CVE-2009-3000

The sockfs module in the kernel in Sun Solaris 10 and OpenSolaris snv_41 through snv_122, when Network Cache Accelerator (NCA) logging is enabled, allows remote attackers to cause a denial of service (panic) via unspecified web-server traffic that triggers a NULL pointer dereference in the nl7c_http_log function, related to "improper http response handling."

Published: 2009-08-28 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2009-3000 is rated Moderate Risk (49.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.42%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2009-3000

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.11% 0.42% +0.32%
2 2023-03-07 1.05% 0.11% -0.95%
3 2022-02-04 1.05%

Full EPSS history (3 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2009-3000

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.1 2.0 HIGH
AV:N/AC:M/Au:N/C:N/I:N/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:C)
Complete availability impact.
8.6 6.9 [email protected]

Weakness enumeration for CVE-2009-3000

Affected software / configurations for CVE-2009-3000

Vendor Product Version Raw CPE
sun opensolaris snv_41 cpe:2.3:o:sun:opensolaris:snv_41:*:sparc:*:*:*:*:*
sun opensolaris snv_42 cpe:2.3:o:sun:opensolaris:snv_42:*:sparc:*:*:*:*:*
sun opensolaris snv_43 cpe:2.3:o:sun:opensolaris:snv_43:*:sparc:*:*:*:*:*
sun opensolaris snv_44 cpe:2.3:o:sun:opensolaris:snv_44:*:sparc:*:*:*:*:*
sun opensolaris snv_45 cpe:2.3:o:sun:opensolaris:snv_45:*:sparc:*:*:*:*:*
sun opensolaris snv_46 cpe:2.3:o:sun:opensolaris:snv_46:*:sparc:*:*:*:*:*
sun opensolaris snv_47 cpe:2.3:o:sun:opensolaris:snv_47:*:sparc:*:*:*:*:*
sun opensolaris snv_48 cpe:2.3:o:sun:opensolaris:snv_48:*:sparc:*:*:*:*:*
sun opensolaris snv_49 cpe:2.3:o:sun:opensolaris:snv_49:*:sparc:*:*:*:*:*
sun opensolaris snv_50 cpe:2.3:o:sun:opensolaris:snv_50:*:sparc:*:*:*:*:*
sun opensolaris snv_51 cpe:2.3:o:sun:opensolaris:snv_51:*:sparc:*:*:*:*:*
sun opensolaris snv_52 cpe:2.3:o:sun:opensolaris:snv_52:*:sparc:*:*:*:*:*
sun opensolaris snv_53 cpe:2.3:o:sun:opensolaris:snv_53:*:sparc:*:*:*:*:*
sun opensolaris snv_54 cpe:2.3:o:sun:opensolaris:snv_54:*:sparc:*:*:*:*:*
sun opensolaris snv_55 cpe:2.3:o:sun:opensolaris:snv_55:*:sparc:*:*:*:*:*
sun opensolaris snv_56 cpe:2.3:o:sun:opensolaris:snv_56:*:sparc:*:*:*:*:*
sun opensolaris snv_57 cpe:2.3:o:sun:opensolaris:snv_57:*:sparc:*:*:*:*:*
sun opensolaris snv_58 cpe:2.3:o:sun:opensolaris:snv_58:*:sparc:*:*:*:*:*
sun opensolaris snv_59 cpe:2.3:o:sun:opensolaris:snv_59:*:sparc:*:*:*:*:*
sun opensolaris snv_60 cpe:2.3:o:sun:opensolaris:snv_60:*:sparc:*:*:*:*:*
sun opensolaris snv_61 cpe:2.3:o:sun:opensolaris:snv_61:*:sparc:*:*:*:*:*
sun opensolaris snv_62 cpe:2.3:o:sun:opensolaris:snv_62:*:sparc:*:*:*:*:*
sun opensolaris snv_63 cpe:2.3:o:sun:opensolaris:snv_63:*:sparc:*:*:*:*:*
sun opensolaris snv_64 cpe:2.3:o:sun:opensolaris:snv_64:*:sparc:*:*:*:*:*
sun opensolaris snv_65 cpe:2.3:o:sun:opensolaris:snv_65:*:sparc:*:*:*:*:*
sun opensolaris snv_66 cpe:2.3:o:sun:opensolaris:snv_66:*:sparc:*:*:*:*:*
sun opensolaris snv_67 cpe:2.3:o:sun:opensolaris:snv_67:*:sparc:*:*:*:*:*
sun opensolaris snv_68 cpe:2.3:o:sun:opensolaris:snv_68:*:sparc:*:*:*:*:*
sun opensolaris snv_69 cpe:2.3:o:sun:opensolaris:snv_69:*:sparc:*:*:*:*:*
sun opensolaris snv_70 cpe:2.3:o:sun:opensolaris:snv_70:*:sparc:*:*:*:*:*
sun opensolaris snv_71 cpe:2.3:o:sun:opensolaris:snv_71:*:sparc:*:*:*:*:*
sun opensolaris snv_72 cpe:2.3:o:sun:opensolaris:snv_72:*:sparc:*:*:*:*:*
sun opensolaris snv_73 cpe:2.3:o:sun:opensolaris:snv_73:*:sparc:*:*:*:*:*
sun opensolaris snv_74 cpe:2.3:o:sun:opensolaris:snv_74:*:sparc:*:*:*:*:*
sun opensolaris snv_75 cpe:2.3:o:sun:opensolaris:snv_75:*:sparc:*:*:*:*:*
sun opensolaris snv_76 cpe:2.3:o:sun:opensolaris:snv_76:*:sparc:*:*:*:*:*
sun opensolaris snv_77 cpe:2.3:o:sun:opensolaris:snv_77:*:sparc:*:*:*:*:*
sun opensolaris snv_78 cpe:2.3:o:sun:opensolaris:snv_78:*:sparc:*:*:*:*:*
sun opensolaris snv_79 cpe:2.3:o:sun:opensolaris:snv_79:*:sparc:*:*:*:*:*
sun opensolaris snv_80 cpe:2.3:o:sun:opensolaris:snv_80:*:sparc:*:*:*:*:*
sun opensolaris snv_81 cpe:2.3:o:sun:opensolaris:snv_81:*:sparc:*:*:*:*:*
sun opensolaris snv_82 cpe:2.3:o:sun:opensolaris:snv_82:*:sparc:*:*:*:*:*
sun opensolaris snv_83 cpe:2.3:o:sun:opensolaris:snv_83:*:sparc:*:*:*:*:*
sun opensolaris snv_84 cpe:2.3:o:sun:opensolaris:snv_84:*:sparc:*:*:*:*:*
sun opensolaris snv_85 cpe:2.3:o:sun:opensolaris:snv_85:*:sparc:*:*:*:*:*
sun opensolaris snv_86 cpe:2.3:o:sun:opensolaris:snv_86:*:sparc:*:*:*:*:*
sun opensolaris snv_87 cpe:2.3:o:sun:opensolaris:snv_87:*:sparc:*:*:*:*:*
sun opensolaris snv_88 cpe:2.3:o:sun:opensolaris:snv_88:*:sparc:*:*:*:*:*
sun opensolaris snv_89 cpe:2.3:o:sun:opensolaris:snv_89:*:sparc:*:*:*:*:*
sun opensolaris snv_90 cpe:2.3:o:sun:opensolaris:snv_90:*:sparc:*:*:*:*:*
sun opensolaris snv_91 cpe:2.3:o:sun:opensolaris:snv_91:*:sparc:*:*:*:*:*
sun opensolaris snv_92 cpe:2.3:o:sun:opensolaris:snv_92:*:sparc:*:*:*:*:*
sun opensolaris snv_93 cpe:2.3:o:sun:opensolaris:snv_93:*:sparc:*:*:*:*:*
sun opensolaris snv_94 cpe:2.3:o:sun:opensolaris:snv_94:*:sparc:*:*:*:*:*
sun opensolaris snv_95 cpe:2.3:o:sun:opensolaris:snv_95:*:sparc:*:*:*:*:*
sun opensolaris snv_96 cpe:2.3:o:sun:opensolaris:snv_96:*:sparc:*:*:*:*:*
sun opensolaris snv_97 cpe:2.3:o:sun:opensolaris:snv_97:*:sparc:*:*:*:*:*
sun opensolaris snv_98 cpe:2.3:o:sun:opensolaris:snv_98:*:sparc:*:*:*:*:*
sun opensolaris snv_99 cpe:2.3:o:sun:opensolaris:snv_99:*:sparc:*:*:*:*:*
sun opensolaris snv_100 cpe:2.3:o:sun:opensolaris:snv_100:*:sparc:*:*:*:*:*
sun opensolaris snv_101 cpe:2.3:o:sun:opensolaris:snv_101:*:sparc:*:*:*:*:*
sun opensolaris snv_102 cpe:2.3:o:sun:opensolaris:snv_102:*:sparc:*:*:*:*:*
sun opensolaris snv_103 cpe:2.3:o:sun:opensolaris:snv_103:*:sparc:*:*:*:*:*
sun opensolaris snv_104 cpe:2.3:o:sun:opensolaris:snv_104:*:sparc:*:*:*:*:*
sun opensolaris snv_105 cpe:2.3:o:sun:opensolaris:snv_105:*:sparc:*:*:*:*:*
sun opensolaris snv_106 cpe:2.3:o:sun:opensolaris:snv_106:*:sparc:*:*:*:*:*
sun opensolaris snv_107 cpe:2.3:o:sun:opensolaris:snv_107:*:sparc:*:*:*:*:*
sun opensolaris snv_108 cpe:2.3:o:sun:opensolaris:snv_108:*:sparc:*:*:*:*:*
sun opensolaris snv_109 cpe:2.3:o:sun:opensolaris:snv_109:*:sparc:*:*:*:*:*
sun opensolaris snv_110 cpe:2.3:o:sun:opensolaris:snv_110:*:sparc:*:*:*:*:*
sun opensolaris snv_111 cpe:2.3:o:sun:opensolaris:snv_111:*:sparc:*:*:*:*:*
sun opensolaris snv_112 cpe:2.3:o:sun:opensolaris:snv_112:*:sparc:*:*:*:*:*
sun opensolaris snv_113 cpe:2.3:o:sun:opensolaris:snv_113:*:sparc:*:*:*:*:*
sun opensolaris snv_114 cpe:2.3:o:sun:opensolaris:snv_114:*:sparc:*:*:*:*:*
sun opensolaris snv_115 cpe:2.3:o:sun:opensolaris:snv_115:*:sparc:*:*:*:*:*
sun opensolaris snv_116 cpe:2.3:o:sun:opensolaris:snv_116:*:sparc:*:*:*:*:*
sun opensolaris snv_117 cpe:2.3:o:sun:opensolaris:snv_117:*:sparc:*:*:*:*:*
sun opensolaris snv_118 cpe:2.3:o:sun:opensolaris:snv_118:*:sparc:*:*:*:*:*
sun opensolaris snv_119 cpe:2.3:o:sun:opensolaris:snv_119:*:sparc:*:*:*:*:*
sun opensolaris snv_120 cpe:2.3:o:sun:opensolaris:snv_120:*:sparc:*:*:*:*:*

References for CVE-2009-3000

cvelogic Threat Intelligence