Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-2625

Опубликовано: 05 авг. 2009
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

Previously, a denial-of-service flaw was found in Java which allowed the creation of an inifinte loop in XML headers that would consume all CPU resources. This issue was patched and Java is no longer vulnerable to a denial-of-service flaw due to the initiation of an infinte loop by means of XML headers.

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=512921JDK: XML parsing Denial-Of-Service (6845701)

EPSS

Процентиль: 81%
0.01562
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

nvd
больше 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.

debian
больше 16 лет назад

XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime En ...

github
почти 6 лет назад

Denial of service in Apache Xerces2

oracle-oval
почти 15 лет назад

ELSA-2011-0858: xerces-j2 security update (MODERATE)

EPSS

Процентиль: 81%
0.01562
Низкий

5 Medium

CVSS2