CVE-2009-0689 describes an array index error in the dtoa and gdtoa implementations within libc, affecting various operating systems like FreeBSD, NetBSD, OpenBSD, and applications such as Mozilla Firefox, K-Meleon, and SeaMonkey. This vulnerability allows remote attackers to trigger a denial of service (application crash) and potentially execute arbitrary code by providing a large precision value to printf functions, leading to incorrect memory allocation and a heap-based buffer overflow. With a CVSS score of 6.8 (Medium), the vulnerability has a network attack vector and medium attack complexity, with potential impacts on confidentiality, integrity, and availability. Its FAUCET Risk Score of 97/100 indicates high criticality. While not listed on CISA's KEV catalog, several public exploits exist on ExploitDB targeting K-Meleon, Opera, SeaMonkey, KDE KDELibs, and MATLAB, demonstrating its exploitability. Community discussion and media coverage are present, indicating awareness, though it is not currently considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.5.3CPE matchmatch criteria | cpe:2.3:a:k-meleon_project:k-meleon:1.5.3:*:*:*:*:*:*:* | ||
3.0.1CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:* | ||
3.0.2CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:* | ||
3.0.3CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:* | ||
3.0.4CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.