Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-1926

EPSS 70.54% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-1926

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to cause a denial of service (TCP outage) via a series of TCP sessions that have pending data and a (1) small or (2) zero receive window size, and remain in the FIN-WAIT-1 or FIN-WAIT-2 state indefinitely, aka "TCP/IP Orphaned Connections Vulnerability."
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Windows TCP/IP远程拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows是美国微软(Microsoft)公司发布的一系列操作系统。 由于处理TCP接收窗口大小很小或为0的特制报文中的错误,导致Microsoft Windows的TCP/IP处理中存在拒绝服务漏洞。如果应用关闭了仍要发送数据的TCP连接且攻击者设置了很小的或为0的TCP接收窗口大小,受影响的服务器就无法彻底关闭TCP连接。攻击者可以通过向系统发送大量特制报文来利用这个漏洞,导致受影响的系统停止响应新的请求。即使在攻击者停止发送恶意报文之后系统仍保持无响应。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-1926

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-1926

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-09-08 · 64 CVEs total

CVE-2009-3097HP Performance Insight 信息泄露漏洞
CVE-2008-7176Celina_Jorge FacilCMS目录遍历漏洞
CVE-2008-7179OTManager Cookie Admin/index.php 身份认证绕过漏洞
CVE-2008-7178XOOPS Uploader模块 目录遍历漏洞
CVE-2008-7177NASM 多个缓冲区错误漏洞
CVE-2009-3102zmanda zrm_for_my_sql 输入验证漏洞
CVE-2009-3101Sun Solaris和OpenSolaris 资源管理错误漏洞
CVE-2009-3100Sun Solaris和OpenSolaris拒绝服务攻击漏洞
CVE-2009-3099HP OpenView Operations Manager未明漏洞
CVE-2009-3098HP Operations Dashboard 未明漏洞
CVE-2008-7167Page Manager任意文件上传漏洞
CVE-2009-3096HP Performance Insight 多个未明漏洞
CVE-2009-3095Apache HTTP Server 安全漏洞
CVE-2009-3094Apache 安全漏洞
CVE-2009-3093ASUS WL-500W 无线路由器 未明漏洞
CVE-2009-3092ASUS WL-500W 无线路由器 缓冲区溢出漏洞
CVE-2009-3091ASUS WL-330gE 未明漏洞
CVE-2009-3090IBM Tivoli 目录服务器 未明漏洞
CVE-2009-3089IBM Tivoli 目录服务器 拒绝服务攻击漏洞
CVE-2009-3088ibm tivoli_directory_server 缓冲区溢出漏洞

Showing top 20 of 64 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-1926

No comments yet


Leave a comment