CVE Database
/

CVE-2009-3020

Back to search

CVE-2009-3020

Published: Aug 31, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.

VendorProductVersions

n/a

n/a

affected
n/a

References

36250
third-party-advisory
x_refsource_SECUNIA
57016
vdb-entry
x_refsource_OSVDB
36029
vdb-entry
x_refsource_BID
9417
exploit
x_refsource_EXPLOIT-DB
ms-win-opentype-dos(52403)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now