Unrated severityNVD Advisory· Published Sep 28, 2009· Updated Jun 16, 2026
CVE-2009-2865
CVE-2009-2865
Description
Buffer overflow in the login implementation in the Extension Mobility feature in the Unified Communications Manager Express (CME) component in Cisco IOS 12.4XW, 12.4XY, 12.4XZ, and 12.4YA allows remote attackers to execute arbitrary code or cause a denial of service via crafted HTTP requests, aka Bug ID CSCsq58779.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:cisco:unified_communications_manager_express:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:cisco:unified_communications_manager_express:*:*:*:*:*:*:*:*
- (no CPE)range: 12.4XW, 12.4XY, 12.4XZ, 12.4YA
cpe:2.3:o:cisco:ios:12.4xw:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:o:cisco:ios:12.4xw:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:12.4xy:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:12.4xz:*:*:*:*:*:*:*
- cpe:2.3:o:cisco:ios:12.4ya:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
7- tools.cisco.com/security/center/viewAlert.xnvdPatchVendor Advisory
- www.cisco.com/en/US/products/products_security_advisory09186a0080af8116.shtmlnvdPatchVendor Advisory
- www.vupen.com/english/advisories/2009/2758nvdVendor Advisory
- osvdb.org/58335nvd
- www.securityfocus.com/bid/36498nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/53448nvd
News mentions
0No linked articles in our index yet.