Unknown
CVE-2009-0323
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an “HTML GI” in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- amaya,
- amaya 0.9,
- amaya 0.95b,
- amaya 1.0,
- amaya 1.0a,
- amaya 1.1,
- amaya 1.1a,
- amaya 1.1c,
- amaya 1.2,
- amaya 1.2a,
- amaya 1.3,
- amaya 1.3a,
- amaya 1.3b,
- amaya 1.4,
- amaya 1.4a,
- amaya 10.0,
- amaya 2.0,
- amaya 2.1,
- amaya 2.2,
- amaya 2.3,
- amaya 2.4,
- amaya 3.0,
- amaya 3.1,
- amaya 3.2,
- amaya 3.2.1,
- amaya 4.0,
- amaya 4.1,
- amaya 4.2,
- amaya 4.2.1,
- amaya 4.3,
- amaya 4.3.1,
- amaya 4.3.2,
- amaya 5.0,
- amaya 5.1,
- amaya 5.2,
- amaya 5.3,
- amaya 6.0,
- amaya 6.1,
- amaya 6.2,
- amaya 6.3,
- amaya 6.4,
- amaya 7.0,
- amaya 7.1,
- amaya 7.2,
- amaya 8.0,
- amaya 8.1,
- amaya 8.1a,
- amaya 8.1b,
- amaya 8.2,
- amaya 8.3,
- amaya 8.4,
- amaya 8.5,
- amaya 8.52,
- amaya 8.6,
- amaya 8.7,
- amaya 8.7.1,
- amaya 8.7.2,
- amaya 8.8.1,
- amaya 8.8.3,
- amaya 8.8.4,
- amaya 8.8.5,
- amaya 9.0,
- amaya 9.1,
- amaya 9.2.1,
- amaya 9.3,
- amaya 9.4,
- amaya 9.5,
- amaya 9.52,
- amaya 9.53,
- amaya 9.54,
- amaya 9.55
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: