CVE-2009-0647

high

Description

msnmsgr.exe in Windows Live Messenger (WLM) 2009 build 14.0.8064.206, and other 14.0.8064.x builds, allows remote attackers to cause a denial of service (application crash) via a modified header in a packet, as possibly demonstrated by a UTF-8.0 value of the charset field in the Content-Type header line. NOTE: this has been reported as a format string vulnerability by some sources, but the provenance of that information is unknown.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/48810

http://www.vupen.com/english/advisories/2009/0466

http://www.securityfocus.com/bid/33825

http://www.securityfocus.com/archive/1/501043/100/0/threaded

http://secunia.com/advisories/33985

Details

Source: Mitre, NVD

Published: 2009-02-19

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High

EPSS

EPSS: 0.18577