VDB

CVE-2009-2850

CVE-2009-2850 PUBLISHED CVSS 9.300000190734863 CRITICAL

Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) LastRecord64, (4) CDFsel64, and other unspecified functions.

EPSS 0.85% · 75.3th percentile

Risk Scores

CVSS 2.0
9.300000190734863
EPSS Score
0.85%
75.3th percentile

Affected Products

VendorProductVersions
n/an/a*
nasa_goddard_space_flight_centercommon_data_format

Timeline

  • Aug 18, 2009 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 2, 2022 CVE Updated
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›