CVE-2009-1174
published 2009-03-31CVE-2009-1174: The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security…
PriorityP335critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.36%
82.0th percentile
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| linux | linux_kernel | >= 5.7.0 < 6.0.19 | 6.0.19 |
| linux | linux_kernel | >= 6.1.0 < 6.1.5 | 6.1.5 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
vhost_vdpa: fix the crash in unmap a large memory
osv·2025-12-30
CVE-2022-50851 vhost_vdpa: fix the crash in unmap a large memory
vhost_vdpa: fix the crash in unmap a large memory
In the Linux kernel, the following vulnerability has been resolved:
vhost_vdpa: fix the crash in unmap a large memory
While testing in vIOMMU, sometimes Guest will unmap very large memory,
which will cause the crash. To fix this, add a new function
vhost_vdpa_general_unmap(). This function will only unmap the memory
that saved in iotlb.
Call Trace:
[ 647.820144] ------------[ cut here ]------------
[ 647.820848] kernel BUG at drivers/iommu/intel/iommu.c:1174!
[ 647.821486] invalid opcode: 0000 [#1] PREEMPT SMP PTI
[ 647.822082] CPU: 10 PID: 1181 Comm: qemu-system-x86 Not tainted 6.0.0-rc1home_lulu_2452_lulu7_vhost+ #62
[ 647.823139] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.15.0-29-g6a62e0cb0dfe-prebuilt.qem4
[ 647.
GHSA
GHSA-f454-gp59-g2j5: The Web Services Security component in IBM WebSphere Application Server (WAS) 6
ghsa_unreviewed·2022-05-02
CVE-2009-1174 [HIGH] GHSA-f454-gp59-g2j5: The Web Services Security component in IBM WebSphere Application Server (WAS) 6
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.
Red Hat
kernel: Linux kernel (vhost_vdpa): Denial of service via large memory unmap
vendor_redhat·2025-12-30·CVSS 6.6
CVE-2022-50851 [MEDIUM] CWE-754 kernel: Linux kernel (vhost_vdpa): Denial of service via large memory unmap
kernel: Linux kernel (vhost_vdpa): Denial of service via large memory unmap
In the Linux kernel, the following vulnerability has been resolved:
vhost_vdpa: fix the crash in unmap a large memory
While testing in vIOMMU, sometimes Guest will unmap very large memory,
which will cause the crash. To fix this, add a new function
vhost_vdpa_general_unmap(). This function will only unmap the memory
that saved in iotlb.
Call Trace:
[ 647.820144] ------------[ cut here ]------------
[ 647.820848] kernel BUG at drivers/iommu/intel/iommu.c:1174!
[ 647.821486] invalid opcode: 0000 [#1] PREEMPT SMP PTI
[ 647.822082] CPU: 10 PID: 1181 Comm: qemu-system-x86 Not tainted 6.0.0-rc1home_lulu_2452_lulu7_vhost+ #62
[ 647.823139] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.15.0-29-g6a62e0cb0d
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/34131http://secunia.com/advisories/34461http://secunia.com/advisories/35301http://www-01.ibm.com/support/docview.wss?uid=swg1PK80596http://www-01.ibm.com/support/docview.wss?uid=swg21384925http://www-01.ibm.com/support/docview.wss?uid=swg27006876http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www.securityfocus.com/bid/34506http://www.vupen.com/english/advisories/2009/1464http://secunia.com/advisories/34131http://secunia.com/advisories/34461http://secunia.com/advisories/35301http://www-01.ibm.com/support/docview.wss?uid=swg1PK80596http://www-01.ibm.com/support/docview.wss?uid=swg21384925http://www-01.ibm.com/support/docview.wss?uid=swg27006876http://www-01.ibm.com/support/docview.wss?uid=swg27014463http://www.securityfocus.com/bid/34506http://www.vupen.com/english/advisories/2009/1464
2009-03-31
Published