Sploitus

CVE-2009-1236

1 known exploit for CVE-2009-1236

Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.

Affected products
Macos X, Xnu
Apple Mac Os X
≤ 10.5.6, 10.0, 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, 10.1, 10.1.0, 10.1.1, 10.1.2, 10.1.3, 10.1.4, 10.1.5, 10.2, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 10.2.7, 10.2.8, 10.3, 10.3.0, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.3.6, 10.3.7, 10.3.8, 10.3.9, 10.4, 10.4.0, 10.4.1, 10.4.2, 10.4.3
Fix
Available
CVSS 2.0
10.0 HIGH
EPSS
8.4% (94th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2009-04-02
CVE-2009-1236 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2009-1236

Proof-of-concept code and exploit modules indexed by Sploitus