VDB

DEBIAN-CVE-2009-1885

DEBIAN-CVE-2009-1885 PUBLISHED CVSS 9.300000190734863 CRITICAL

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:13xerces-c0, 0, 0
Debian:14xerces-c0, 0, 0
Debian:12xerces-c0, 0, 0
Debian:11xerces-c0, 0, 0

Timeline

  • Aug 11, 2009 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›