Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0215 | First vendor Publication | 2009-03-25 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0215 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 |
SAINT Exploits
Description | Link |
---|---|
IBM Access Support ActiveX GetXMLValue buffer overflow | More info here |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
52958 | IBM Access Support ActiveX (IbmEgath.dll) GetXMLValue() Method Overflow A buffer overflow exists in IBM Access Support ActiveX control. IbmEgath.dll fails to validate data passed to the GetXMLValue() method resulting in a stack overflow. With a specially crafted website, a context-dependent attacker can cause arbitrary code execution resulting in a loss of integrity. |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | IBM Access Support ActiveX GetXMLValue method buffer overflow attempt RuleID : 16750 - Revision : 3 - Type : WEB-CLIENT |
2014-01-10 | IBM Access Support ActiveX function call unicode access RuleID : 16749 - Revision : 3 - Type : WEB-ACTIVEX |
2014-01-10 | IBM Access Support ActiveX function call access RuleID : 16748 - Revision : 8 - Type : BROWSER-PLUGINS |
2014-01-10 | IBM Access Support ActiveX clsid unicode access RuleID : 16747 - Revision : 3 - Type : WEB-ACTIVEX |
2014-01-10 | IBM Access Support ActiveX clsid access RuleID : 16746 - Revision : 10 - Type : BROWSER-PLUGINS |
2014-01-10 | IBM Access Support ActiveX GetXMLValue method buffer overflow attempt RuleID : 16610 - Revision : 8 - Type : BROWSER-PLUGINS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-06-01 | Name : The remote Windows host has an ActiveX control that is affected by a buffer o... File : ibmegath_activex_getxmlvalue_overflow.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:48 |
|
2024-11-28 12:18:07 |
|
2021-05-04 12:09:02 |
|
2021-04-22 01:09:23 |
|
2020-05-23 13:16:52 |
|
2020-05-23 00:23:15 |
|
2017-08-08 09:24:39 |
|
2016-06-28 17:33:48 |
|
2016-04-26 18:34:17 |
|
2014-02-17 10:48:28 |
|
2014-01-19 21:25:36 |
|
2013-05-10 23:42:46 |
|