CVE-2009-4776
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD
Description
Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF image processing APIs by a Java application, and a different issue from CVE-2007-3794.
Affected (295)
Products: Hitachi: Ucosminexus/opentp1 Web Web Front Endset, Ucosminexus Application Server, Ucosminexus Client, Ucosminexus Collaboration, Ucosminexus Developer, Ucosminexus Operator, Ucosminexus Service Architect, Ucosminexus Service Platform, Processing Kit For Xml, Ibm Xl C/c++ V7 For Aix & Hitachi Developer's Kit For Java, Ibm Xl C/c++ V8 For Aix & Hitachi Developer's Kit For Java, Groupmax Collaboration, Electronic Form Workflow Set, Electronic Form Workflow Standard Set, Electronic Form Workflow Professional Set, Electronic Form Workflow Professional Library Set, Electronic Form Workflow Developer Set, Electronic Form Workflow Developer Client Set, Developer's Kit For Java, Cosminexus/opentp1 Web Web Front Endset, Cosminexus Application Server, Cosminexus Client, Cosminexus Studio, Cosminexus Server, Cosminexus Developer
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 02-70-/a | |
| Version 06-70-/a | |
| Version 06-70-/f | |
| Version 06-20-/d | |
| Version 06-70-/f | |
| Version 07-00 | |
| Version 07-00 | |
| Version 07-00 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01-00 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01-00 | |
| Version 01-00 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 07-20-/d |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 07-50-/d |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 06-70-/c |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 07-50-/d |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 06-70-/c |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 07-50-/d |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 06-70-/f |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version 01-00-/b |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 05-00-/i |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 06-00-/i |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 04-00-/a |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 04-00-/a |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 05-00-/i |
References (10)
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.