CVE-2009-0689

Array index error - DoS

Title source: llm

Description

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

Exploits (12)

exploitdb STUB VERIFIED
by Maksymilian Arciemowicz · cdososx
https://www.exploit-db.com/exploits/33479
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · textdoslinux
https://www.exploit-db.com/exploits/33480
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · textremotemultiple
https://www.exploit-db.com/exploits/33363
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · textremotelinux
https://www.exploit-db.com/exploits/33364
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz & sp3x · textdoslinux
https://www.exploit-db.com/exploits/10184
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz & sp3x · textdosbsd
https://www.exploit-db.com/exploits/10185
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz & sp3x · textdosbsd
https://www.exploit-db.com/exploits/10187
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz & sp3x · textdosbsd
https://www.exploit-db.com/exploits/10186
exploitdb WORKING POC VERIFIED
by Alin Rad Pop · textdoslinux
https://www.exploit-db.com/exploits/33312
exploitdb WORKING POC VERIFIED
by Maksymilian Arciemowicz · textdosmultiple
https://www.exploit-db.com/exploits/33058
exploitdb WRITEUP
by Maksymilian Arciemowicz & sp3x · perlremotewindows
https://www.exploit-db.com/exploits/10380
nomisec WORKING POC 83 stars
by Fullmetal5 · poc
https://github.com/Fullmetal5/str2hax

Scores

EPSS 0.4176
EPSS Percentile 97.4%

Details

CWE
CWE-119
Status published
Products (24)
freebsd/freebsd 6.4 (7 CPE variants)
freebsd/freebsd 7.2 (3 CPE variants)
k-meleon_project/k-meleon 1.5.3
mozilla/firefox 3.0.1
mozilla/firefox 3.0.2
mozilla/firefox 3.0.3
mozilla/firefox 3.0.4
mozilla/firefox 3.0.5
mozilla/firefox 3.0.6
mozilla/firefox 3.0.7
... and 14 more
Published Jul 01, 2009
Tracked Since Feb 18, 2026