AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-1291

HIGH · CVSS 10 EPSS 6.43%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-04-30 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 10.0. It may be remotely exploitable.

CVE
CVE-2009-1291
Severity
HIGH
CVSS
10
EPSS
6.43%

Original NVD Description

Stack-based buffer overflow in TIBCO SmartSockets before 6.8.2, SmartSockets Product Family (aka RTworks) before 4.0.5, and Enterprise Message Service (EMS) 4.0.0 through 5.1.1, as used in SmartSockets Server and RTworks Server (aka RTserver), SmartSockets client libraries and add-on products, RTworks libraries and components, EMS Server (aka tibemsd), SmartMQ, iProcess Engine, ActiveMatrix products, and CA Enterprise Communicator, allows remote attackers to execute arbitrary code via "inbound data," as demonstrated by requests to the UDP interface of the RTserver component, and data injection into the TCP stream to tibemsd.