Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0909 | First vendor Publication | 2009-04-06 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0909 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:6251 | |||
Oval ID: | oval:org.mitre.oval:def:6251 | ||
Title: | VMware Heap Overflows in VNnc Codec Lets Remote Users Execute Arbitrary Code | ||
Description: | Heap-based buffer overflow in the VNnc Codec in VMware Workstation 6.5.x before 6.5.2 build 156735, VMware Player 2.5.x before 2.5.2 build 156735, VMware ACE 2.5.x before 2.5.2 build 156735, and VMware Server 2.0.x before 2.0.1 build 156745 allows remote attackers to execute arbitrary code via a crafted web page or video file, aka ZDI-CAN-435. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-0909 | Version: | 2 |
Platform(s): | VMWare ESX Server 3 VMWare ESX Server 3.5 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Application | 1 | |
Application | 1 |
OpenVAS Exploits
Date | Description |
---|---|
2012-10-03 | Name : Gentoo Security Advisory GLSA 201209-25 (vmware-server vmware-player vmware-w... File : nvt/glsa_201209_25.nasl |
2009-05-18 | Name : VMware Products Multiple Vulnerabilities (Linux) Apr09 File : nvt/secpod_vmware_prdts_mult_vuln_lin_apr09.nasl |
2009-05-18 | Name : VMware Products Multiple Vulnerabilities (Win) Apr09 File : nvt/secpod_vmware_prdts_mult_vuln_win_apr09.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
55943 | VMWare Multiple Products VMnc Codec (vmnc.dll) Invalid RFB Message Type Handl... |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2009-04-09 | IAVM : 2009-B-0015 - Multiple Vulnerabilities in VMware Severity : Category I - VMSKEY : V0018638 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2012-10-01 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201209-25.nasl - Type : ACT_GATHER_INFO |
2009-07-27 | Name : The remote VMware ESXi / ESX host is missing one or more security-related pat... File : vmware_VMSA-2009-0005.nasl - Type : ACT_GATHER_INFO |
2009-07-27 | Name : The remote VMware ESXi / ESX host is missing a security-related patch. File : vmware_VMSA-2009-0006.nasl - Type : ACT_GATHER_INFO |
2009-04-09 | Name : The remote host has an application that is affected by multiple issues. File : vmware_multiple_vmsa_2009_0005.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:41 |
|
2024-11-28 12:18:30 |
|
2021-05-04 12:09:16 |
|
2021-04-22 01:09:36 |
|
2020-05-23 00:23:29 |
|
2017-09-29 09:24:07 |
|
2016-04-26 18:41:54 |
|
2014-02-17 10:49:13 |
|
2013-11-11 12:38:14 |
|
2013-05-16 17:02:34 |
|
2013-05-10 23:46:18 |
|