Lucene search

K
cve[email protected]CVE-2009-0323
HistoryJan 28, 2009 - 8:30 p.m.

CVE-2009-0323

2009-01-2820:30:03
CWE-119
web.nvd.nist.gov
25
cve-2009-0323
buffer overflow
w3c amaya web browser
remote code execution
nvd
security vulnerability.

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.952 High

EPSS

Percentile

99.3%

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an “HTML GI” in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.

Affected configurations

NVD
Node
w3amayaRange11.0
OR
w3amayaMatch0.9
OR
w3amayaMatch0.95b
OR
w3amayaMatch1.0
OR
w3amayaMatch1.0a
OR
w3amayaMatch1.1
OR
w3amayaMatch1.1a
OR
w3amayaMatch1.1c
OR
w3amayaMatch1.2
OR
w3amayaMatch1.2a
OR
w3amayaMatch1.3
OR
w3amayaMatch1.3a
OR
w3amayaMatch1.3b
OR
w3amayaMatch1.4
OR
w3amayaMatch1.4a
OR
w3amayaMatch2.0
OR
w3amayaMatch2.1
OR
w3amayaMatch2.2
OR
w3amayaMatch2.3
OR
w3amayaMatch2.4
OR
w3amayaMatch3.0
OR
w3amayaMatch3.1
OR
w3amayaMatch3.2
OR
w3amayaMatch3.2.1
OR
w3amayaMatch4.0
OR
w3amayaMatch4.1
OR
w3amayaMatch4.2
OR
w3amayaMatch4.2.1
OR
w3amayaMatch4.3
OR
w3amayaMatch4.3.1
OR
w3amayaMatch4.3.2
OR
w3amayaMatch5.0
OR
w3amayaMatch5.1
OR
w3amayaMatch5.2
OR
w3amayaMatch5.3
OR
w3amayaMatch6.0
OR
w3amayaMatch6.1
OR
w3amayaMatch6.2
OR
w3amayaMatch6.3
OR
w3amayaMatch6.4
OR
w3amayaMatch7.0
OR
w3amayaMatch7.1
OR
w3amayaMatch7.2
OR
w3amayaMatch8.0
OR
w3amayaMatch8.1
OR
w3amayaMatch8.1a
OR
w3amayaMatch8.1b
OR
w3amayaMatch8.2
OR
w3amayaMatch8.3
OR
w3amayaMatch8.4
OR
w3amayaMatch8.5
OR
w3amayaMatch8.6
OR
w3amayaMatch8.7
OR
w3amayaMatch8.7.1
OR
w3amayaMatch8.7.2
OR
w3amayaMatch8.8.1
OR
w3amayaMatch8.8.3
OR
w3amayaMatch8.8.4
OR
w3amayaMatch8.8.5
OR
w3amayaMatch8.52
OR
w3amayaMatch9.0
OR
w3amayaMatch9.1
OR
w3amayaMatch9.2.1
OR
w3amayaMatch9.3
OR
w3amayaMatch9.4
OR
w3amayaMatch9.5
OR
w3amayaMatch9.52
OR
w3amayaMatch9.53
OR
w3amayaMatch9.54
OR
w3amayaMatch9.55
OR
w3amayaMatch10.0

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.952 High

EPSS

Percentile

99.3%