to spoof the address bar, via window.open with a relative URI, ...
CVE-2009-3005Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show...
CVE-2009-3004Avant Browser 11.7 Builds 35 and 36 allows remote attackers to spoof the address bar, via window.open with a relative UR...
CVE-2009-3003Microsoft Internet Explorer 6 through 8 allows remote attackers to spoof the address bar, via window.open with a relativ...
CVE-2009-3002The Linux kernel before 2.6.31-rc7 does not initialize certain data structures within getname functions, which allows lo...
CVE-2009-3001The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain...
CVE-2009-3000The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator...
CVE-2009-2695The Linux kernel before 2.6.31-rc7 does not properly prevent mmap operations that target page zero and other low memory ...
CVE-2009-2978SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote at...
CVE-2009-2977The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in lo...
CVE-2009-2976Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, whi...
CVE-2009-2975Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, ...
CVE-2009-2974Google Chrome 1.0.154.65, 1.0.154.48, and earlier allows remote attackers to (1) cause a denial of service (application ...
CVE-2009-2973Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1)...
CVE-2009-2972in.lpd in the print service in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (memory consumpt...
CVE-2009-2698HIGH7.8The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel befo...
CVE-2009-2935Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on readin...
CVE-2009-2861The Over-the-Air Provisioning (OTAP) functionality on Cisco Aironet Lightweight Access Point 1100 and 1200 devices does ...
CVE-2009-2054Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 be...
CVE-2009-2053Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 be...
CVE-2009-2052Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 be...
CVE-2009-2051Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communic...
CVE-2009-2050Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a d...

Check if your code is affected by 2009 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now