Lucene search

K
cve[email protected]CVE-2009-2501
HistoryOct 14, 2009 - 10:30 a.m.

CVE-2009-2501

2009-10-1410:30:01
CWE-119
web.nvd.nist.gov
79
cve
2009
2501
gdi+
buffer overflow
microsoft
internet explorer
windows xp
office
sql server
remote code execution
png image
vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

9.7 High

AI Score

Confidence

High

0.805 High

EPSS

Percentile

98.3%

Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted PNG image file, aka β€œGDI+ PNG Heap Overflow Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_2003_serversp2itanium
OR
microsoftwindows_2003_serversp2x64
OR
microsoftwindows_server_2008itanium
OR
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_vista
OR
microsoftwindows_vistax64
OR
microsoftwindows_vistasp1
OR
microsoftwindows_xpsp2
OR
microsoftwindows_xpsp2professional_x64
OR
microsoftwindows_xpsp3
Node
microsoftwindows_2000sp4
AND
microsoft.net_frameworkMatch1.1sp1
OR
microsoft.net_frameworkMatch2.0sp1
OR
microsoft.net_frameworkMatch2.0sp2
OR
microsoftinternet_explorerMatch6sp1
Node
microsoftreport_viewerMatch2005sp1redistributable_package
OR
microsoftreport_viewerMatch2008redistributable_package
OR
microsoftreport_viewerMatch2008sp1redistributable_package
OR
microsoftsql_serverMatch2005sp2
OR
microsoftsql_serverMatch2005sp2itanium
OR
microsoftsql_serverMatch2005sp2x64
OR
microsoftsql_serverMatch2005sp3
OR
microsoftsql_serverMatch2005sp3itanium
OR
microsoftsql_serverMatch2005sp3x64
OR
microsoftsql_server_reporting_servicesMatch2000sp2
Node
microsoftexcel_viewerMatch2003
OR
microsoftexcel_viewerMatch2003sp3
OR
microsoftexpression_web
OR
microsoftexpression_webMatch2
OR
microsoftofficeMatch2003sp3
OR
microsoftofficeMatch2007sp1
OR
microsoftofficeMatch2007sp2
OR
microsoftofficeMatchxp
OR
microsoftoffice_compatibility_packMatch2007sp1
OR
microsoftoffice_compatibility_packMatch2007sp2
OR
microsoftoffice_excel_viewer
OR
microsoftoffice_grooveMatch2007
OR
microsoftoffice_grooveMatch2007sp1
OR
microsoftoffice_powerpoint_viewer
OR
microsoftoffice_powerpoint_viewerMatch2007sp1
OR
microsoftoffice_powerpoint_viewerMatch2007sp2
OR
microsoftoffice_word_viewer
OR
microsoftprojectMatch2002sp1
OR
microsoftvisioMatch2002sp2
OR
microsoftword_viewerMatch2003
OR
microsoftword_viewerMatch2003sp3
OR
microsoftworksMatch8.5
Node
microsoftplatform_sdkredistrutable_gdi\+
OR
microsoftreport_viewerMatch2005sp1redistributable_package
OR
microsoftreport_viewerMatch2008redistributable_package
OR
microsoftreport_viewerMatch2008sp1redistributable_package
OR
microsoftvisual_studioMatch2008
OR
microsoftvisual_studioMatch2008sp1
OR
microsoftvisual_studio_.netMatch2003sp1
OR
microsoftvisual_studio_.netMatch2005sp1
Node
microsoftforefront_client_securityMatch1.0
OR
microsoftvisual_foxproMatch8.0sp1
OR
microsoftvisual_foxproMatch9.0sp2
AND
microsoftwindows_2000sp4

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

9.7 High

AI Score

Confidence

High

0.805 High

EPSS

Percentile

98.3%