CVE-2009-1219 describes a denial-of-service vulnerability affecting Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server versions 6 2004Q2 through 6.3-7.01. An unauthenticated remote attacker can crash the daemon by sending multiple requests to the default URI with alphabetic characters in the tzid parameter. This vulnerability has a CVSS score of 5.0, indicating a medium severity with low attack complexity and no authentication required, leading to a partial availability impact. While not listed in CISA's KEV catalog and lacking significant community discussion or media coverage, a public exploit (EDB-32860) exists, demonstrating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6CPE matchmatch criteria | cpe:2.3:a:sun:java_system_calendar_server:6:-:sparc:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:a:sun:java_system_calendar_server:6.3:-:sparc:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:sun:one_calendar_server:6.0:-:sparc:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:sun:java_system_calendar_server:6:-:x86:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:a:sun:java_system_calendar_server:6.3:-:x86:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.