Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-1291

EPSS 31.14% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-1291

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and components, EMS Server (aka tibemsd), SmartMQ, iProcess Engine, ActiveMatrix products, and CA Enterprise Communicator, allows remote attackers to execute arbitrary code via "inbound data," as demonstrated by requests to the UDP interface of the RTserver component, and data injection into the TCP stream to tibemsd.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
TIBCO SmartSockets的RTserver组件栈溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TIBCO SmartSockets是用于通过独立通道传输消息的传送框架,RTserver是其中的服务器组件。 SmartSockets的RTserver组件在处理入站请求时存在栈溢出漏洞。如果远程攻击者向RTserver的UDP接口发送了超长请求的话,就可能触发这个溢出,导致执行任意指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-1291

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-1291

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-04-30 · 16 CVEs total

CVE-2009-1313Mozilla Firefox 资源管理错误漏洞
CVE-2009-0663Cmu Perl DBD::Pg 'pg_getline()' 和'getline()'堆缓冲区溢出漏洞
CVE-2009-1255Memcached和MemcacheDB stats maps命令信息泄露漏洞
CVE-2009-1295Apport 本地任意文件删除漏洞
CVE-2009-1339twiki 会话劫持和跨站请求伪造漏洞
CVE-2009-1341Debian Perl DBD::Pg 'quote.c'内存泄露漏洞
CVE-2009-1348McAfee Products 'RAR/ZIP'文件扫描绕过漏洞
CVE-2009-1415GnuTLS 函数库libgnutls "lib/pk-libgcrypt.c" 远程安全漏洞
CVE-2009-1416GnuTLS 函数库libgnutls "lib/gnutls_pk.c" 远程安全漏洞
CVE-2009-1417GnuTLS "gnutls-cli" 远程安全漏洞
CVE-2009-1432Symantec Reporting Server 输入验证错误漏洞
CVE-2009-1434Foswiki 会话劫持和跨站请求伪造漏洞
CVE-2009-1492Adobe Reader "JavaScript API" 远程代码执行漏洞
CVE-2009-1493Adobe Reader "JavaScript API" 方法customDictionaryOpen远程代码执行漏洞
CVE-2009-1494memcached 'process_stat'函数信息泄露漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-1291

No comments yet


Leave a comment