Lucene search

K
cve[email protected]CVE-2009-4417
HistoryOct 03, 2022 - 4:24 p.m.

CVE-2009-4417

2022-10-0316:24:05
CWE-264
web.nvd.nist.gov
24
cve-2009-4417
zend_framework
vulnerability
shutdown function
zend_log_writer_mail
nvd
email
arbitrary
mailing vectors

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.8%

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to “events not yet mailed.”

Affected configurations

NVD
Node
zendframeworkRange1.9.6
OR
zendframeworkMatch0.1.3preview
OR
zendframeworkMatch0.1.4preview
OR
zendframeworkMatch0.1.5preview
OR
zendframeworkMatch0.2.0preview
OR
zendframeworkMatch0.6.0preview
OR
zendframeworkMatch0.7.0preview
OR
zendframeworkMatch0.8.0preview
OR
zendframeworkMatch0.9.0beta
OR
zendframeworkMatch0.9.1beta
OR
zendframeworkMatch0.9.2beta
OR
zendframeworkMatch0.9.3beta
OR
zendframeworkMatch1.0.0
OR
zendframeworkMatch1.0.0rc1
OR
zendframeworkMatch1.0.0rc2
OR
zendframeworkMatch1.0.0rc3
OR
zendframeworkMatch1.0.1
OR
zendframeworkMatch1.0.2
OR
zendframeworkMatch1.0.3
OR
zendframeworkMatch1.0.4
OR
zendframeworkMatch1.5.0
OR
zendframeworkMatch1.5.0preview
OR
zendframeworkMatch1.5.0rc1
OR
zendframeworkMatch1.5.0rc2
OR
zendframeworkMatch1.5.0rc3
OR
zendframeworkMatch1.5.1
OR
zendframeworkMatch1.5.2
OR
zendframeworkMatch1.5.3
OR
zendframeworkMatch1.6.0
OR
zendframeworkMatch1.6.0rc1
OR
zendframeworkMatch1.6.0rc2
OR
zendframeworkMatch1.6.0rc3
OR
zendframeworkMatch1.6.1
OR
zendframeworkMatch1.6.2
OR
zendframeworkMatch1.7.0
OR
zendframeworkMatch1.7.0preview
OR
zendframeworkMatch1.7.1
OR
zendframeworkMatch1.7.2
OR
zendframeworkMatch1.7.3
OR
zendframeworkMatch1.7.4
OR
zendframeworkMatch1.7.5
OR
zendframeworkMatch1.7.6
OR
zendframeworkMatch1.7.7
OR
zendframeworkMatch1.7.8
OR
zendframeworkMatch1.8.0
OR
zendframeworkMatch1.8.0alpha_1
OR
zendframeworkMatch1.8.0beta_1
OR
zendframeworkMatch1.8.1
OR
zendframeworkMatch1.8.2
OR
zendframeworkMatch1.8.3
OR
zendframeworkMatch1.8.4
OR
zendframeworkMatch1.9
OR
zendframeworkMatch1.9.0
OR
zendframeworkMatch1.9.0alpha_1
OR
zendframeworkMatch1.9.0beta_1
OR
zendframeworkMatch1.9.0rc1
OR
zendframeworkMatch1.9.1
OR
zendframeworkMatch1.9.2
OR
zendframeworkMatch1.9.3
OR
zendframeworkMatch1.9.4
OR
zendframeworkMatch1.9.5

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

40.8%

Related for CVE-2009-4417