CVE-2006-0743
published 2006-03-09CVE-2006-0743: Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
6.22%
92.7th percentile
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4net | — | — |
| apache | log4net | >= 0 < 1.2.10 | 1.2.10 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache log4net format string vulnerability causes DoS
osv·2022-05-01
CVE-2006-0743 [MEDIUM] Apache log4net format string vulnerability causes DoS
Apache log4net format string vulnerability causes DoS
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
GHSA
Apache log4net format string vulnerability causes DoS
ghsa·2022-05-01
CVE-2006-0743 [MEDIUM] CWE-134 Apache log4net format string vulnerability causes DoS
Apache log4net format string vulnerability causes DoS
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
CISA ICS
Rockwell Automation AADvance Standalone OPC-DA Server
cisa_ics·2024-08-13·CVSS 5.0
[MEDIUM] Rockwell Automation AADvance Standalone OPC-DA Server
ICS Advisory
##
Rockwell Automation AADvance Standalone OPC-DA Server
Release DateAugust 13, 2024
Alert CodeICSA-24-226-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Rockwell Automation
- Equipment: AADvance Standalone OPC-DA Server
- Vulnerabilities: Improper Input Validation, Use of Externally Controlled Format String
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code in the affected product.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Rockwell Automation AADvance Standalone OPC-DA Server are af
Red Hat
CVE-2006-0743: Format string vulnerability in LocalSyslogAppender in Apache log4net 1
vendor_redhat·CVSS 5.0
CVE-2006-0743 [MEDIUM] CVE-2006-0743: Format string vulnerability in LocalSyslogAppender in Apache log4net 1
Format string vulnerability in LocalSyslogAppender in Apache log4net 1.2.9 might allow remote attackers to cause a denial of service (memory corruption and termination) via unknown vectors.
Statement: Not vulnerable. Red Hat Enterprise Linux 2.1, 3, and 4 do not include log4net.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://issues.apache.org/jira/browse/LOG4NET-67http://secunia.com/advisories/19241http://secunia.com/advisories/22932http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/23905http://www.securityfocus.com/bid/17095http://www.vupen.com/english/advisories/2006/0955https://exchange.xforce.ibmcloud.com/vulnerabilities/25196http://issues.apache.org/jira/browse/LOG4NET-67http://secunia.com/advisories/19241http://secunia.com/advisories/22932http://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.osvdb.org/23905http://www.securityfocus.com/bid/17095http://www.vupen.com/english/advisories/2006/0955https://exchange.xforce.ibmcloud.com/vulnerabilities/25196
2006-03-09
Published