CVE-2009-2944

Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read arbitrary files via crafted TeX commands.

Published: 2009-08-31 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-2944 is rated Moderate Risk (47.7/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.80%). Core evidence: EPSS rose +1.27% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-2944

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.53% 1.80% +1.27%
2 2025-03-30 1.28% 0.53% -0.75%
3 2025-03-29 1.28%

Full EPSS history (5 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-2944

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2009-2944

OS Trackers for CVE-2009-2944

vendor priority summary link
debian not yet assigned CVE-2009-2944 not yet assigned priority: Debian including 1 source packages (ikiwiki), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2009-2944
redhat medium https://access.redhat.com/security/cve/CVE-2009-2944
ubuntu medium CVE-2009-2944 medium priority: Ubuntu including 1 source packages (ikiwiki), 10 status rows across 10 suites (dapper, hardy, intrepid, jaunty, karmic, lucid, maverick, natty, oneiric, upstream): ignored 4, not-affected 4, DNE 1, released 1. https://ubuntu.com/security/CVE-2009-2944

Affected software / configurations for CVE-2009-2944

Vendor Product Version Raw CPE
ikiwiki ikiwiki <= 3.141592 cpe:2.3:a:ikiwiki:ikiwiki:*:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.0 cpe:2.3:a:ikiwiki:ikiwiki:2.0:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.00 cpe:2.3:a:ikiwiki:ikiwiki:2.00:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.1 cpe:2.3:a:ikiwiki:ikiwiki:2.1:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.2 cpe:2.3:a:ikiwiki:ikiwiki:2.2:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.3 cpe:2.3:a:ikiwiki:ikiwiki:2.3:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.4 cpe:2.3:a:ikiwiki:ikiwiki:2.4:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.5 cpe:2.3:a:ikiwiki:ikiwiki:2.5:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.6 cpe:2.3:a:ikiwiki:ikiwiki:2.6:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.6.1 cpe:2.3:a:ikiwiki:ikiwiki:2.6.1:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.7 cpe:2.3:a:ikiwiki:ikiwiki:2.7:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.8 cpe:2.3:a:ikiwiki:ikiwiki:2.8:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.9 cpe:2.3:a:ikiwiki:ikiwiki:2.9:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.10 cpe:2.3:a:ikiwiki:ikiwiki:2.10:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.11 cpe:2.3:a:ikiwiki:ikiwiki:2.11:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.12 cpe:2.3:a:ikiwiki:ikiwiki:2.12:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.13 cpe:2.3:a:ikiwiki:ikiwiki:2.13:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.14 cpe:2.3:a:ikiwiki:ikiwiki:2.14:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.15 cpe:2.3:a:ikiwiki:ikiwiki:2.15:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.16 cpe:2.3:a:ikiwiki:ikiwiki:2.16:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.17 cpe:2.3:a:ikiwiki:ikiwiki:2.17:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.18 cpe:2.3:a:ikiwiki:ikiwiki:2.18:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.19 cpe:2.3:a:ikiwiki:ikiwiki:2.19:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.20 cpe:2.3:a:ikiwiki:ikiwiki:2.20:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.30 cpe:2.3:a:ikiwiki:ikiwiki:2.30:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.31 cpe:2.3:a:ikiwiki:ikiwiki:2.31:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.31.1 cpe:2.3:a:ikiwiki:ikiwiki:2.31.1:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.31.2 cpe:2.3:a:ikiwiki:ikiwiki:2.31.2:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.31.3 cpe:2.3:a:ikiwiki:ikiwiki:2.31.3:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.40 cpe:2.3:a:ikiwiki:ikiwiki:2.40:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.41 cpe:2.3:a:ikiwiki:ikiwiki:2.41:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.42 cpe:2.3:a:ikiwiki:ikiwiki:2.42:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.43 cpe:2.3:a:ikiwiki:ikiwiki:2.43:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.44 cpe:2.3:a:ikiwiki:ikiwiki:2.44:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.45 cpe:2.3:a:ikiwiki:ikiwiki:2.45:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.46 cpe:2.3:a:ikiwiki:ikiwiki:2.46:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.47 cpe:2.3:a:ikiwiki:ikiwiki:2.47:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.48 cpe:2.3:a:ikiwiki:ikiwiki:2.48:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.49 cpe:2.3:a:ikiwiki:ikiwiki:2.49:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.50 cpe:2.3:a:ikiwiki:ikiwiki:2.50:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.51 cpe:2.3:a:ikiwiki:ikiwiki:2.51:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.52 cpe:2.3:a:ikiwiki:ikiwiki:2.52:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.53 cpe:2.3:a:ikiwiki:ikiwiki:2.53:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.54 cpe:2.3:a:ikiwiki:ikiwiki:2.54:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.55 cpe:2.3:a:ikiwiki:ikiwiki:2.55:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.56 cpe:2.3:a:ikiwiki:ikiwiki:2.56:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.60 cpe:2.3:a:ikiwiki:ikiwiki:2.60:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.61 cpe:2.3:a:ikiwiki:ikiwiki:2.61:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.62 cpe:2.3:a:ikiwiki:ikiwiki:2.62:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.62.1 cpe:2.3:a:ikiwiki:ikiwiki:2.62.1:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.63 cpe:2.3:a:ikiwiki:ikiwiki:2.63:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.64 cpe:2.3:a:ikiwiki:ikiwiki:2.64:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.65 cpe:2.3:a:ikiwiki:ikiwiki:2.65:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.66 cpe:2.3:a:ikiwiki:ikiwiki:2.66:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.67 cpe:2.3:a:ikiwiki:ikiwiki:2.67:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.68 cpe:2.3:a:ikiwiki:ikiwiki:2.68:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.69 cpe:2.3:a:ikiwiki:ikiwiki:2.69:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.70 cpe:2.3:a:ikiwiki:ikiwiki:2.70:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.71 cpe:2.3:a:ikiwiki:ikiwiki:2.71:*:*:*:*:*:*:*
ikiwiki ikiwiki 2.72 cpe:2.3:a:ikiwiki:ikiwiki:2.72:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.0 cpe:2.3:a:ikiwiki:ikiwiki:3.0:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.00 cpe:2.3:a:ikiwiki:ikiwiki:3.00:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.01 cpe:2.3:a:ikiwiki:ikiwiki:3.01:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.02 cpe:2.3:a:ikiwiki:ikiwiki:3.02:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.03 cpe:2.3:a:ikiwiki:ikiwiki:3.03:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.04 cpe:2.3:a:ikiwiki:ikiwiki:3.04:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.06 cpe:2.3:a:ikiwiki:ikiwiki:3.06:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.07 cpe:2.3:a:ikiwiki:ikiwiki:3.07:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.08 cpe:2.3:a:ikiwiki:ikiwiki:3.08:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.09 cpe:2.3:a:ikiwiki:ikiwiki:3.09:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.10 cpe:2.3:a:ikiwiki:ikiwiki:3.10:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.11 cpe:2.3:a:ikiwiki:ikiwiki:3.11:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.12 cpe:2.3:a:ikiwiki:ikiwiki:3.12:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.13 cpe:2.3:a:ikiwiki:ikiwiki:3.13:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.14 cpe:2.3:a:ikiwiki:ikiwiki:3.14:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.141 cpe:2.3:a:ikiwiki:ikiwiki:3.141:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.1415 cpe:2.3:a:ikiwiki:ikiwiki:3.1415:*:*:*:*:*:*:*
ikiwiki ikiwiki 3.14159 cpe:2.3:a:ikiwiki:ikiwiki:3.14159:*:*:*:*:*:*:*

References for CVE-2009-2944

cvelogic Threat Intelligence