Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-0689

49
FAUCET Score

CVE-2009-0689 describes an array index error in the dtoa and gdtoa implementations within libc, affecting various operating systems like FreeBSD, NetBSD, OpenBSD, and applications such as Mozilla Firefox, K-Meleon, and SeaMonkey. This vulnerability allows remote attackers to trigger a denial of service (application crash) and potentially execute arbitrary code by providing a large precision value to printf functions, leading to incorrect memory allocation and a heap-based buffer overflow. With a CVSS score of 6.8 (Medium), the vulnerability has a network attack vector and medium attack complexity, with potential impacts on confidentiality, integrity, and availability. Its FAUCET Risk Score of 97/100 indicates high criticality. While not listed on CISA's KEV catalog, several public exploits exist on ExploitDB targeting K-Meleon, Opera, SeaMonkey, KDE KDELibs, and MATLAB, demonstrating its exploitability. Community discussion and media coverage are present, indicating awareness, though it is not currently considered actively exploited.

Impacted Technologies

VendorProductVersion(s)CPE
1.5.3CPE matchmatch criteria
cpe:2.3:a:k-meleon_project:k-meleon:1.5.3:*:*:*:*:*:*:*
3.0.1CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:3.0.1:*:*:*:*:*:*:*
3.0.2CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:3.0.2:*:*:*:*:*:*:*
3.0.3CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:3.0.3:*:*:*:*:*:*:*
3.0.4CPE matchmatch criteria
cpe:2.3:a:mozilla:firefox:3.0.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
28.05%
Probability of exploitation in next 30 days
EPSS Percentile
97.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-33479 · Jan 8, 2010
This CVE's current EPSS score of 0.2805 is in the 98th percentile among its peer group of 19,955 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Extended Update SupportFixed in: php-0:5.1.6-40.el5_9.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: seamonkey-0:1.0.9-0.47.el3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: firefox-0:3.0.15-3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: nspr-0:4.7.6-1.el4_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: seamonkey-0:1.0.9-50.el4_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: kdelibs-6:3.3.1-17.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: thunderbird-0:1.5.0.12-25.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: firefox-0:3.0.15-3.el5_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: nspr-0:4.7.6-1.el5_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xulrunner-0:1.9.0.15-3.el5_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kdelibs-6:3.5.4-25.el5_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: thunderbird-0:2.0.0.24-2.el5_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: php-0:5.1.6-44.el5_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.3 Long LifeFixed in: php-0:5.1.6-23.6.el5_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 Long LifeFixed in: php-0:5.1.6-27.el5_6.7
View patch
mozillavendor investigatingvia nvd_reference
View patch
redhatno patchvia redhat_api
Product: OpenShift Enterprise 1Fixed in: js
redhatno patchvia redhat_api
Product: Red Hat OpenShift Enterprise 2Fixed in: js

Vendor Advisories (1)

redhatCVE-2009-0689Critical

array index error in dtoa implementation of many products

Nov 20, 2009

References

cvsweb.netbsd.org / bsdweb.cgi/src/lib/libc/gdtoa/gdtoaimp.h
Patch
lists.apple.com / archives/security-announce/2010/Jun/msg00003.html
lists.apple.com / archives/security-announce/2010//Mar/msg00001.html
Vendor Advisory
lists.opensuse.org / opensuse-security-announce/2009-11/msg00004.html
lists.opensuse.org / opensuse-security-announce/2010-06/msg00001.html
rhn.redhat.com / errata/RHSA-2014-0311.html
rhn.redhat.com / errata/RHSA-2014-0312.html
bugzilla.mozilla.org / show_bug.cgi
bugzilla.mozilla.org / show_bug.cgi
secunia.com / advisories/37431
Vendor Advisory
secunia.com / advisories/37682
Vendor Advisory
secunia.com / advisories/37683
Vendor Advisory
secunia.com / advisories/38066
Vendor Advisory
secunia.com / advisories/38977
Vendor Advisory
secunia.com / advisories/39001
Vendor Advisory
secunia.com / secunia_research/2009-35
Vendor Advisory
securityreason.com / achievement_securityalert/63
Exploit
securityreason.com / achievement_securityalert/69
securityreason.com / achievement_securityalert/71
securityreason.com / achievement_securityalert/72
securityreason.com / achievement_securityalert/73
securityreason.com / achievement_securityalert/75
securityreason.com / achievement_securityalert/76
securityreason.com / achievement_securityalert/77
securityreason.com / achievement_securityalert/78
securityreason.com / achievement_securityalert/81
securitytracker.com / id
Patch
lists.debian.org / debian-lts-announce/2018/11/msg00001.html
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6528
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9541
sunsolve.sun.com / search/document.do
support.apple.com / kb/HT4077
support.apple.com / kb/HT4225
mandriva.com / security/advisories
mandriva.com / security/advisories
mozilla.org / security/announce/2009/mfsa2009-59.html
Vendor Advisory
openbsd.org / cgi-bin/cvsweb/src/lib/libc/gdtoa/misc.c
PatchVendor Advisory
opera.com / support/kb/view/942
redhat.com / support/errata/RHSA-2009-1601.html
redhat.com / support/errata/RHSA-2010-0153.html
redhat.com / support/errata/RHSA-2010-0154.html
securityfocus.com / archive/1/507977/100/0/threaded
securityfocus.com / archive/1/507979/100/0/threaded
securityfocus.com / archive/1/508417/100/0/threaded
securityfocus.com / archive/1/508423/100/0/threaded
securityfocus.com / bid/35510
ExploitPatch
ubuntu.com / usn/USN-915-1
vupen.com / english/advisories/2009/3297
Vendor Advisory
vupen.com / english/advisories/2009/3299
Vendor Advisory
vupen.com / english/advisories/2009/3334
Vendor Advisory
vupen.com / english/advisories/2010/0094
Vendor Advisory
vupen.com / english/advisories/2010/0648
Vendor Advisory
vupen.com / english/advisories/2010/0650
Vendor Advisory