CVE-2003-0259
published 2003-05-27CVE-2003-0259: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.13%
79.8th percentile
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | vpn_3000_concentrator | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
| cisco | vpn_3000_concentrator_series_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco VPN 3000 Concentrator Vulnerabilities
vendor_cisco·2003-05-07
CVE-2003-0258 Cisco VPN 3000 Concentrator Vulnerabilities
Cisco VPN 3000 Concentrator Vulnerabilities
This advisory documents vulnerabilities for the Cisco VPN 3000 series
concentrators and Cisco VPN 3002 Hardware Client. These vulnerabilities are
documented as Cisco bug ID CSCea77143 (IPSec over TCP), CSCdz15393 (SSH), and
CSCdt84906 (ICMP). There are workarounds available to mitigate the effects of
these vulnerabilities. Upgrading to the latest version of code for the Cisco
VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client, version 4.0.1
and 3.6.7F, would protect against all of these documented vulnerabilities.
This advisory will be posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20030507-vpn3k.
Cisco
Cisco VPN 3000 Concentrator Vulnerabilities
vendor_cisco
CVE-2003-0259 Cisco VPN 3000 Concentrator Vulnerabilities
CVE-2003-0259: Cisco VPN 3000 Concentrator Vulnerabilities
This advisory documents vulnerabilities for the Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client. These vulnerabilities are documented as Cisco bug ID CSCea77143 (IPSec over TCP), CSCdz15393 (SSH), and CSCdt84906 (ICMP). There are
Bug IDs: CSCea77143, CSCdz15393, CSCdt84906, CSCea77143, CSCdz15393
GHSA
GHSA-fxv2-2jj5-v5wc: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2
ghsa_unreviewed·2022-04-29
CVE-2003-0259 [MEDIUM] GHSA-fxv2-2jj5-v5wc: Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2
Cisco VPN 3000 series concentrators and Cisco VPN 3002 Hardware Client 2.x.x through 3.6.7 allows remote attackers to cause a denial of service (reload) via a malformed SSH initialization packet.
No detection rules found.
No public exploits indexed.
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
blogs_talos·2014-01-14·CVSS 9.8
CVE-2014-0258 [CRITICAL] Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
The first Microsoft Update Tuesday of 2014 is here and it’s a very light month this time around. We’ve got 4 bulletins covering 6 CVEs. What’s remarkable is that there’s no Internet Explorer bulletin this month. There are also no bulletins that are marked critical, all 4 bulletins are marked as important.
The first bulletin, MS14-001, is for Word and Office Web Apps, this bulletin covers 3 CVEs (CVE-2014-0258, CVE-2014-0259 and CVE-2014-0260. They are memory corruption vulnerabilities in Word, which could result in remote code execution.
MS14-002 is a fix for the Windows XP/2003 0-day kernel escalation of privilege vulnerability (CVE-2013-5065) that was being exploited in the wild in tandem with the Adobe Reader vulnerability (CVE-2013-3346). Here an attacker would convince the user to o
Talos
Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
blogs_talos·2014-01-14·CVSS 9.8
CVE-2014-0258 [CRITICAL] Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
## Microsoft Update Tuesday: January 2014, fix for the XP/2003 0-day vulnerability
The first Microsoft Update Tuesday of 2014 is here and it’s a very light month this time around. We’ve got 4 bulletins covering 6 CVEs. What’s remarkable is that there’s no Internet Explorer bulletin this month. There are also no bulletins that are marked critical, all 4 bulletins are marked as important.
The first bulletin, MS14-001 , is for Word and Office Web Apps, this bulletin covers 3 CVEs ( CVE-2014-0258 , CVE-2014-0259 and CVE-2014-0260 . They are memory corruption vulnerabilities in Word, which could result in remote code execution.
MS14-002 is a fix for the Windows XP/2003 0-day kernel escalation of privilege vulnerability ( CVE-2013-5065 ) that was being exploited in the wild in tandem with the
Bugzilla
CVE-2009-0259 openoffice.org: text converter memory corruption via a crafted (1) .doc, (2) .wri, or (3) .rtf Word97 file
bugzilla·2008-12-10·CVSS 9.3
CVE-2009-0259 [CRITICAL] CVE-2009-0259 openoffice.org: text converter memory corruption via a crafted (1) .doc, (2) .wri, or (3) .rtf Word97 file
CVE-2009-0259 openoffice.org: text converter memory corruption via a crafted (1) .doc, (2) .wri, or (3) .rtf Word97 file
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4841 to
the following vulnerability:
The WordPad Text Converter for Word 97 files in Microsoft Windows 2000
SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to
execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf
Word 97 file that triggers memory corruption, as exploited in the wild
in December 2008. NOTE: As of 20081210, it is unclear whether this
vulnerability is related to a WordPad issue disclosed on 20080925 with
a 2008-crash.doc.rar example, but there are insufficient details to be
sure.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4841
http
http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtmlhttp://www.kb.cert.org/vuls/id/317348https://exchange.xforce.ibmcloud.com/vulnerabilities/11955http://www.cisco.com/warp/public/707/cisco-sa-20030507-vpn3k.shtmlhttp://www.kb.cert.org/vuls/id/317348https://exchange.xforce.ibmcloud.com/vulnerabilities/11955
2003-05-27
Published