← Back

CVE-2009-0323

nvd nist
Published: Jan 28, 2009Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.

Affected (71)

Products: W3: Amaya
1 product
Amaya
Configuration A
71 vulnerable
Vulnerable SoftwareAffected Versions
W3
Up to 11.0
Version 0.95b
Version 0.9
Version 1.0
Version 1.0a
Version 1.1
Version 1.1a
Version 1.1c
Version 1.2
Version 1.2a
Version 1.3
Version 1.3a
Version 1.3b
Version 1.4
Version 1.4a
Version 10.0
Version 2.0
Version 2.1
Version 2.2
Version 2.3
Version 2.4
Version 3.0
Version 3.1
Version 3.2.1
Version 3.2
Version 4.0
Version 4.1
Version 4.2.1
Version 4.2
Version 4.3.1
Version 4.3.2
Version 4.3
Version 5.0
Version 5.1
Version 5.2
Version 5.3
Version 6.0
Version 6.1
Version 6.2
Version 6.3
Version 6.4
Version 7.0
Version 7.1
Version 7.2
Version 8.0
Version 8.1
Version 8.1a
Version 8.1b
Version 8.2
Version 8.3
Version 8.4
Version 8.52
Version 8.5
Version 8.6
Version 8.7.1
Version 8.7.2
Version 8.7
Version 8.8.1
Version 8.8.3
Version 8.8.4
Version 8.8.5
Version 9.0
Version 9.1
Version 9.2.1
Version 9.3
Version 9.4
Version 9.52
Version 9.53
Version 9.54
Version 9.55
Version 9.5

References (8)

Timeline

No history available yet.