← All CVEs

CVE-2009-0077

medium · 5

The firewall engine in Microsoft Forefront Threat Management Gateway, Medium Business Edition (TMG MBE); and Internet Security and Acceleration (ISA) Server 2004 SP3, 2006, 2006 Supportability Update, and 2006 SP1; does not properly manage the session state of web listeners, which allows remote attackers to cause a denial of service (many stale sessions) via crafted packets, aka "Web Proxy TCP State Limited Denial of Service Vulnerability."

5
CVSS
78.5%
EPSS (exploit prob.)
100th
EPSS percentile
2009-04-15
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

VendorProductAffected versions
microsoftforefront_threat_management_gatewayall versions
microsoftinternet_security_and_acceleration_server2004
microsoftinternet_security_and_acceleration_server2004
microsoftinternet_security_and_acceleration_server2006
microsoftinternet_security_and_acceleration_server2006

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-0077