Sploitus

CVE-2009-1885

No indexed exploits for CVE-2009-1885 yet

Stack consumption vulnerability in validators/DTD/DTDScanner.cpp in Apache Xerces C++ 2.7.0 and 2.8.0 allows context-dependent attackers to cause a denial of service (application crash) via vectors involving nested parentheses and invalid byte values in "simply nested DTD structures," as demonstrated by the Codenomicon XML fuzzing framework.

Affected products
Apache Xerces-C
Apache Xerces-c\+\+
= 2.7.0, 2.8.0
CVSS 2.0
4.3 MEDIUM
EPSS
5.3% (92th percentile)
Weakness
CWE-119
NVD status
Modified
Published
2009-08-11
CVE-2009-1885 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2009-1885 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2009-1885 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.