CVE
- Id
- 39928
- CVE No.
- CVE-2009-2493
- Status
- Candidate
- Description
- The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."
- Phase
- Assigned (20090717)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
| Id | CVE Id | CVE No. | Reference | Actions |
|---|---|---|---|---|
| 438818 | 39928 | CVE-2009-2493 | MISC:http://blogs.technet.com/srd/archive/2009/08/11/ms09-037-why-we-are-using-cve-s-already-used-in-ms09-035.aspx | View |
| 438819 | 39928 | CVE-2009-2493 | CONFIRM:http://www.adobe.com/support/security/advisories/apsa09-04.html | View |
| 438820 | 39928 | CVE-2009-2493 | CONFIRM:http://www.adobe.com/support/security/bulletins/apsb09-11.html | View |
| 438821 | 39928 | CVE-2009-2493 | CONFIRM:http://www.adobe.com/support/security/bulletins/apsb09-13.html | View |
| 438822 | 39928 | CVE-2009-2493 | CONFIRM:http://www.adobe.com/support/security/bulletins/apsb09-10.html | View |
| 438823 | 39928 | CVE-2009-2493 | CONFIRM:http://www.openoffice.org/security/cves/CVE-2009-2493.html | View |
| 438824 | 39928 | CVE-2009-2493 | CONFIRM:http://www.novell.com/support/viewContent.do?externalId=7004997&sliceId=1 | View |
| 438825 | 39928 | CVE-2009-2493 | HP:HPSBMA02488 | View |
| 438826 | 39928 | CVE-2009-2493 | URL:http://marc.info/?l=bugtraq&m=126592505426855&w=2 | View |
| 438827 | 39928 | CVE-2009-2493 | HP:SSRT100013 | View |
| 438828 | 39928 | CVE-2009-2493 | URL:http://marc.info/?l=bugtraq&m=126592505426855&w=2 | View |
| 438829 | 39928 | CVE-2009-2493 | MS:MS09-035 | View |
| 438830 | 39928 | CVE-2009-2493 | URL:http://www.microsoft.com/technet/security/Bulletin/MS09-035.mspx | View |
| 438831 | 39928 | CVE-2009-2493 | MS:MS09-037 | View |
| 438832 | 39928 | CVE-2009-2493 | URL:http://www.microsoft.com/technet/security/Bulletin/MS09-037.mspx | View |
| 438833 | 39928 | CVE-2009-2493 | MS:MS09-055 | View |
| 438834 | 39928 | CVE-2009-2493 | URL:http://www.microsoft.com/technet/security/Bulletin/MS09-055.mspx | View |
| 438835 | 39928 | CVE-2009-2493 | MS:MS09-060 | View |
| 438836 | 39928 | CVE-2009-2493 | URL:http://www.microsoft.com/technet/security/Bulletin/MS09-060.mspx | View |
| 438837 | 39928 | CVE-2009-2493 | MS:MS09-072 | View |
| 438838 | 39928 | CVE-2009-2493 | URL:http://www.microsoft.com/technet/security/Bulletin/MS09-072.mspx | View |
| 438839 | 39928 | CVE-2009-2493 | SUNALERT:264648 | View |
| 438840 | 39928 | CVE-2009-2493 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-66-264648-1 | View |
| 438841 | 39928 | CVE-2009-2493 | SUNALERT:266108 | View |
| 438842 | 39928 | CVE-2009-2493 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-66-266108-1 | View |
| 438843 | 39928 | CVE-2009-2493 | SUNALERT:1020775 | View |
| 438844 | 39928 | CVE-2009-2493 | URL:http://sunsolve.sun.com/search/document.do?assetkey=1-77-1020775.1-1 | View |
| 438845 | 39928 | CVE-2009-2493 | SUSE:SUSE-SA:2009:053 | View |
| 438846 | 39928 | CVE-2009-2493 | URL:http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00002.html | View |
| 438847 | 39928 | CVE-2009-2493 | CERT:TA09-195A | View |
| 438848 | 39928 | CVE-2009-2493 | URL:http://www.us-cert.gov/cas/techalerts/TA09-195A.html | View |
| 438849 | 39928 | CVE-2009-2493 | CERT:TA09-223A | View |
| 438850 | 39928 | CVE-2009-2493 | URL:http://www.us-cert.gov/cas/techalerts/TA09-223A.html | View |
| 438851 | 39928 | CVE-2009-2493 | CERT:TA09-286A | View |
| 438852 | 39928 | CVE-2009-2493 | URL:http://www.us-cert.gov/cas/techalerts/TA09-286A.html | View |
| 438853 | 39928 | CVE-2009-2493 | CERT:TA09-342A | View |
| 438854 | 39928 | CVE-2009-2493 | URL:http://www.us-cert.gov/cas/techalerts/TA09-342A.html | View |
| 438855 | 39928 | CVE-2009-2493 | OVAL:oval:org.mitre.oval:def:6245 | View |
| 438856 | 39928 | CVE-2009-2493 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6245 | View |
| 438857 | 39928 | CVE-2009-2493 | OVAL:oval:org.mitre.oval:def:6304 | View |
| 438858 | 39928 | CVE-2009-2493 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6304 | View |
| 438859 | 39928 | CVE-2009-2493 | OVAL:oval:org.mitre.oval:def:6421 | View |
| 438860 | 39928 | CVE-2009-2493 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6421 | View |
| 438861 | 39928 | CVE-2009-2493 | OVAL:oval:org.mitre.oval:def:6473 | View |
| 438862 | 39928 | CVE-2009-2493 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6473 | View |
| 438863 | 39928 | CVE-2009-2493 | OVAL:oval:org.mitre.oval:def:6621 | View |
| 438864 | 39928 | CVE-2009-2493 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6621 | View |
| 438865 | 39928 | CVE-2009-2493 | OVAL:oval:org.mitre.oval:def:6716 | View |
| 438866 | 39928 | CVE-2009-2493 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:6716 | View |
| 438867 | 39928 | CVE-2009-2493 | SECUNIA:36187 | View |
| 438868 | 39928 | CVE-2009-2493 | URL:http://secunia.com/advisories/36187 | View |
| 438869 | 39928 | CVE-2009-2493 | SECUNIA:36374 | View |
| 438870 | 39928 | CVE-2009-2493 | URL:http://secunia.com/advisories/36374 | View |
| 438871 | 39928 | CVE-2009-2493 | SECUNIA:38568 | View |
| 438872 | 39928 | CVE-2009-2493 | URL:http://secunia.com/advisories/38568 | View |
| 438873 | 39928 | CVE-2009-2493 | SECUNIA:36746 | View |
| 438874 | 39928 | CVE-2009-2493 | URL:http://secunia.com/advisories/36746 | View |
| 438875 | 39928 | CVE-2009-2493 | SECUNIA:35967 | View |
| 438876 | 39928 | CVE-2009-2493 | URL:http://secunia.com/advisories/35967 | View |
| 438877 | 39928 | CVE-2009-2493 | SECUNIA:41818 | View |
| 438878 | 39928 | CVE-2009-2493 | URL:http://secunia.com/advisories/41818 | View |
| 438879 | 39928 | CVE-2009-2493 | VUPEN:ADV-2009-2034 | View |
| 438880 | 39928 | CVE-2009-2493 | URL:http://www.vupen.com/english/advisories/2009/2034 | View |
| 438881 | 39928 | CVE-2009-2493 | VUPEN:ADV-2009-2232 | View |
| 438882 | 39928 | CVE-2009-2493 | URL:http://www.vupen.com/english/advisories/2009/2232 | View |
| 438883 | 39928 | CVE-2009-2493 | VUPEN:ADV-2010-0366 | View |
Related JVN
| Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 41226 | JVNDB-2009-002233 | Microsoft .NET Framework および Silverlight におけるインターフェース処理に関する任意のコードを実行される脆弱性 | Microsoft .NET Framework および Silverlight の Common Language Runtime (CLR) には、インターフェース処理を適切に行わないため、任意のコードを実行される脆弱性が存在します。 | CVE-2009-2497 | 39928 | 9.3 | http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002233.html | View |