cbcvebase.
CVE-2009-4405
published 2009-12-23

CVE-2009-4405: Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results…

PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.97%
78.2th percentile
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results when using alternate formats" or (2) a "check for the 'raw' role that is missing in docutils < 0.6."

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiantrac< trac 0.11.6-1 (sid)trac 0.11.6-1 (sid)
edgewalltrac<= 0.11.5
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac
edgewalltrac

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.