CVE-2009-0370
published 2009-01-30CVE-2009-0370: Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64…
PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.37%
29.3th percentile
Multiple unspecified vulnerabilities in IBM AIX 5.2.0 through 6.1.2 allow local users to append data to arbitrary files, related to (1) rmsock and (2) rmsock64 not creating "secure log files."
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
| ibm | aix | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0601 wireshark: denial of service (application crash) via format string specifiers in the HOME environment variable.
bugzilla·2009-02-17·CVSS 2.1
CVE-2009-0601 [LOW] CVE-2009-0601 wireshark: denial of service (application crash) via format string specifiers in the HOME environment variable.
CVE-2009-0601 wireshark: denial of service (application crash) via format string specifiers in the HOME environment variable.
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0601 to
the following vulnerability:
Format string vulnerability in Wireshark 0.99.8 through 1.0.5 on
non-Windows platforms allows local users to cause a denial of service
(application crash) via format string specifiers in the HOME
environment variable.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0601
http://www.wireshark.org/security/wnpa-sec-2009-01.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=3150
http://www.securityfocus.com/bid/33690
http://www.frsirt.com/english/advisories/2009/0370
Discussion:
This issue does NOT affect the version of the wireshark pa
Bugzilla
CVE-2009-0600 wireshark: denial of service (application crash) via a crafted Tektronix K12 text capture file
bugzilla·2009-02-17·CVSS 4.3
CVE-2009-0600 [MEDIUM] CVE-2009-0600 wireshark: denial of service (application crash) via a crafted Tektronix K12 text capture file
CVE-2009-0600 wireshark: denial of service (application crash) via a crafted Tektronix K12 text capture file
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0600 to
the following vulnerability:
Wireshark 0.99.6 through 1.0.5 allows user-assisted remote attackers
to cause a denial of service (application crash) via a crafted
Tektronix K12 text capture file, as demonstrated by a file with
exactly one frame.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0600
http://www.wireshark.org/security/wnpa-sec-2009-01.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=1937
http://www.securityfocus.com/bid/33690
http://www.frsirt.com/english/advisories/2009/0370
http://secunia.com/advisories/33872
Discussion:
This issue does NOT affect the version of
http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.aschttp://www.ibm.com/support/docview.wss?uid=isg1IZ40386http://www.ibm.com/support/docview.wss?uid=isg1IZ41510http://www.ibm.com/support/docview.wss?uid=isg1IZ41593http://www.ibm.com/support/docview.wss?uid=isg1IZ41599http://www.ibm.com/support/docview.wss?uid=isg1IZ42785http://www.ibm.com/support/docview.wss?uid=isg1IZ42786http://www.ibm.com/support/docview.wss?uid=isg1IZ42787http://www.ibm.com/support/docview.wss?uid=isg1IZ42788http://www.securityfocus.com/bid/33522https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6028http://aix.software.ibm.com/aix/efixes/security/rmsock_advisory.aschttp://www.ibm.com/support/docview.wss?uid=isg1IZ40386http://www.ibm.com/support/docview.wss?uid=isg1IZ41510http://www.ibm.com/support/docview.wss?uid=isg1IZ41593http://www.ibm.com/support/docview.wss?uid=isg1IZ41599http://www.ibm.com/support/docview.wss?uid=isg1IZ42785http://www.ibm.com/support/docview.wss?uid=isg1IZ42786http://www.ibm.com/support/docview.wss?uid=isg1IZ42787http://www.ibm.com/support/docview.wss?uid=isg1IZ42788http://www.securityfocus.com/bid/33522https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6028
2009-01-30
Published