cbcvebase.
CVE-2009-1885
published 2009-08-11

CVE-2009-1885: Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
5.32%
91.7th percentile
Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

Affected

7 ranges
VendorProductVersion rangeFixed in
apachexerces-c
apachexerces-c
apachexerces-c>= 0 < 3.0.1-23.0.1-2
apachexerces-c>= 0 < 3.0.1-23.0.1-2
apachexerces-c>= 0 < 3.0.1-23.0.1-2
apachexerces-c>= 0 < 3.0.1-23.0.1-2
debianxerces-c< xerces-c 3.0.1-2 (bookworm)xerces-c 3.0.1-2 (bookworm)

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.