Shortened for this page: results: 3 of 25 shown; results[].references: first 10 items; results[].configurations[].nodes[].cpe_match: first 10 items; results[].enrichment.cpe: first 10 items; results[].enrichment.cwe[].capec_id: first 10 items
{
"page": 1,
"page_size": 25,
"result_count": 1222,
"results": [
{
"id": "CVE-2009-4143",
"source_identifier": "user@redhat.com",
"published": "2009-12-21T16:30:00Z",
"last_modified": "2026-06-16T23:13:07Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive."
},
{
"lang": "es",
"value": "PHP versiones anteriores a v5.2.12 no maneja adecuadamente los datos de sesión, teniendo un impacto no especificado y vectores de ataque relacionado con (1) la interrupción de corrupción de la selección SESSION superglobal y (2) la directiva session.save_path."
}
],
"references": [
{
"url": "http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://marc.info/?l=bugtraq&m=127680701405735&w=2",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://secunia.com/advisories/37821",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/38648",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/40262",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/41480",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/41490",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.apple.com/kb/HT4077",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://www.debian.org/security/2010/dsa-2001",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995",
"source": "user@redhat.com",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"match_criteria_id": "DD613CC3-281B-43D1-A352-53D339B040FA",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.2.11",
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:*",
"match_criteria_id": "92647629-083F-4042-8365-4AD2EBC9C1BF",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:*",
"match_criteria_id": "FF72E8D5-9F8C-4BD4-9AA4-28E23CB48A47",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:*",
"match_criteria_id": "83BE1120-6370-4470-8586-6581EDF3FD69",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*",
"match_criteria_id": "245C601D-0FE7-47E3-8304-6FF45E9567D6",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*",
"match_criteria_id": "691BB8BB-329A-4640-B758-7590C99B5E42",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*",
"match_criteria_id": "E2BC4CCE-2774-463E-82EA-36CD442D3A7B",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*",
"match_criteria_id": "C478024C-2FCD-463F-A75E-E04660AA9DF1",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*",
"match_criteria_id": "AC9C32F4-5102-4E9B-9F32-B24B65A5ED2F",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*",
"match_criteria_id": "A5BD99C0-E875-496E-BE5E-A8DCBD414B5C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Red Hat",
"comment": "We do not consider safe_mode / open_basedir restriction bypass issues being security sensitive. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php",
"last_modified": "2009-12-23T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.2.11",
"version_end_excluding": null,
"affected_versions_first": "0.1",
"affected_versions_last": "5.2.11"
},
{
"criteria": "cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "1.0",
"affected_versions_last": "1.0"
},
{
"criteria": "cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0",
"affected_versions_last": "2.0"
},
{
"criteria": "cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0b10",
"affected_versions_last": "2.0b10"
},
{
"criteria": "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0",
"affected_versions_last": "3.0"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.1",
"affected_versions_last": "3.0.1"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.2",
"affected_versions_last": "3.0.2"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.3",
"affected_versions_last": "3.0.3"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.4",
"affected_versions_last": "3.0.4"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.5",
"affected_versions_last": "3.0.5"
}
],
"cwe": null,
"epss_score": {
"epss": 0.02946,
"percentile": 0.86567,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
},
{
"id": "CVE-2009-3245",
"source_identifier": "user@mitre.org",
"published": "2010-03-05T19:30:00Z",
"last_modified": "2026-06-16T23:11:13Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors."
},
{
"lang": "es",
"value": "OpenSSL en versiones anterioes a v0.9.8m cuando recibe un valor de retorno NULL de la funcion bn_wexpand hace una llamada a (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, y (4) engines/e_ubsec.c, lo que tiene un impacto inespecifico y vectores de ataque dependientes del contexto."
}
],
"references": [
{
"url": "http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.asc",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://marc.info/?l=bugtraq&m=127128920008563&w=2",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://marc.info/?l=bugtraq&m=127678688104458&w=2",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://marc.info/?l=openssl-cvs&m=126692159706582&w=2",
"source": "user@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://marc.info/?l=openssl-cvs&m=126692170906712&w=2",
"source": "user@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://marc.info/?l=openssl-cvs&m=126692180606861&w=2",
"source": "user@mitre.org",
"tags": [
"Patch"
]
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": true,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"match_criteria_id": "81FB3B26-CC83-4FA5-BDE1-05F35AB99741",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "0.9.8l",
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*",
"match_criteria_id": "8A4E446D-B9D3-45F2-9722-B41FA14A6C31",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*",
"match_criteria_id": "AF4EA988-FC80-4170-8933-7C6663731981",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*",
"match_criteria_id": "64F8F53B-24A1-4877-B16E-F1917C4E4E81",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*",
"match_criteria_id": "75D3ACD5-905F-42BB-BE1A-8382E9D823BF",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*",
"match_criteria_id": "766EA6F2-7FA4-4713-9859-9971CCD2FDCB",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*",
"match_criteria_id": "EFBC30B7-627D-48DC-8EF0-AE8FA0C6EDBA",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*",
"match_criteria_id": "2BB38AEA-BAF0-4920-9A71-747C24444770",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*",
"match_criteria_id": "1F33EA2B-DE15-4695-A383-7A337AC38908",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*",
"match_criteria_id": "261EE631-AB43-44FE-B02A-DFAAB8D35927",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Red Hat",
"comment": "Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2009-3245\n\nThis issue was fixed in openssl packages in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2010-0162.html\n\nThis issue was fixed in openssl096b packages in Red Hat Enterprise Linux 3 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0173.html\n\nThe Red Hat Security Response Team has rated this issue as having low security impact on openssl packages in Red Hat Enterprise Linux 3 and 4, a future update may address this flaw.",
"last_modified": "2010-03-25T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "0.9.8l",
"version_end_excluding": null,
"affected_versions_first": "0.9.6d",
"affected_versions_last": "0.9.8"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8",
"affected_versions_last": "0.9.8"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8a",
"affected_versions_last": "0.9.8a"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8b",
"affected_versions_last": "0.9.8b"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8c",
"affected_versions_last": "0.9.8c"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8d",
"affected_versions_last": "0.9.8d"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8e",
"affected_versions_last": "0.9.8e"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8f",
"affected_versions_last": "0.9.8f"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8g",
"affected_versions_last": "0.9.8g"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8h",
"affected_versions_last": "0.9.8h"
}
],
"cwe": [
{
"id": 20,
"owasptop10_2021": "A03 Injection",
"name": "Improper Input Validation",
"description": "The product receives input or data, but it does\n not validate or incorrectly validates that the input has the\n properties that are required to process the data safely and\n correctly.",
"capec_id": [
3,
7,
8,
9,
10,
13,
14,
22,
23,
24
],
"scope": [
"Availability",
"Confidentiality",
"Integrity"
],
"impact": [
"DoS: Crash, Exit, or Restart",
"DoS: Resource Consumption (CPU)",
"DoS: Resource Consumption (Memory)",
"Execute Unauthorized Code or Commands",
"Modify Memory",
"Read Files or Directories",
"Read Memory"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Fuzzing",
"Manual Static Analysis",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
}
],
"epss_score": {
"epss": 0.06471,
"percentile": 0.93442,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
},
{
"id": "CVE-2009-2688",
"source_identifier": "user@mitre.org",
"published": "2009-08-05T19:30:01Z",
"last_modified": "2026-06-16T23:10:01Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the png_instantiate function processing a crafted PNG file, and (3) the jpeg_instantiate function processing a crafted JPEG file, all which trigger a heap-based buffer overflow. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de enteros en glyphs-eimage.c en XEmacs v21.4.22, cuando corre en Windows, permite a atacantes remotos causar una denegación de servicio (caída) o ejecutar código a su elección a través (1) la función tiff_instantiate produciendo un fichero TIFF manipulado, (2) la función png_instantiate produciendo un fichero PNG manipulado, y (3) la función jpeg_instantiate produciendo un fichero JPEG manipulado, todas provocan un desbordamiento de búfer basado en memoria dinámica. NOTA: el origen de esta información es desconocido; Los detalles han sido obtenidos a partir de terceros."
}
],
"references": [
{
"url": "http://osvdb.org/55298",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://secunia.com/advisories/35348",
"source": "user@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://tracker.xemacs.org/XEmacs/its/issue534",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://www.securityfocus.com/bid/35473",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://www.vupen.com/english/advisories/2009/1666",
"source": "user@mitre.org",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://bugs.gentoo.org/show_bug.cgi?id=275397",
"source": "user@mitre.org",
"tags": null
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=511994",
"source": "user@mitre.org",
"tags": null
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51332",
"source": "user@mitre.org",
"tags": null
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51333",
"source": "user@mitre.org",
"tags": null
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/51334",
"source": "user@mitre.org",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": false,
"obtain_all_privilege": true,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-189"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:xemacs:xemacs:21.4.22:*:*:*:*:*:*:*",
"match_criteria_id": "246EDF0B-B3C0-489A-AD11-1FAC352F6694",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Red Hat",
"comment": "Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2009-2688\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/\n",
"last_modified": "2009-08-06T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:xemacs:xemacs:21.4.22:*:*:*:*:*:*:*",
"vendor": "xemacs",
"product": "xemacs",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "21.4.22",
"affected_versions_last": "21.4.22"
}
],
"cwe": null,
"epss_score": {
"epss": 0.08636,
"percentile": 0.94867,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
}
]
}