CVE-2009-2625

Aliases:GHSA-334p-wv2m-w3vp
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 06 Aug 2009, 15:00
Last modified:07 Aug 2024, 05:59

Vulnerability Summary

Overall Risk (default)
low
20/100
CVSS Score
5 MEDIUM
v2.0 (nvd)
EPSS Score
1.04% LOW
1% probability +0.69%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Aug 2009, 15:00
Published
Vulnerability first disclosed
07 Aug 2024, 05:59
Last Modified
Vulnerability information updated

Description

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

CVSS Metrics

  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 1.04% Percentile: 78%

Affected Systems

  • apachexerces2_java

    2.9.1

  • canonicalubuntu_linux

    6.06 | 8.04 | 8.10 | 9.04 | 9.10

  • debiandebian_linux

    4.0 | 5.0

  • fedoraprojectfedora

    10 | 11

  • xercesxercesImpl

    < 2.10.0

  • opensuseopensuse

    11.0 | 11.1 | 11.2

  • oraclejdk

    1.5.0 | 1.5.0:update1 | 1.5.0:update10 | 1.5.0:update11 | 1.5.0:update12 | 1.5.0:update13 | 1.5.0:update14 | 1.5.0:update15 | 1.5.0:update16 | 1.5.0:update17 | 1.5.0:update18 | 1.5.0:update19 | 1.5.0:update2 | 1.5.0:update3 | 1.5.0:update4 | 1.5.0:update5 | 1.5.0:update6 | 1.5.0:update7 | 1.5.0:update8 | 1.5.0:update9 | 1.6.0 | 1.6.0:update1 | 1.6.0:update10 | 1.6.0:update11 | 1.6.0:update12 | 1.6.0:update13 | 1.6.0:update14 | 1.6.0:update2 | 1.6.0:update3 | 1.6.0:update4 | 1.6.0:update5 | 1.6.0:update6 | 1.6.0:update7

  • oracleprimavera_p6_enterprise_project_portfolio_management

    6.1 | 6.2.1 | 7.0

  • oracleprimavera_web_services

    6.2.1 | 7.0 | 7.0:sp1

  • suselinux_enterprise_server

    9 | 10:sp2 | 10:sp3 | 11

References (68)