AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3305

MEDIUM · CVSS 5 EPSS 10.07%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-12-24 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-3305
Severity
MEDIUM
CVSS
5
EPSS
10.07%

Original NVD Description

Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.