CVE-2009-0007
published 2009-01-21CVE-2009-0007: Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute…
PriorityP341critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
7.72%
94.0th percentile
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | quicktime | <= 7.5.5 | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
| apple | quicktime | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gmp-mc2j-jqxr: Heap-based buffer overflow in Apple QuickTime before 7
ghsa_unreviewed·2022-05-02
CVE-2009-0007 [HIGH] CWE-119 GHSA-9gmp-mc2j-jqxr: Heap-based buffer overflow in Apple QuickTime before 7
Heap-based buffer overflow in Apple QuickTime before 7.6 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via a QuickTime movie file containing invalid image width data in JPEG atoms within STSD atoms.
VMware
VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
vendor_vmware·2010-04-09·CVSS 8.5
CVE-2009-1564 [HIGH] VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
VMSA-2010-0007: VMware hosted products, vCenter Server and ESX patches resolve multiple security issues
a. Windows-based VMware Tools Unsafe Library Loading vulnerability A vulnerability in the way VMware libraries are referenced allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to lure the user that is logged on a Windows Guest Operating System to click on the attacker's file on a network share. This file could be in any file format. The attacker will need to have the ability to host their malicious files on a network share. VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS Security ( http://www.across
No detection rules found.
Exploit-DB
VMware Remote Console e.x.p build-158248 - Format String
exploitdb·2010-04-12·CVSS 10.0
CVE-2009-3732 [CRITICAL] VMware Remote Console e.x.p build-158248 - Format String
VMware Remote Console e.x.p build-158248 - Format String
---
[DSECRG-09-053] VMware Remote Console - format string vulnerability
http://www.dsecrg.com/pages/vul/show.php?id=153
VMrc vulnerable to format string attacks. Exploitation of this issue may lead to arbitrary code execution on the system where VMrc is installed.
Digital Security Research Group [DSecRG] Advisory DSECRG-09-053
Application: VMware Remoute Console
Version: e.x.p build-158248
Vendor URL: http://vmware.com
Bugs: Format String Vulnerabilitys
Exploits: YES (PoC)
Reported: 07.08.2009
Vendor response: 13.08.2009
Date of Public Advisory: 09.04.2010
CVE: CVE-2009-3732
VSA: VMSA-2010-0007
Authors: Alexey Sintsov of
Digital Security Research Group [DSecRG] (research [at] dsecrg [dot] com)
Description
VMware Remote Conso
Exploit-DB
VMware Player / VMware Workstation 6.5.3 - 'VMware-authd' Remote Denial of Service
exploitdb·2009-10-07
CVE-2009-3707 VMware Player / VMware Workstation 6.5.3 - 'VMware-authd' Remote Denial of Service
VMware Player / VMware Workstation 6.5.3 - 'VMware-authd' Remote Denial of Service
---
source: https://www.securityfocus.com/bid/36630/info
VMware Player and Workstation are prone to a remote denial-of-service vulnerability because the applications fail to perform adequate validation checks on user-supplied input.
An attacker can exploit this issue to crash the 'vmware-authd' process, denying service to legitimate users.
NOTE: This issue was also covered in BID 39345 (VMware Hosted Products VMSA-2010-0007 Multiple Remote and Local Vulnerabilities); this BID is being retained to properly document the issue.
# ----------------------------------------------------------------------------
# VMware Authorization Service exploit.py 127.0.0.1 912
import socket
import time
import sys
host =
Bugzilla
CVE-2009-0500 moodle: XSS vuln due to missing input validation in logs
bugzilla·2009-02-10·CVSS 4.3
CVE-2009-0500 [MEDIUM] CVE-2009-0500 moodle: XSS vuln due to missing input validation in logs
CVE-2009-0500 moodle: XSS vuln due to missing input validation in logs
me: CVE-2009-0500
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0500
Assigned: 20090209
Reference: MLIST:[oss-security] 20090204 CVS request - Moodle
Reference: URL: http://www.openwall.com/lists/oss-security/2009/02/04/1
Reference: CONFIRM: http://moodle.org/security/
Cross-site scripting (XSS) vulnerability in course/lib.php in Moodle
1.6 before 1.6.9, 1.7 before 1.7.7, 1.8 before 1.8.8, and 1.9 before
1.9.4 allows remote attackers to inject arbitrary web script or HTML
via crafted log table information that is not properly handled when it
is displayed in a log report.
Additional information from upstream (http://moodle.org/security/)
MSA-09-0007: Missing input validation in logs allows potential XS
Bugzilla
CVE-2008-2368 Certificate System: plain text passwords stored in debug log
bugzilla·2008-06-18·CVSS 2.1
CVE-2008-2368 [LOW] CVE-2008-2368 Certificate System: plain text passwords stored in debug log
CVE-2008-2368 Certificate System: plain text passwords stored in debug log
It was discovered that Red Hat Certificate System may store plain text passwords
in multiple debug log files (such as UserDirEnrollment password or RA wizard
installer log).
This problem allows any local user to extract plain text passwords from the Red
Hat Certificate System debug log files.
Discussion:
Lifting embargo.
---
This issue was addressed in:
Red Hat Certificate System:
http://rhn.redhat.com/errata/RHSA-2009-0006.html
http://rhn.redhat.com/errata/RHSA-2009-0007.html
Bugzilla
CVE-2008-2367 Certificate System: insecure config file permissions
bugzilla·2008-06-18·CVSS 2.1
CVE-2008-2367 [LOW] CVE-2008-2367 Certificate System: insecure config file permissions
CVE-2008-2367 Certificate System: insecure config file permissions
It was discovered that Red Hat Certificate System use insecure default file
permissions on configuration files (such as password.conf) that may contain
authentication credentials or other sensitive information that should only be
accessible to administrative and service users.
This problem allows any local user to read Red Hat Certificate System
configuration files.
Discussion:
Lifting embargo.
---
This issue was addressed in:
Red Hat Certificate System:
http://rhn.redhat.com/errata/RHSA-2009-0006.html
http://rhn.redhat.com/errata/RHSA-2009-0007.html
http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.htmlhttp://osvdb.org/51530http://secunia.com/advisories/33632http://support.apple.com/kb/HT3403http://www.securityfocus.com/bid/33390http://www.us-cert.gov/cas/techalerts/TA09-022A.htmlhttp://www.vupen.com/english/advisories/2009/0212http://www.zerodayinitiative.com/advisories/ZDI-09-008/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6132http://lists.apple.com/archives/security-announce/2009/Jan/msg00000.htmlhttp://osvdb.org/51530http://secunia.com/advisories/33632http://support.apple.com/kb/HT3403http://www.securityfocus.com/bid/33390http://www.us-cert.gov/cas/techalerts/TA09-022A.htmlhttp://www.vupen.com/english/advisories/2009/0212http://www.zerodayinitiative.com/advisories/ZDI-09-008/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6132
2009-01-21
Published