Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:internet2:shibboleth-sp:1.3.1:*:*:*:*:*:*:*", "matchCriteriaId": "CE02AD93-8ED6-46F1-81D8-B70CB9EB79BF", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:shibboleth-sp:1.3.2:*:*:*:*:*:*:*", "matchCriteriaId": "A6CF3BEC-262B-4901-8D73-D8BB1869A166", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:shibboleth-sp:1.3.3:*:*:*:*:*:*:*", "matchCriteriaId": "6C44598D-2BB6-48AB-81E8-3789D0056B68", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:shibboleth-sp:1.3f:*:*:*:*:*:*:*", "matchCriteriaId": "4515685C-B170-4829-9261-8FAD5C9F1874", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:a:internet2:opensaml:1.1:*:*:*:*:*:*:*", "matchCriteriaId": "619E183F-BAA6-4964-8B58-175856734146", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:opensaml:1.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "759EB34A-48FB-43E8-9030-545E41622371", "vulnerable": true}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:internet2:xmltooling:1.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "B2D36F93-B9DE-422C-AD73-3D8AA58DB6BE", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:xmltooling:1.1.0:*:*:*:*:*:*:*", "matchCriteriaId": "F5FCBF08-0DD9-4899-B4F5-5D7BFB0B5830", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:xmltooling:1.1.1:*:*:*:*:*:*:*", "matchCriteriaId": "5457FF44-CB80-486B-B3B2-D40F34565976", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:xmltooling:1.2.0:*:*:*:*:*:*:*", "matchCriteriaId": "5C3A371A-AF3E-44E5-8854-C5D61FF5660C", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:xmltooling:1.2.1:*:*:*:*:*:*:*", "matchCriteriaId": "AB54B310-7562-48E3-A514-04D70AF7A28B", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:a:internet2:shibboleth-sp:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "8FC9CB94-188C-4BE2-AD8E-EBBA5BA3731E", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:shibboleth-sp:2.1:*:*:*:*:*:*:*", "matchCriteriaId": "B9E3DA80-673A-47D7-BDE2-0AC112BB6C4C", "vulnerable": true}, {"criteria": "cpe:2.3:a:internet2:shibboleth-sp:2.2:*:*:*:*:*:*:*", "matchCriteriaId": "673CCD0B-9202-4EBA-96B2-11A438E8D464", "vulnerable": true}], "negate": false, "operator": "OR"}], "operator": "AND"}], "cveTags": [], "descriptions": [{"lang": "en", "value": "Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL."}, {"lang": "es", "value": "Desbordamiento de b\u00fafer en OpenSAML anterior a v1.1.3 utilizado en Internet2 Shibboleth Service Provider software v1.3.x anterior a v1.3.4, y XMLTooling anterior a v1.2.2 utilizado en Internet2 Shibboleth Service Provider software v2.x anterior a 2.2.1, permite a atacantes remotos provocar una denegaci\u00f3n de servicio y posiblemente ejecutar c\u00f3digo de su elecci\u00f3n a trav\u00e9s de una URL codificada mal formada."}], "id": "CVE-2009-3476", "lastModified": "2025-04-09T00:30:58.490", "metrics": {"cvssMetricV2": [{"acInsufInfo": false, "baseSeverity": "HIGH", "cvssData": {"accessComplexity": "MEDIUM", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "COMPLETE", "baseScore": 9.3, "confidentialityImpact": "COMPLETE", "integrityImpact": "COMPLETE", "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C", "version": "2.0"}, "exploitabilityScore": 8.6, "impactScore": 10.0, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": true}]}, "published": "2009-09-29T23:30:00.267", "references": [{"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/36869"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/36870"}, {"source": "cve@mitre.org", "tags": ["Vendor Advisory"], "url": "http://shibboleth.internet2.edu/secadv/secadv_20090826.txt"}, {"source": "cve@mitre.org", "url": "http://www.securityfocus.com/bid/36514"}, {"source": "cve@mitre.org", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53471"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/36869"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://secunia.com/advisories/36870"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "http://shibboleth.internet2.edu/secadv/secadv_20090826.txt"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "http://www.securityfocus.com/bid/36514"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/53471"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Deferred", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-119"}], "source": "nvd@nist.gov", "type": "Primary"}]}