CVE-2000-1123
published 2001-01-09CVE-2000-1123: Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
PriorityP420high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.45%
36.5th percentile
Buffer overflow in pioout command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling While Processing CFF Blend DICT Operator
exploitdb·2019-07-10
CVE-2019-1123 Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling While Processing CFF Blend DICT Operator
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling While Processing CFF Blend DICT Operator
---
-----=====[ Background ]=====-----
AFDKO (Adobe Font Development Kit for OpenType) is a set of tools for examining, modifying and building fonts. The core part of this toolset is a font handling library written in C, which provides interfaces for reading and writing Type 1, OpenType, TrueType (to some extent) and several other font formats. While the library existed as early as 2000, it was open-sourced by Adobe in 2014 on GitHub [1, 2], and is still actively developed. The font parsing code can be generally found under afdko/c/public/lib/source/*read/*.c in the project directory tree.
At the time of this writing, based on the available source code, we conclude that A
Exploit-DB
Microsoft SQL Server - Hello Overflow (MS02-056) (Metasploit)
exploitdb·2010-04-30
CVE-2002-1123 Microsoft SQL Server - Hello Overflow (MS02-056) (Metasploit)
Microsoft SQL Server - Hello Overflow (MS02-056) (Metasploit)
---
##
# $Id: ms02_056_hello.rb 9179 2010-04-30 08:40:19Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Microsoft SQL Server Hello Overflow',
'Description' => %q{
By sending malformed data to TCP port 1433, an
unauthenticated remote attacker could overflow a buffer and
possibly execute code on the server with SYSTEM level
privileges. This module should work against any vulnerable
SQL Server 2000 or MSDE install ( [ 'MC' ],
'License' => MSF_LICENSE,
'Version' => '$Revisi
Exploit-DB
Microsoft SQL Server 2000 - User Authentication Remote Buffer Overflow
exploitdb·2002-08-06·CVSS 2.1
CVE-2002-1123 [LOW] Microsoft SQL Server 2000 - User Authentication Remote Buffer Overflow
Microsoft SQL Server 2000 - User Authentication Remote Buffer Overflow
---
source: https://www.securityfocus.com/bid/5411/info
A vulnerability has been discovered in Microsoft SQL Server that could make it possible for remote attackers to gain access to target hosts.
It is possible for an attacker to cause a buffer overflow condition on the vulnerable SQL server with a malformed login request. This may allow a remote attacker to execute arbitrary code as the SQL Server process.
This vulnerability reportedly occurs even before authentication can proceed.
##
#
# this script tests for the "You had me at hello" overflow
# in MSSQL (tcp/1433)
# Copyright Dave Aitel (2002)
# Bug found by: Dave Aitel (2002)
#
##
#TODO:
#techically we should also go to the UDP 1434 resolver service
#and get
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=97569466809056&w=2http://www-1.ibm.com/support/search.wss?rs=0&q=IY12638&apar=onlyhttp://www.securityfocus.com/bid/2036https://exchange.xforce.ibmcloud.com/vulnerabilities/5617http://marc.info/?l=bugtraq&m=97569466809056&w=2http://www-1.ibm.com/support/search.wss?rs=0&q=IY12638&apar=onlyhttp://www.securityfocus.com/bid/2036https://exchange.xforce.ibmcloud.com/vulnerabilities/5617
2001-01-09
Published