← All CVEs

CVE-2009-0689

medium · 6.8

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

6.8
CVSS
28.1%
EPSS (exploit prob.)
98th
EPSS percentile
2009-07-01
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
k-meleon_projectk-meleon1.5.3
mozillafirefox3.0.1
mozillafirefox3.0.2
mozillafirefox3.0.3
mozillafirefox3.0.4
mozillafirefox3.0.5
mozillafirefox3.0.6
mozillafirefox3.0.7
mozillafirefox3.0.8
mozillafirefox3.0.9
mozillafirefox3.0.10
mozillafirefox3.0.11
mozillafirefox3.0.12
mozillafirefox3.0.13
mozillafirefox3.0.14
mozillafirefox3.5
mozillafirefox3.5.1
mozillafirefox3.5.2
mozillafirefox3.5.3
mozillaseamonkey1.1.8
freebsdfreebsd6.4
freebsdfreebsd6.4
freebsdfreebsd6.4
freebsdfreebsd6.4
freebsdfreebsd6.4
freebsdfreebsd6.4
freebsdfreebsd6.4
freebsdfreebsd7.2
freebsdfreebsd7.2
freebsdfreebsd7.2
netbsdnetbsd5.0
openbsdopenbsd4.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-0689