10

CVE-2009-0323

Exploit
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable.  NOTE: these are different vectors than CVE-2008-6005.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
W3Amaya Version <= 11.0
W3Amaya Version0.9
W3Amaya Version0.95b
W3Amaya Version1.0
W3Amaya Version1.0a
W3Amaya Version1.1
W3Amaya Version1.1a
W3Amaya Version1.1c
W3Amaya Version1.2
W3Amaya Version1.2a
W3Amaya Version1.3
W3Amaya Version1.3a
W3Amaya Version1.3b
W3Amaya Version1.4
W3Amaya Version1.4a
W3Amaya Version2.0
W3Amaya Version2.1
W3Amaya Version2.2
W3Amaya Version2.3
W3Amaya Version2.4
W3Amaya Version3.0
W3Amaya Version3.1
W3Amaya Version3.2
W3Amaya Version3.2.1
W3Amaya Version4.0
W3Amaya Version4.1
W3Amaya Version4.2
W3Amaya Version4.2.1
W3Amaya Version4.3
W3Amaya Version4.3.1
W3Amaya Version4.3.2
W3Amaya Version5.0
W3Amaya Version5.1
W3Amaya Version5.2
W3Amaya Version5.3
W3Amaya Version6.0
W3Amaya Version6.1
W3Amaya Version6.2
W3Amaya Version6.3
W3Amaya Version6.4
W3Amaya Version7.0
W3Amaya Version7.1
W3Amaya Version7.2
W3Amaya Version8.0
W3Amaya Version8.1
W3Amaya Version8.1a
W3Amaya Version8.1b
W3Amaya Version8.2
W3Amaya Version8.3
W3Amaya Version8.4
W3Amaya Version8.5
W3Amaya Version8.6
W3Amaya Version8.7
W3Amaya Version8.7.1
W3Amaya Version8.7.2
W3Amaya Version8.8.1
W3Amaya Version8.8.3
W3Amaya Version8.8.4
W3Amaya Version8.8.5
W3Amaya Version8.52
W3Amaya Version9.0
W3Amaya Version9.1
W3Amaya Version9.2.1
W3Amaya Version9.3
W3Amaya Version9.4
W3Amaya Version9.5
W3Amaya Version9.52
W3Amaya Version9.53
W3Amaya Version9.54
W3Amaya Version9.55
W3Amaya Version10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 72.46% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.