CVE-2009-2500
published 2009-10-14CVE-2009-2500: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and…
PriorityP258critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
23.65%
97.6th percentile
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulnerability."
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | excel_viewer | — | — |
| microsoft | expression_web | — | — |
| microsoft | forefront_client_security | — | — |
| microsoft | internet_explorer | — | — |
| microsoft | net_framework | — | — |
| microsoft | net_framework | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office | — | — |
| microsoft | office_compatibility_pack | — | — |
| microsoft | office_groove | — | — |
| microsoft | office_powerpoint_viewer | — | — |
| microsoft | project | — | — |
| microsoft | report_viewer | — | — |
| microsoft | report_viewer | — | — |
| microsoft | sql_server | — | — |
| microsoft | sql_server_reporting_services | — | — |
| microsoft | visio | — | — |
| microsoft | visual_foxpro | — | — |
| microsoft | visual_foxpro | — | — |
| microsoft | visual_studio | — | — |
| microsoft | visual_studio_net | — | — |
| microsoft | visual_studio_net | — | — |
| microsoft | word_viewer | — | — |
| microsoft | works | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4px9-25hv-vh6p: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP
ghsa_unreviewed·2022-05-02
CVE-2009-2500 [HIGH] GHSA-4px9-25hv-vh6p: Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted WMF image file, aka "GDI+ WMF Integer Overflow Vulner
Cisco
Vulnerabilities in Cisco Video Surveillance Products
vendor_cisco·2009-06-24·CVSS 7.8
CVE-2009-2045 [HIGH] CWE-200 Vulnerabilities in Cisco Video Surveillance Products
Vulnerabilities in Cisco Video Surveillance Products
Cisco Video Surveillance Stream Manager firmware for the Cisco Video
Surveillance Services Platforms and Cisco Video Surveillance Integrated
Services Platforms contain a denial of service (DoS) vulnerability that could
result in a reboot on systems that receive a crafted packet.
Cisco Video Surveillance 2500 Series IP Cameras contain an information
disclosure vulnerability that could allow an authenticated user to view any
file on a vulnerable camera.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that mitigate these
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090624-video.
Cisco
Vulnerabilities in Cisco Video Surveillance Products
vendor_cisco
CVE-2009-2046 Vulnerabilities in Cisco Video Surveillance Products
CVE-2009-2046: Vulnerabilities in Cisco Video Surveillance Products
Cisco Video Surveillance Stream Manager firmware for the Cisco Video Surveillance Services Platforms and Cisco Video Surveillance Integrated Services Platforms contain a denial of service (DoS) vulnerability that could result in a reboot on systems that receive a crafted packet. Cisco Video Surveillance 2500 Series IP Cameras contain an information disclosure vulnerability that could allow an authenticated user to view any file on a vulnerable camera. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-200, CWE-399, CWE-200, CWE-399
Bug IDs: CSCsj47924, CSCsu05515, CSCsr96497
Cisco
Vulnerabilities in Cisco Video Surveillance Products
vendor_cisco
CVE-2009-2045 Vulnerabilities in Cisco Video Surveillance Products
CVE-2009-2045: Vulnerabilities in Cisco Video Surveillance Products
Cisco Video Surveillance Stream Manager firmware for the Cisco Video Surveillance Services Platforms and Cisco Video Surveillance Integrated Services Platforms contain a denial of service (DoS) vulnerability that could result in a reboot on systems that receive a crafted packet. Cisco Video Surveillance 2500 Series IP Cameras contain an information disclosure vulnerability that could allow an authenticated user to view any file on a vulnerable camera. Cisco has released software updates that address these vulnerabilities. There are no
CWE: CWE-200, CWE-399, CWE-200, CWE-399
Bug IDs: CSCsj47924, CSCsu05515, CSCsr96497
No detection rules found.
No writeups or analysis indexed.
http://www.us-cert.gov/cas/techalerts/TA09-286A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-062https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5967http://www.us-cert.gov/cas/techalerts/TA09-286A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-062https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5967
2009-10-14
Published