{"api_version":"1","generated_at":"2026-07-23T14:52:37+00:00","cve":"CVE-2009-0218","urls":{"html":"https://cve.report/CVE-2009-0218","api":"https://cve.report/api/cve/CVE-2009-0218.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-0218","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-0218"},"summary":{"title":"CVE-2009-0218","description":"Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors.","state":"PUBLISHED","assigner":"certcc","published_at":"2009-04-13 16:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/MAPG-7PYRP4","name":"http://www.kb.cert.org/vuls/id/MAPG-7PYRP4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"LDRA Software Technology Information for VU#908801","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34395","name":"http://www.securityfocus.com/bid/34395","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Particle Software IntraLaunch ActiveX Control Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/WDON-7Q4RZN","name":"http://www.kb.cert.org/vuls/id/WDON-7Q4RZN","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"Particle Software Information for VU#908801","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/908801","name":"http://www.kb.cert.org/vuls/id/908801","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#908801 - Particle Software IntraLaunch Application Launcher ActiveX control fails to restrict access to dangerous methods","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49684","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-0218","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-0218","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"218","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ldra","cpe5":"tbbrowse","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"218","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"particlesoftware","cpe5":"intralaunch","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T04:24:18.308Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"34395","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34395"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/WDON-7Q4RZN"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/MAPG-7PYRP4"},{"name":"VU#908801","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/908801"},{"name":"intralaunch-activex-code-execution(49684)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49684"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-04-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-07T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"34395","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34395"},{"tags":["x_refsource_MISC"],"url":"http://www.kb.cert.org/vuls/id/WDON-7Q4RZN"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kb.cert.org/vuls/id/MAPG-7PYRP4"},{"name":"VU#908801","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/908801"},{"name":"intralaunch-activex-code-execution(49684)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49684"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2009-0218","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"34395","refsource":"BID","url":"http://www.securityfocus.com/bid/34395"},{"name":"http://www.kb.cert.org/vuls/id/WDON-7Q4RZN","refsource":"MISC","url":"http://www.kb.cert.org/vuls/id/WDON-7Q4RZN"},{"name":"http://www.kb.cert.org/vuls/id/MAPG-7PYRP4","refsource":"CONFIRM","url":"http://www.kb.cert.org/vuls/id/MAPG-7PYRP4"},{"name":"VU#908801","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/908801"},{"name":"intralaunch-activex-code-execution(49684)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49684"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2009-0218","datePublished":"2009-04-13T16:00:00.000Z","dateReserved":"2009-01-20T00:00:00.000Z","dateUpdated":"2024-08-07T04:24:18.308Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-04-13 16:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:ldra:tbbrowse:*:*:*:*:*:*:*:*","matchCriteriaId":"895AFA6E-E2D0-4B53-8AF5-E282B1A92372"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:particlesoftware:intralaunch:-:*:*:*:*:*:*:*","matchCriteriaId":"0874C9E8-F91A-4F58-BBD9-CE1B30BD01A0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"218","Ordinal":"1","Title":"CVE-2009-0218","CVE":"CVE-2009-0218","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"218","Ordinal":"1","NoteData":"Insecure method vulnerability in Particle Software IntraLaunch Application Launcher ActiveX control in IntraLaunch.ocx, as used in LDRA TBbrowse and possibly other products, allows remote attackers to execute arbitrary code via unknown vectors.","Type":"Description","Title":"CVE-2009-0218"},{"CveYear":"2009","CveId":"218","Ordinal":"2","NoteData":"2009-04-13","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"218","Ordinal":"3","NoteData":"2017-08-07","Type":"Other","Title":"Modified"}]}}}