peter bassill · operator
$ cve CVE-2009-3691 JSON

CVE-2009-3691 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 7% (pctl 94)

Patch early

A public exploit exists.

Description

Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (3) ServerSize, field that triggers a stack-based buffer overflow involving a crafted HostList field. NOTE: some of these details are obtained from third party information.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS7.04% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-189
On CISA KEVno
Public exploityes
Published2009-10-13
Last modified2026-06-16

Affected (2)

VendorProduct
ibminformix client sdk
ibminformix connect runtime

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD