CVE-2009-0015
published 2009-02-13CVE-2009-0015: Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem…
PriorityP412medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.32%
24.5th percentile
Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-5345 JRE allows unauthorized file access and connections to localhost
bugzilla·2008-12-05·CVSS 7.5
CVE-2008-5345 [HIGH] CVE-2008-5345 JRE allows unauthorized file access and connections to localhost
CVE-2008-5345 JRE allows unauthorized file access and connections to localhost
Name: CVE-2008-5345
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5345
Reference: SUNALERT:246387
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-246387-1
Unspecified vulnerability in Java Runtime Environment (JRE) with Sun
JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and
earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23
and earlier allows code that is loaded from a local filesystem to read
arbitrary files and make unauthorized connections to localhost via
unknown vectors.
Discussion:
Another mention of this issue:
http://secunia.com/advisories/32991/
---
Red Hat advisory RHSA-2009-0015 says that this is one of the
Bugzilla
CVE-2008-5339 JavaWebStart allows unauthorized network connections
bugzilla·2008-12-05·CVSS 5.0
CVE-2008-5339 [MEDIUM] CVE-2008-5339 JavaWebStart allows unauthorized network connections
CVE-2008-5339 JavaWebStart allows unauthorized network connections
Name: CVE-2008-5339
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5339
Reference: SUNALERT:244988
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in
with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update
16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted
JWS applications to perform network connections to unauthorized hosts
via unknown vectors.
Discussion:
Another mention of this issue:
http://secunia.com/advisories/32991/ (Point 5) )
---
This bug is listed in Red Hat advisory RHSA-2009-0015 as being fixed, yet is in state NEW.
https://rhn.redhat.com/errata/
Bugzilla
CVE-2008-5344 Java WebStart unprivileged local file and network access
bugzilla·2008-12-05·CVSS 7.5
CVE-2008-5344 [HIGH] CVE-2008-5344 Java WebStart unprivileged local file and network access
CVE-2008-5344 Java WebStart unprivileged local file and network access
Name: CVE-2008-5344
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5344
Reference: SUNALERT:244988
Reference: URL:http://sunsolve.sun.com/search/document.do?assetkey=1-26-244988-1
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in
with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update
16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted
applets to read arbitrary files and make unauthorized network
connections via unknown vectors related to applet classloading.
Discussion:
Another mention of this issue:
http://secunia.com/advisories/32991/
---
Red Hat advisory RHSA-2009-0015 states that this bug is fixed:
https://rhn.redhat.com/errata/R
http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://secunia.com/advisories/33937http://support.apple.com/kb/HT3438http://www.securityfocus.com/bid/33759http://www.securityfocus.com/bid/33821http://www.vupen.com/english/advisories/2009/0422http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://secunia.com/advisories/33937http://support.apple.com/kb/HT3438http://www.securityfocus.com/bid/33759http://www.securityfocus.com/bid/33821http://www.vupen.com/english/advisories/2009/0422
2009-02-13
Published