CVE-2009-2433: Buffer Overflow
Published Jul 10, 2009
·Updated
Stack-based buffer overflow in the AddFavorite method in Microsoft Internet Explorer allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a long URL in the first argument.
Affected Software
14 affected components
Microsoft ie=8.0b
Microsoft Internet Explorer=7
Microsoft Internet Explorer=7.0.5730-unknown
Microsoft Internet Explorer=7.0-beta
Microsoft Internet Explorer=7.0
Microsoft Internet Explorer=7.0.5730.11
Microsoft Internet Explorer=7.0-beta1
Microsoft Internet Explorer=7.0-beta2
Microsoft Internet Explorer=7.0-beta3
Microsoft Internet Explorer=7.00.5730.1100
Microsoft Internet Explorer=7.00.6000.16386
Microsoft Internet Explorer=7.00.6000.16441
Microsoft Internet Explorer=8.0.6001-beta
Microsoft Internet Explorer=8.0.6001
Event History
Jul 10, 2009
CVE Published
via MITRE·08:25 PM
Data Sourced
via MITRE·08:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2433?
CVE-2009-2433 has a moderate severity level due to the potential for denial of service and application crashes.
2
How do I fix CVE-2009-2433?
To fix CVE-2009-2433, ensure that you are using the latest version of Internet Explorer and apply any available security patches.
3
What versions of Internet Explorer are affected by CVE-2009-2433?
CVE-2009-2433 affects Internet Explorer versions 7 and 8, including various beta releases.
4
What type of vulnerability is CVE-2009-2433?
CVE-2009-2433 is classified as a stack-based buffer overflow vulnerability.
5
Can CVE-2009-2433 be exploited remotely?
Yes, CVE-2009-2433 can be exploited remotely through a specially crafted URL.