5

CVE-2009-2625

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Data is provided by the National Vulnerability Database (NVD)
OracleJdk Version1.5.0 Update-
OracleJdk Version1.5.0 Updateupdate1
OracleJdk Version1.5.0 Updateupdate10
OracleJdk Version1.5.0 Updateupdate11
OracleJdk Version1.5.0 Updateupdate12
OracleJdk Version1.5.0 Updateupdate13
OracleJdk Version1.5.0 Updateupdate14
OracleJdk Version1.5.0 Updateupdate15
OracleJdk Version1.5.0 Updateupdate16
OracleJdk Version1.5.0 Updateupdate17
OracleJdk Version1.5.0 Updateupdate18
OracleJdk Version1.5.0 Updateupdate19
OracleJdk Version1.5.0 Updateupdate2
OracleJdk Version1.5.0 Updateupdate3
OracleJdk Version1.5.0 Updateupdate4
OracleJdk Version1.5.0 Updateupdate5
OracleJdk Version1.5.0 Updateupdate6
OracleJdk Version1.5.0 Updateupdate7
OracleJdk Version1.5.0 Updateupdate8
OracleJdk Version1.5.0 Updateupdate9
OracleJdk Version1.6.0 Update-
OracleJdk Version1.6.0 Updateupdate1
OracleJdk Version1.6.0 Updateupdate10
OracleJdk Version1.6.0 Updateupdate11
OracleJdk Version1.6.0 Updateupdate12
OracleJdk Version1.6.0 Updateupdate13
OracleJdk Version1.6.0 Updateupdate14
OracleJdk Version1.6.0 Updateupdate2
OracleJdk Version1.6.0 Updateupdate3
OracleJdk Version1.6.0 Updateupdate4
OracleJdk Version1.6.0 Updateupdate5
OracleJdk Version1.6.0 Updateupdate6
OracleJdk Version1.6.0 Updateupdate7
FedoraprojectFedora Version10
FedoraprojectFedora Version11
OpensuseOpensuse Version11.0
OpensuseOpensuse Version11.1
OpensuseOpensuse Version11.2
SuseLinux Enterprise Server Version10 Updatesp2
SuseLinux Enterprise Server Version10 Updatesp3 SwEdition-
SuseLinux Enterprise Server Version11 Update-
DebianDebian Linux Version4.0
DebianDebian Linux Version5.0
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
CanonicalUbuntu Linux Version9.10
OraclePrimavera Web Services Version6.2.1
OraclePrimavera Web Services Version7.0 Update-
OraclePrimavera Web Services Version7.0 Updatesp1
ApacheXerces2 Java Version2.9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.43% 0.618
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
http://marc.info/?l=bugtraq&m=125787273209737&w=2
Third Party Advisory
Mailing List
http://www.us-cert.gov/cas/techalerts/TA09-294A.html
Third Party Advisory
US Government Resource
http://www.openwall.com/lists/oss-security/2009/10/22/9
Patch
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/35958
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1022680
Third Party Advisory
VDB Entry
http://www.us-cert.gov/cas/techalerts/TA10-012A.html
Third Party Advisory
US Government Resource
https://bugzilla.redhat.com/show_bug.cgi?id=512921
Third Party Advisory
Issue Tracking