CVE-2009-1234
Estado: ModificadaMedia (4.3)—💥 Exploit
Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 6.52%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
💥 Exploits públicos
Hay código de explotación o plantillas de detección públicos. No es lo mismo que explotación activa confirmada (KEV), pero aumenta el riesgo: parchee con prioridad.
- Publicado en Exploit-DB · Opera 9.64 - 7400 nested elements XML Parsing Remote Crash (30/3/2009)
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html
- http://websecurity.com.ua/3216/
- http://www.securityfocus.com/bid/34298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49522
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5432
- https://www.exploit-db.com/exploits/8320
- http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html
- http://websecurity.com.ua/3216/
- http://www.securityfocus.com/bid/34298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49522
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5432
- https://www.exploit-db.com/exploits/8320
JSON original (NVD)
Mostrar
{
"id": "CVE-2009-1234",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2009-04-02T17:30:00.313",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html",
"source": "cve@mitre.org"
},
{
"url": "http://websecurity.com.ua/3216/",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/34298",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49522",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5432",
"source": "cve@mitre.org"
},
{
"url": "https://www.exploit-db.com/exploits/8320",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-09/msg00001.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://websecurity.com.ua/3216/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/34298",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49522",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5432",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.exploit-db.com/exploits/8320",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Opera 9.64 allows remote attackers to cause a denial of service (application crash) via an XML document containing a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 9.52 is also affected."
},
{
"lang": "es",
"value": "Opera versión 9.64, permite a los atacantes remotos causar una denegación de servicio (bloqueo de aplicación) por medio de un documento XML que contiene una serie larga de etiquetas de inicio sin las etiquetas finales correspondientes. NOTA: más tarde se informó que la versión 9.52 también está afectada."
}
],
"lastModified": "2026-06-16T23:06:49.453",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opera:opera_browser:9.52:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F1B7AA6F-9918-4356-894C-72833B791201"
},
{
"criteria": "cpe:2.3:a:opera:opera_browser:9.64:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "14200693-2B22-42BF-9917-FF4B541D9188"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}