CVE-2009-0001
published 2009-01-21CVE-2009-0001: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
6.80%
93.3th percentile
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a crafted RTSP URL.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.5.5 | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-3170 [MEDIUM] CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Richard Moore and Simon Ward reported flaws in the way browsers such
as Firefox handled wildcard characters in the Common Name field of
a certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Firefox, the attacker could
use the certificate during the man-in-the-middle attack and potentially
confuse Firefox into accepting it by mistake. Different vulnerability than
CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335731
Discussion:
This will be fixed in NSS 3.12.8
---
Mozilla has assigned CVE-2010-3170 identifier to this issue.
Mozilla upstream bug:
[3]
Bugzilla
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-5076 [MEDIUM] CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
Richard Moore and Simon Ward reported flaw in the way Qt software toolkit
handled wildcard characters in the Common Name field of a x509v3 digital
certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Konqueror / Arora web browsers,
the attacker could use the certificate during the man-in-the-middle attack
and potentially confuse Konqueror / Arora into accepting it by mistake.
Different vulnerability than CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335730
Discussion:
Upstream commit addressing this issue:
http://qt.gitorious.org/qt/qt/commit/846f1b
http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.htmlhttp://secunia.com/advisories/33632http://support.apple.com/kb/HT3403http://www.securityfocus.com/bid/33385http://www.us-cert.gov/cas/techalerts/TA09-022A.htmlhttp://www.vupen.com/english/advisories/2009/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/48154https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6135http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.htmlhttp://secunia.com/advisories/33632http://support.apple.com/kb/HT3403http://www.securityfocus.com/bid/33385http://www.us-cert.gov/cas/techalerts/TA09-022A.htmlhttp://www.vupen.com/english/advisories/2009/0212https://exchange.xforce.ibmcloud.com/vulnerabilities/48154https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6135
2009-01-21
Published