← Back

CVE-2009-4417

nvd nist
Published: Dec 24, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages to any recipient address via vectors related to "events not yet mailed."

Affected (61)

Products: Zend: Framework
1 product
Framework
Configuration A
61 vulnerable
Vulnerable SoftwareAffected Versions
Zend
Up to 1.9.6
Version 0.1.3 preview
Version 0.1.4 preview
Version 0.1.5 preview
Version 0.2.0 preview
Version 0.6.0 preview
Version 0.7.0 preview
Version 0.8.0 preview
Version 0.9.0 beta
Version 0.9.1 beta
Version 0.9.2 beta
Version 0.9.3 beta
Version 1.0.0
Version 1.0.0 rc1
Version 1.0.0 rc2
Version 1.0.0 rc3
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0.4
Version 1.5.0
Version 1.5.0 preview
Version 1.5.0 rc1
Version 1.5.0 rc2
Version 1.5.0 rc3
Version 1.5.1
Version 1.5.2
Version 1.5.3
Version 1.6.0
Version 1.6.0 rc1
Version 1.6.0 rc2
Version 1.6.0 rc3
Version 1.6.1
Version 1.6.2
Version 1.7.0
Version 1.7.0 preview
Version 1.7.1
Version 1.7.2
Version 1.7.3
Version 1.7.4
Version 1.7.5
Version 1.7.6
Version 1.7.7
Version 1.7.8
Version 1.8.0
Version 1.8.0 alpha_1
Version 1.8.0 beta_1
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.9.0
Version 1.9.0 alpha_1
Version 1.9.0 beta_1
Version 1.9.0 rc1
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4
Version 1.9.5
Version 1.9

Related CWEs

Timeline

No history available yet.