Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-2473

neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.082
EPSS Ranking 91.8%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2009-2473
  • Webdav » Neon » Version: 0.28.6
    cpe:2.3:a:webdav:neon:0.28.6


Contact Us

Shodan ® - All rights reserved