← back
CVE-2009-3699

CVE-2009-3699

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 62%
from disclosure to weapon392 days
Published on NVDOct 15
1st PoC+392d
metasploitOct 7
exploitation probability
62%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through 6.1.3, and VIOS 2.1 and earlier, allows remote attackers to execute arbitrary code via a long XDR string in the first argument to procedure 21 of rpc.cmsd.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.