CVE-2008-2595
published 2008-07-15CVE-2008-2595: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote…
PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
11.34%
95.5th percentile
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_10g | — | — |
| oracle | database_10g | — | — |
| oracle | database_9i | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Talos
Rule release for today
blogs_talos·2008-12-16·CVSS 5.0
CVE-2008-2595 [MEDIUM] Rule release for today
Today's VRT Certified Rule release has coverage for a vulnerability in Oracle Internet Directory and CUPS. There are also a few new rules added in chat.rules and others.
Oracle Internet Directory Denial of Service (CVE-2008-2595):
Oracle Internet Directory contains a programming error that may allow a remote attacker to cause a Denial of Service (DoS) against the application. This issue does not require authentication.
CUPS Integer Overflow (CVE-2008-5286):
A vulnerability in the _cupsImageReadPNG function in CUPS may allow a remote attacker to execute code on a vulnerable system.
Here's the link to today's release: http://www.snort.org/vrt/advisories/vrt-rules-2008-12-16.html
Talos
Rule release for today
blogs_talos·2008-12-16·CVSS 5.0
CVE-2008-2595 [MEDIUM] Rule release for today
## Rule release for today
Today's VRT Certified Rule release has coverage for a vulnerability in Oracle Internet Directory and CUPS. There are also a few new rules added in chat.rules and others.
Oracle Internet Directory Denial of Service (CVE-2008-2595): Oracle Internet Directory contains a programming error that may allow a remote attacker to cause a Denial of Service (DoS) against the application. This issue does not require authentication.
CUPS Integer Overflow (CVE-2008-5286): A vulnerability in the _cupsImageReadPNG function in CUPS may allow a remote attacker to execute code on a vulnerable system.
Here's the link to today's release: http://www.snort.org/vrt/advisories/vrt-rules-2008-12-16.html
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=725http://secunia.com/advisories/31087http://secunia.com/advisories/31113http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.htmlhttp://www.securitytracker.com/id?1020494http://www.vupen.com/english/advisories/2008/2109/referenceshttp://www.vupen.com/english/advisories/2008/2115https://www.exploit-db.com/exploits/6101http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c00727143http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=725http://secunia.com/advisories/31087http://secunia.com/advisories/31113http://www.oracle.com/technetwork/topics/security/cpujul2008-090335.htmlhttp://www.securitytracker.com/id?1020494http://www.vupen.com/english/advisories/2008/2109/referenceshttp://www.vupen.com/english/advisories/2008/2115https://www.exploit-db.com/exploits/6101
2008-07-15
Published