{"cve":{"cve_id":"CVE-2009-0537","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.03592,"epss_percentile":0.8794,"epss_as_of":"2026-06-23","description":"Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0 build 10.0.6030.0 allows context-dependent attackers to cause a denial of service (application crash) via a deep directory tree, related to the fts_level structure member, as demonstrated by (a) du, (b) rm, (c) chmod, and (d) chgrp on OpenBSD; and (e) SearchIndexer.exe on Vista Enterprise.","published_at":"2009-03-09T21:00:00Z","last_modified_at":"2026-06-16T23:05:15.360000Z","cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-189"],"nvd_references":["https://www.exploit-db.com/exploits/8163","http://www.securitytracker.com/id?1021818","http://securityreason.com/achievement_securityalert/60","http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c.diff?r1=1.41%3Br2=1.42%3Bf=h","http://www.securityfocus.com/bid/34008","http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c","http://www.securityfocus.com/archive/1/501505/100/0/threaded"],"vuln_status":"Modified","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:04:55.541086Z"},"effective_severity":null,"badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"interix","product_name":"interix","version_start":"6.0","version_start_inclusive":true,"version_end":"6.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:interix:6.0:*:10.0.6030.0:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":null,"version_start_inclusive":null,"version_end":"4.4","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:*:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.0","version_start_inclusive":true,"version_end":"2.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.0:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.1","version_start_inclusive":true,"version_end":"2.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.1:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.2","version_start_inclusive":true,"version_end":"2.2","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.2:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.3","version_start_inclusive":true,"version_end":"2.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.3:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.4","version_start_inclusive":true,"version_end":"2.4","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.4:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.5","version_start_inclusive":true,"version_end":"2.5","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.5:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.6","version_start_inclusive":true,"version_end":"2.6","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.6:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.7","version_start_inclusive":true,"version_end":"2.7","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.7:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.8","version_start_inclusive":true,"version_end":"2.8","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.8:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"2.9","version_start_inclusive":true,"version_end":"2.9","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:2.9:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.0","version_start_inclusive":true,"version_end":"3.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.0:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.1","version_start_inclusive":true,"version_end":"3.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.1:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.2","version_start_inclusive":true,"version_end":"3.2","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.2:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.3","version_start_inclusive":true,"version_end":"3.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.3:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.4","version_start_inclusive":true,"version_end":"3.4","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.4:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.5","version_start_inclusive":true,"version_end":"3.5","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.5:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.6","version_start_inclusive":true,"version_end":"3.6","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.6:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.7","version_start_inclusive":true,"version_end":"3.7","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.7:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.8","version_start_inclusive":true,"version_end":"3.8","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.8:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"3.9","version_start_inclusive":true,"version_end":"3.9","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:3.9:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"4.0","version_start_inclusive":true,"version_end":"4.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:4.0:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"4.1","version_start_inclusive":true,"version_end":"4.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:4.1:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"4.2","version_start_inclusive":true,"version_end":"4.2","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:*"},{"vendor_slug":"openbsd","vendor_name":"OpenBSD","product_slug":"openbsd","product_name":"OpenBSD","version_start":"4.3","version_start_inclusive":true,"version_end":"4.3","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:openbsd:openbsd:4.3:*:*:*:*:*:*:*"}],"exploit_refs":[],"news":[],"references":[{"url":"https://www.exploit-db.com/exploits/8163","source_type":"EXPLOIT","tags":["exploit"]},{"url":"http://www.securitytracker.com/id?1021818","source_type":"MISC","tags":[]},{"url":"http://securityreason.com/achievement_securityalert/60","source_type":"MISC","tags":[]},{"url":"http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c.diff?r1=1.41%3Br2=1.42%3Bf=h","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/bid/34008","source_type":"MISC","tags":[]},{"url":"http://www.openbsd.org/cgi-bin/cvsweb/src/lib/libc/gen/fts.c","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/archive/1/501505/100/0/threaded","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2009-03-09T21:00:00Z","label":"CVE published","source":null}]}