Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-2409

EPSS 2.21% · P85
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-2409

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other products support MD2 with X.509 certificates, which might allow remote attackers to spoof certificates by using MD2 design flaws to generate a hash collision in less than brute-force time. NOTE: the scope of this issue is currently limited because the amount of computation required is still large.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Network Security Services 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Network Security Services(NSS)是一套用于跨平台开发且启用了安全功能的客户端和服务器应用的库,用NSS编译的应用可支持SSLv2、SSLv3、TLS等安全标准。 Network Security Services存在加密问题漏洞,该漏洞源于网络系统或产品未正确使用相关密码算法,导致内容未正确加密、弱加密、明文存储敏感信息等。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-2409

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-2409

Please Login to view more intelligence information

Same Patch Batch · n/a · 2009-07-30 · 16 CVEs total

CVE-2009-1168Cisco IOS畸形BGP报文触发内存崩溃导致拒绝服务漏洞
CVE-2009-2049Cisco IOS畸形BGP报文更新重载导致拒绝服务漏洞
CVE-2009-2410Fedora SSSD BE数据库空口令绕过认证漏洞
CVE-2008-6879Apache Roller 跨站脚本攻击漏洞
CVE-2008-6880EasySiteNetwork Free Jokes Website 脚本joke.php SQL注入漏洞
CVE-2008-6881Joompolitan Live Chat多个SQL注入漏洞
CVE-2008-6882Joompolitan Live Chat公开HTTP代理脚本xmlhttp.php安全漏洞
CVE-2009-2408Mozilla NSS空字符CA SSL证书验证绕过安全限制漏洞
CVE-2009-2646RIM Xpdf JBIG2解码器JBIG2多个缓冲区溢出和拒绝服务漏洞
CVE-2009-2647Kaspersky Anti-Virus And Kaspersky Internet Security 未明安全绕过漏洞
CVE-2009-2648FlashDen Guestbook 脚本phpinfo.php 信息泄露漏洞
CVE-2009-2649FreeBSD 驱动IATA 本地拒绝服务漏洞
CVE-2009-2650Sorcerer Software MultiMedia Jukebox多个堆缓冲区溢出和代码执行漏洞
CVE-2008-6883Joompolitan Live Chat SQL注入漏洞
CVE-2009-2651Digium Asterisk文本帧处理RTP拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-2409

No comments yet


Leave a comment