Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2009-2625

Опубликовано: 06 авг. 2009
Источник: debian
EPSS Низкий

Описание

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
sun-java5fixed1.5.0-20-1package
sun-java5no-dsaetchpackage
sun-java5fixed1.5.0-22-0lenny1lennypackage
sun-java6fixed6-15-1package
sun-java6fixed6-20-0lenny1lennypackage
openjdk-6fixed6b16-1.6-1package
libxerces2-javafixed2.9.1-4.1package

EPSS

Процентиль: 55%
0.00326
Низкий

Связанные уязвимости

ubuntu
почти 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

redhat
почти 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

nvd
почти 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

github
около 5 лет назад

Denial of service in Apache Xerces2

oracle-oval
около 14 лет назад

ELSA-2011-0858: xerces-j2 security update (MODERATE)

EPSS

Процентиль: 55%
0.00326
Низкий