{"api_version":"1","generated_at":"2026-07-23T08:13:05+00:00","cve":"CVE-2009-3476","urls":{"html":"https://cve.report/CVE-2009-3476","api":"https://cve.report/api/cve/CVE-2009-3476.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3476","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3476"},"summary":{"title":"CVE-2009-3476","description":"Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-29 23:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53471","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36514","name":"http://www.securityfocus.com/bid/36514","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"OpenSAML URI Handling Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/36869","name":"http://secunia.com/advisories/36869","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"XMLTooling-C URL Handling Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36870","name":"http://secunia.com/advisories/36870","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"OpenSAML URL Handling Buffer Overflow Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://shibboleth.internet2.edu/secadv/secadv_20090826.txt","name":"http://shibboleth.internet2.edu/secadv/secadv_20090826.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Shibboleth - InCommon","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3476","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3476","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"opensaml","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"opensaml","cpe6":"1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"1.3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"1.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"1.3.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"1.3f","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"shibboleth-sp","cpe6":"2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"xmltooling","cpe6":"1.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"xmltooling","cpe6":"1.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"xmltooling","cpe6":"1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"xmltooling","cpe6":"1.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3476","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"internet2","cpe5":"xmltooling","cpe6":"1.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:31:09.966Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36870","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36870"},{"name":"36514","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36514"},{"name":"36869","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36869"},{"name":"opensaml-xmltooling-url-bo(53471)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53471"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://shibboleth.internet2.edu/secadv/secadv_20090826.txt"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-08-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"36870","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36870"},{"name":"36514","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36514"},{"name":"36869","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36869"},{"name":"opensaml-xmltooling-url-bo(53471)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53471"},{"tags":["x_refsource_CONFIRM"],"url":"http://shibboleth.internet2.edu/secadv/secadv_20090826.txt"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3476","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"36870","refsource":"SECUNIA","url":"http://secunia.com/advisories/36870"},{"name":"36514","refsource":"BID","url":"http://www.securityfocus.com/bid/36514"},{"name":"36869","refsource":"SECUNIA","url":"http://secunia.com/advisories/36869"},{"name":"opensaml-xmltooling-url-bo(53471)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53471"},{"name":"http://shibboleth.internet2.edu/secadv/secadv_20090826.txt","refsource":"CONFIRM","url":"http://shibboleth.internet2.edu/secadv/secadv_20090826.txt"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3476","datePublished":"2009-09-29T23:00:00.000Z","dateReserved":"2009-09-29T00:00:00.000Z","dateUpdated":"2024-08-07T06:31:09.966Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-29 23:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:1.3.1:*:*:*:*:*:*:*","matchCriteriaId":"CE02AD93-8ED6-46F1-81D8-B70CB9EB79BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:1.3.2:*:*:*:*:*:*:*","matchCriteriaId":"A6CF3BEC-262B-4901-8D73-D8BB1869A166"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:1.3.3:*:*:*:*:*:*:*","matchCriteriaId":"6C44598D-2BB6-48AB-81E8-3789D0056B68"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:1.3f:*:*:*:*:*:*:*","matchCriteriaId":"4515685C-B170-4829-9261-8FAD5C9F1874"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:opensaml:1.1:*:*:*:*:*:*:*","matchCriteriaId":"619E183F-BAA6-4964-8B58-175856734146"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:opensaml:1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"759EB34A-48FB-43E8-9030-545E41622371"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:xmltooling:1.0.1:*:*:*:*:*:*:*","matchCriteriaId":"B2D36F93-B9DE-422C-AD73-3D8AA58DB6BE"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:xmltooling:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"F5FCBF08-0DD9-4899-B4F5-5D7BFB0B5830"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:xmltooling:1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"5457FF44-CB80-486B-B3B2-D40F34565976"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:xmltooling:1.2.0:*:*:*:*:*:*:*","matchCriteriaId":"5C3A371A-AF3E-44E5-8854-C5D61FF5660C"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:xmltooling:1.2.1:*:*:*:*:*:*:*","matchCriteriaId":"AB54B310-7562-48E3-A514-04D70AF7A28B"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:2.0:*:*:*:*:*:*:*","matchCriteriaId":"8FC9CB94-188C-4BE2-AD8E-EBBA5BA3731E"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:2.1:*:*:*:*:*:*:*","matchCriteriaId":"B9E3DA80-673A-47D7-BDE2-0AC112BB6C4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:internet2:shibboleth-sp:2.2:*:*:*:*:*:*:*","matchCriteriaId":"673CCD0B-9202-4EBA-96B2-11A438E8D464"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3476","Ordinal":"1","Title":"CVE-2009-3476","CVE":"CVE-2009-3476","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3476","Ordinal":"1","NoteData":"Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.","Type":"Description","Title":"CVE-2009-3476"},{"CveYear":"2009","CveId":"3476","Ordinal":"2","NoteData":"2009-09-29","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3476","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}