Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-2625

33
FAUCET Score

CVE-2009-2625 describes a denial-of-service vulnerability in Apache Xerces2 Java, affecting Sun Java Runtime Environment (JRE) and other products, where malformed XML input can trigger an infinite loop and application hang. This vulnerability has a CVSS score of 5.0, indicating a medium severity, with a network attack vector, low attack complexity, and a partial impact on availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
1.5.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.5.0:-:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.5.0:update1:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.5.0:update10:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.5.0:update11:*:*:*:*:*:*
1.5.0CPE matchmatch criteria
cpe:2.3:a:oracle:jdk:1.5.0:update12:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
30.38%
Probability of exploitation in next 30 days
EPSS Percentile
98.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.3038 is in the 98th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (113)

mavenpatch availablevia ghsa
Product: xerces:xercesImplFixed in: 2.10.0
redhatpatch availablevia redhat_api
Product: Extras for RHEL 3Fixed in: java-1.4.2-ibm-0:1.4.2.13.1-1jpp.1.el3
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-sun-0:1.5.0.20-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.6.0-sun-1:1.6.0.15-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.5.0-ibm-1:1.5.0.10-1jpp.4.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.4.2-ibm-0:1.4.2.13.1-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Extras for RHEL 4Fixed in: java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: glassfish-javamail-0:1.4.2-0jpp.ep1.5.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: glassfish-jsf-0:1.2_13-2.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hibernate3-annotations-0:3.3.1-1.11.GA_CP02.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: hibernate3-entitymanager-0:3.3.2-2.5.GA_CP01.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jacorb-0:2.3.0-1jpp.ep1.9.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jakarta-commons-logging-jboss-0:1.1-9.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-aop-0:1.5.5-3.CP04.2.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossas-0:4.2.0-5.GA_CP08.5.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-common-0:1.2.1-0jpp.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-remoting-0:2.2.3-3.SP1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jboss-seam-0:1.2.1-1.ep1.22.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jcommon-0:1.0.16-1.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jfreechart-0:1.0.13-2.3.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: jgroups-1:2.4.7-1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: quartz-0:1.5.2-1jpp.patch01.ep1.4.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: rh-eap-docs-0:4.2.0-6.GA_CP08.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: xerces-j2-0:2.7.1-9jpp.4.patch_02.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 4Fixed in: xml-security-0:1.3.0-1.3.patch01.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: glassfish-jsf-0:1.2_13-2.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: hibernate3-annotations-0:3.3.1-1.11GA_CP02.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: hibernate3-entitymanager-0:3.3.2-2.5.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jacorb-0:2.3.0-1jpp.ep1.9.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-aop-0:1.5.5-3.CP04.2.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossas-0:4.2.0-5.GA_CP08.5.2.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-common-0:1.2.1-0jpp.ep1.3.el5.1
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-remoting-0:2.2.3-3.SP1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jboss-seam-0:1.2.1-1.ep1.14.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jcommon-0:1.0.16-1.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jfreechart-0:1.0.13-2.3.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: jgroups-1:2.4.7-1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: quartz-0:1.5.2-1jpp.patch01.ep1.4.1.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: rh-eap-docs-0:4.2.0-6.GA_CP08.ep1.3.el5
View patch
redhatpatch availablevia redhat_api
Product: JBEAP 4.2.0 for RHEL 5Fixed in: xml-security-0:1.3.0-1.3.patch01.ep1.2.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: java-1.6.0-openjdk-1:1.6.0.0-1.2.b09.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: xerces-j2-0:2.7.1-7jpp.2.el5_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: xerces-j2-0:2.7.1-12.6.el6_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: glassfish-javamail-0:1.4.2-0jpp.ep1.5.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: glassfish-jaxb-0:2.1.4-1.12.patch03.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: glassfish-jsf-0:1.2_13-2.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: hibernate3-annotations-0:3.3.1-1.11.GA_CP02.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: hibernate3-entitymanager-0:3.3.2-2.5.GA_CP01.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jacorb-0:2.3.0-1jpp.ep1.9.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jakarta-commons-logging-jboss-0:1.1-9.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jboss-aop-0:1.5.5-3.CP04.2.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossas-0:4.3.0-6.GA_CP07.4.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jboss-common-0:1.2.1-0jpp.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jboss-messaging-0:1.4.0-3.SP3_CP09.4.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jboss-remoting-0:2.2.3-3.SP1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.18.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jboss-seam2-0:2.0.2.FP-1.ep1.21.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossws-0:2.0.1-4.SP2_CP07.2.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossws-common-0:1.0.0-2.GA_CP05.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jbossws-framework-0:2.0.1-1.GA_CP05.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jcommon-0:1.0.16-1.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jfreechart-0:1.0.13-2.3.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: jgroups-1:2.4.7-1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: quartz-0:1.5.2-1jpp.patch01.ep1.4.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: rh-eap-docs-0:4.3.0-6.GA_CP07.ep1.3.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: xerces-j2-0:2.7.1-9jpp.4.patch_02.1.ep1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4Fixed in: xml-security-0:1.3.0-1.3.patch01.ep1.2.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: glassfish-jaxb-0:2.1.4-1.12.patch03.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: glassfish-jsf-0:1.2_13-2.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: hibernate3-1:3.2.4-1.SP1_CP09.0jpp.ep1.2.4.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: hibernate3-annotations-0:3.3.1-1.11GA_CP02.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: hibernate3-entitymanager-0:3.3.2-2.5.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jacorb-0:2.3.0-1jpp.ep1.9.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jboss-aop-0:1.5.5-3.CP04.2.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossas-0:4.3.0-6.GA_CP07.4.2.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jboss-common-0:1.2.1-0jpp.ep1.3.el5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jboss-messaging-0:1.4.0-3.SP3_CP09.4.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jboss-remoting-0:2.2.3-3.SP1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.12.el5.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jboss-seam2-0:2.0.2.FP-1.ep1.18.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossts-1:4.2.3-1.SP5_CP08.1jpp.ep1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossweb-0:2.0.0-6.CP12.0jpp.ep1.2.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossws-0:2.0.1-4.SP2_CP07.2.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossws-common-0:1.0.0-2.GA_CP05.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jbossws-framework-0:2.0.1-1.GA_CP05.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jcommon-0:1.0.16-1.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jfreechart-0:1.0.13-2.3.1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: jgroups-1:2.4.7-1.ep1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: quartz-0:1.5.2-1jpp.patch01.ep1.4.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: rh-eap-docs-0:4.3.0-6.GA_CP07.ep1.3.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5Fixed in: xml-security-0:1.3.0-1.3.patch01.ep1.2.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Operations Network 3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Portal 5.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Framework Kit 2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: java-1.5.0-sun-0:1.5.0.22-1jpp.1.el4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.3Fixed in: java-1.6.0-ibm-1:1.6.0.7-1jpp.3.el4
View patch
redhatpatch availablevia redhat_api
Product: RHEL 4 for SAPFixed in: java-1.4.2-ibm-0:1.4.2.13.2.sap-1jpp.4.el4_8
View patch
redhatpatch availablevia redhat_api
Product: RHEL 5 for SAPFixed in: java-1.4.2-ibm-0:1.4.2.13.2.sap-1jpp.4.el5_3
View patch
redhatpatch availablevia redhat_api
Product: RHEV Manager version 3.0Fixed in: jasperreports-server-pro-0:4.7.1-2.el6ev
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-sun-0:1.5.0.20-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-sun-1:1.6.0.15-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.5.0-ibm-1:1.5.0.10-1jpp.4.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.4.2-ibm-0:1.4.2.13.1-1jpp.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Supplementary for Red Hat Enterprise Linux 5Fixed in: java-1.6.0-ibm-1:1.6.0.6-1jpp.3.el5
View patch

Vendor Advisories (2)

mavenGHSA-334p-wv2m-w3vpmedium

Denial of service in Apache Xerces2

Jun 15, 2020
redhatCVE-2009-2625Moderate

JDK: XML parsing Denial-Of-Service (6845701)

Aug 5, 2009

References

lists.apple.com / archives/security-announce/2009/Sep/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-10/msg00001.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-10/msg00004.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2009-11/msg00002.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2010-06/msg00001.html
Third Party Advisory
marc.info
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2012-1232.html
Broken Link
rhn.redhat.com / errata/RHSA-2012-1537.html
Broken Link
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/36162
Third Party Advisory
secunia.com / advisories/36176
Third Party Advisory
secunia.com / advisories/36180
Third Party Advisory
secunia.com / advisories/36199
Third Party Advisory
secunia.com / advisories/37300
Third Party Advisory
secunia.com / advisories/37460
Third Party Advisory
secunia.com / advisories/37671
Third Party Advisory
secunia.com / advisories/37754
Third Party Advisory
secunia.com / advisories/38231
Third Party Advisory
secunia.com / advisories/38342
Third Party Advisory
secunia.com / advisories/43300
Third Party Advisory
secunia.com / advisories/50549
Third Party Advisory
slackware.com / security/viewer.php
Third Party Advisory
lists.apache.org / thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5%40%3Csolr-user.lucene.apache.org%3E
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8520
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9356
Third Party Advisory
rhn.redhat.com / errata/RHSA-2009-1199.html
Broken Link
rhn.redhat.com / errata/RHSA-2009-1200.html
Broken Link
rhn.redhat.com / errata/RHSA-2009-1201.html
Broken Link
rhn.redhat.com / errata/RHSA-2009-1636.html
Broken Link
rhn.redhat.com / errata/RHSA-2009-1637.html
Broken Link
rhn.redhat.com / errata/RHSA-2009-1649.html
Broken Link
rhn.redhat.com / errata/RHSA-2009-1650.html
Broken Link
sunsolve.sun.com / search/document.do
Broken LinkPatch
sunsolve.sun.com / search/document.do
Broken LinkPatchVendor Advisory
sunsolve.sun.com / search/document.do
Broken Link
sunsolve.sun.com / search/document.do
Broken Link
svn.apache.org / viewvc/xerces/java/trunk/src/org/apache/xerces/impl/XMLScanner.java
PatchVendor Advisory
redhat.com / archives/fedora-package-announce/2009-August/msg00310.html
Mailing ListThird Party Advisory
redhat.com / archives/fedora-package-announce/2009-August/msg00325.html
Mailing ListThird Party Advisory
cert.fi / en/reports/2009/vulnerability2009085.html
Third Party Advisory
codenomicon.com / labs/xml
Third Party Advisory
debian.org / security/2010/dsa-1984
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
networkworld.com / columnists/2009/080509-xml-flaw.html
Third Party Advisory
openwall.com / lists/oss-security/2009/09/06/1
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2009/10/22/9
Mailing ListPatchThird Party Advisory
openwall.com / lists/oss-security/2009/10/23/6
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2009/10/26/3
Mailing ListThird Party Advisory
oracle.com / technetwork/topics/security/cpujan2010-084891.html
Third Party Advisory
oracle.com / technetwork/topics/security/cpuoct2009-096303.html
Broken Link
redhat.com / support/errata/RHSA-2009-1615.html
Third Party Advisory
redhat.com / support/errata/RHSA-2011-0858.html
Third Party Advisory
securityfocus.com / archive/1/507985/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/35958
Third Party AdvisoryVDB Entry
securitytracker.com / id
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-890-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA09-294A.html
Third Party AdvisoryUS Government Resource
us-cert.gov / cas/techalerts/TA10-012A.html
Third Party AdvisoryUS Government Resource
vmware.com / security/advisories/VMSA-2009-0016.html
Third Party Advisory
vupen.com / english/advisories/2009/2543
Permissions Required
vupen.com / english/advisories/2009/3316
Permissions Required
vupen.com / english/advisories/2011/0359
Permissions Required