CVE-2009-4776

critical

Description

Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF image processing APIs by a Java application, and a different issue from CVE-2007-3794.

References

http://www.vupen.com/english/advisories/2009/2574

http://www.securityfocus.com/bid/36309

http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS09-014/index.html

http://secunia.com/advisories/36622

http://osvdb.org/57834

Details

Source: Mitre, NVD

Published: 2010-04-21

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.01341