CVE-2009-2433
medium · 4.3Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
4.3
CVSS
18.9%
EPSS (exploit prob.)
97th
EPSS percentile
2009-07-10
Published
AV:N/AC:M/Au:N/C:N/I:N/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | ie | 8.0b |
| microsoft | internet_explorer | 7 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0 |
| microsoft | internet_explorer | 7.0.5730 |
| microsoft | internet_explorer | 7.0.5730.11 |
| microsoft | internet_explorer | 7.00.5730.1100 |
| microsoft | internet_explorer | 7.00.6000.16386 |
| microsoft | internet_explorer | 7.00.6000.16441 |
| microsoft | internet_explorer | 8.0.6001 |
| microsoft | internet_explorer | 8.0.6001 |
Check a specific version with /api/v1/cve/match.
References
- http://www.exploit-db.com/exploits/9100
- http://www.securityfocus.com/bid/35620
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12829
- http://www.exploit-db.com/exploits/9100
- http://www.securityfocus.com/bid/35620
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12829
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-2433