← Vulnerability feed

Vulnerability record · CVE-2009-3711 · published 16 October 2009

CVE-2009-3711: httpdx HTTP GET stack buffer overflow in h_handlepeer

Jasper · Httpdx

httpdx 1.4 (and possibly 1.4.3) contains a stack-based buffer overflow in the h_handlepeer function in http.cpp, triggered by a long HTTP GET request. A remote, unauthenticated attacker can crash the server and possibly execute arbitrary code, making this a full-impact flaw for any exposed instance.

10.0 CVSS 2.0 High EPSS 64% · top 0.8% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network, unauthenticated, full-impact characteristics and public exploit references, though no confirmed in-the-wild exploitation per KEV.

What it is

httpdx 1.4 (and possibly 1.4.3) contains a stack-based buffer overflow in the h_handlepeer function in http.cpp, triggered by a long HTTP GET request. A remote, unauthenticated attacker can crash the server and possibly execute arbitrary code, making this a full-impact flaw for any exposed instance.

Impact

An attacker gains the ability to crash the httpdx service and potentially execute arbitrary code with the privileges of the server process, which per the CVSS vector implies full confidentiality, integrity and availability loss.

Attack surface

Reachable over the network via a crafted HTTP GET request to the httpdx listener; no authentication or user interaction is required (AV:N/AC:L/Au:N).

Exploitation

Public exploit references are tagged in the record, and EPSS is high (0.639, 99th percentile), but the CVE is not listed in CISA KEV, so active exploitation in the wild is not confirmed by the supplied data.

What to do

  • Upgrade httpdx to a version later than 1.4.3 if one is available; the record does not name a fixed version, so verify with the vendor.
  • If no patch exists, remove httpdx from internet-facing exposure or place it behind a reverse proxy that enforces strict request-line length limits.
  • Restrict network access to the httpdx service to trusted hosts only.
  • Run the service under a low-privilege account and enable OS-level exploit mitigations (ASLR, DEP) to limit code execution impact.
  • Monitor vendor advisories for httpdx for a fixed release.

Detection

  • Inspect HTTP server logs for abnormally long GET request lines or request URIs targeting httpdx.
  • Alert on httpdx process crashes or restarts, which may indicate a failed overflow attempt.
  • Use network IDS signatures for oversized HTTP GET requests to the httpdx port.
  • Watch for unexpected child processes or outbound connections spawned by the httpdx process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-3711 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-3663Jasper httpdx vulnerabilityFormat string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (cr…EPSS 15%9.3CVE-2009-4769Jasper httpdx vulnerabilityMultiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbit…EPSS 38%7.5CVE-2009-4770Jasper httpdx vulnerabilityThe FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it eas…EPSS 1.3%5.0CVE-2009-4531Jasper httpdx information exposure vulnerabilityhttpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.EPSS 7.1%9.5CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2009-3711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.