5

CVE-2009-1219

Exploit
Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sun ≫ Java System Calendar Server Version 6 Update - Edition sparc
Sun ≫ Java System Calendar Server Version 6.3 Update - Edition sparc
Sun ≫ One Calendar Server Version 6.0 Update - Edition sparc
Sun ≫ Java System Calendar Server Version 6 Update - Edition x86
Sun ≫ Java System Calendar Server Version 6.3 Update - Edition x86
Sun ≫ One Calendar Server Version 6.0 Update - Edition x86
Sun ≫ Java System Calendar Server Version 6 Update - Edition linux
Sun ≫ Java System Calendar Server Version 6.3 Update - Edition linux
Sun ≫ One Calendar Server Version 6.0 Update - Edition linux
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.7% 0.944
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://sunsolve.sun.com/search/document.do?assetkey=1-26-256228-1
Patch
Vendor Advisory
http://www.coresecurity.com/content/sun-calendar-express
Exploit
http://www.securityfocus.com/archive/1/502320/100/0/threaded
http://www.vupen.com/english/advisories/2009/0905
http://sunsolve.sun.com/search/document.do?assetkey=1-66-255008-1
http://www.securityfocus.com/bid/34150
Exploit