AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-3476

HIGH · CVSS 9.3 EPSS 4.10%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-09-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2009-3476
Severity
HIGH
CVSS
9.3
EPSS
4.10%

Original NVD Description

Buffer overflow in OpenSAML before 1.1.3 as used in Internet2 Shibboleth Service Provider software 1.3.x before 1.3.4, and XMLTooling before 1.2.2 as used in Internet2 Shibboleth Service Provider software 2.x before 2.2.1, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malformed encoded URL.