The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirOS 10 and earlier, and MidnightBSD 0.3-current allows remote attackers to cause a denial of service (panic) via crafted IP packets that trigger a NULL pointer dereference during translation, related to an IPv4 packet with an ICMPv6 payload.
Conclusion & alert: CVE-2009-0687 is rated High Exploit Risk (78.4/100): CVSS High severity, with high exploitation likelihood (EPSS 12.89%, 94th percentile). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 8581 | exploit_db | edb | 2009-04-30 | Exploit-DB ↗ |
| 8430 | exploit_db | edb | 2009-04-14 | Exploit-DB ↗ |
| 8406 | exploit_db | edb | 2009-04-13 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-26 | 13.58% | 12.89% | -0.69% |
| 2 | 2025-10-11 | 12.33% | 13.58% | +1.25% |
| 3 | 2025-03-30 | — | 12.33% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| midnightbsd | midnightbsd | 0.3-current | cpe:2.3:o:midnightbsd:midnightbsd:0.3-current:*:*:*:*:*:*:* |
| mirbsd | miros | <= 10 | cpe:2.3:o:mirbsd:miros:*:*:*:*:*:*:*:* |
| netbsd | netbsd | 5.0 | cpe:2.3:o:netbsd:netbsd:5.0:*:*:*:*:*:*:* |
| openbsd | openbsd | 4.2 | cpe:2.3:o:openbsd:openbsd:4.2:*:*:*:*:*:*:* |
| openbsd | openbsd | 4.3 | cpe:2.3:o:openbsd:openbsd:4.3:*:*:*:*:*:*:* |
| openbsd | openbsd | 4.4 | cpe:2.3:o:openbsd:openbsd:4.4:*:*:*:*:*:*:* |
| openbsd | openbsd | 4.5 | cpe:2.3:o:openbsd:openbsd:4.5:*:*:*:*:*:*:* |