Lucene search

K
cve[email protected]CVE-2009-2536
HistoryJul 20, 2009 - 6:30 p.m.

CVE-2009-2536

2009-07-2018:30:01
CWE-399
web.nvd.nist.gov
23
cve-2009-2536
microsoft
internet explorer
dos
memory consumption
application crash
select object

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.4 Medium

AI Score

Confidence

Low

0.044 Low

EPSS

Percentile

92.5%

Microsoft Internet Explorer 5 through 8 allows remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a related issue to CVE-2009-1692.

Affected configurations

NVD
Node
microsoftinternet_explorerRange8
OR
microsoftinternet_explorerMatch5
OR
microsoftinternet_explorerMatch6
OR
microsoftinternet_explorerMatch7

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.4 Medium

AI Score

Confidence

Low

0.044 Low

EPSS

Percentile

92.5%