peter bassill · operator
$ cve CVE-2009-0215 JSON

CVE-2009-0215 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 36.3% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as distributed on IBM and Lenovo computers, allows remote attackers to execute arbitrary code via unspecified vectors.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS36.31% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-03-25
Last modified2026-06-16

Affected (1)

VendorProduct
ibmaccess support activex control

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD