cbcvebase.
CVE-2009-2625
published 2009-08-06

CVE-2009-2625: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20…

PriorityP434medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
30.38%
98.0th percentile
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Affected

71 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server>= 2.0.35 < 2.0.642.0.64
apachehttp_server>= 2.2.0 < 2.2.172.2.17
apachexerces2_java
artifexghostscript>= 0 < 8.71~dfsg-28.71~dfsg-2
artifexghostscript>= 0 < 8.71~dfsg-28.71~dfsg-2
artifexghostscript>= 0 < 8.71~dfsg-28.71~dfsg-2
artifexghostscript>= 0 < 8.71~dfsg-28.71~dfsg-2
audacityteamaudacity>= 0 < 1.3.2-11.3.2-1
audacityteamaudacity>= 0 < 1.3.2-11.3.2-1
audacityteamaudacity>= 0 < 1.3.2-11.3.2-1
audacityteamaudacity>= 0 < 1.3.2-11.3.2-1
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianaudacity< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)
debiancadaver< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)
debiancmake< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)
debiancoin3< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)
debiandebian_linux
debiandebian_linux
debianexpat< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)
debiangdcm< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)
debianghostscript< audacity 1.3.2-1 (bookworm)audacity 1.3.2-1 (bookworm)

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.