CVE-2009-0436
published 2009-02-10CVE-2009-0436: The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS)…
PriorityP421high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.37%
29.8th percentile
The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Server (WAS), set incorrect permissions for AF_UNIX sockets, which has unknown impact and local attack vectors.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings
bugzilla·2009-04-17·CVSS 4.3
CVE-2009-1308 [MEDIUM] CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings
CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings
Web developer Cefn Hoile reported that sites which allow users to embed
third-party stylesheets are vulnerable to script injection attacks using
XBL bindings. While this behavior was documented previously, it was
determined that this particular risk was not well-understood by some
websites. To mitigate this risk Mozilla added a restriction that requires
XBL bindings to come from the same origin as the bound document.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2009:0436 https://rhn.redhat.com/errata/RHSA-2009-0436.html
---
xulrunner-1.9.0.9-1.fc9, firefox-3.0.9-1.fc9, epiphany-extensions-2.22.1-10.fc9, epiphany-2.22.2-10.
Bugzilla
CVE-2009-1302 Firefox 3 Layout engine crashes
bugzilla·2009-04-17·CVSS 5.0
CVE-2009-1302 [MEDIUM] CVE-2009-1302 Firefox 3 Layout engine crashes
CVE-2009-1302 Firefox 3 Layout engine crashes
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances and we presume that with enough effort at least some of these
could be exploited to run arbitrary code.
Olli Pettay, Martijn Wargers, Mats Palmgren, Romaxa, Jesse Ruderman, and
Gary Kwong reported crashes in the layout engine which affected Firefox 3
only.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2009:0436 https://rhn.redhat.com/errata/RHSA-2009-0436.html
---
xulrunner-1.9.0.9-1.fc9, firefox-3.0.9-1.fc9, epiphany-extensions-2.22.1-10
Bugzilla
CVE-2009-1304 Firefox 3 JavaScript engine crashes
bugzilla·2009-04-17·CVSS 5.0
CVE-2009-1304 [MEDIUM] CVE-2009-1304 Firefox 3 JavaScript engine crashes
CVE-2009-1304 Firefox 3 JavaScript engine crashes
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances and we presume that with enough effort at least some of these
could be exploited to run arbitrary code.
Igor Bukanov, and Bob Clary reported crashes in the JavaScript engine which
affected Firefox 3 only.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2009:0436 https://rhn.redhat.com/errata/RHSA-2009-0436.html
---
xulrunner-1.9.0.9-1.fc9, firefox-3.0.9-1.fc9, epiphany-extensions-2.22.1-10.fc9, epiphany-2.22.2-10.fc9, blam-1.8.5-8.fc9.1
Bugzilla
CVE-2009-1310 Firefox Malicious search plugins can inject code into arbitrary sites
bugzilla·2009-04-17·CVSS 4.3
CVE-2009-1310 [MEDIUM] CVE-2009-1310 Firefox Malicious search plugins can inject code into arbitrary sites
CVE-2009-1310 Firefox Malicious search plugins can inject code into arbitrary sites
Security researcher Prateek Saxena reported that a malicious MozSearch
plugin could be created using a javascript: URI in the SearchForm value.
This URI is used as the default landing page when an empty search is
performed. If an attacker could get a user to install the malicious plugin
and perform an empty search, the SearchForm javascript: URI would be
executed within the context of the target site.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2009:0436 https://rhn.redhat.com/errata/RHSA-2009-0436.html
---
xulrunner-1.9.0.9-1.fc9, firefox-3.0.9-1.fc9, epiphany-extensions-2.22.1-10.fc9, epiphany-2.22.2-10.fc9, blam-1.
http://www-01.ibm.com/support/docview.wss?uid=swg27006876http://www-01.ibm.com/support/docview.wss?uid=swg27007033http://www-01.ibm.com/support/docview.wss?uid=swg27007951http://www-01.ibm.com/support/docview.wss?uid=swg27008517http://www-1.ibm.com/support/docview.wss?uid=swg1PK66154http://www.securityfocus.com/bid/33700https://exchange.xforce.ibmcloud.com/vulnerabilities/48526http://www-01.ibm.com/support/docview.wss?uid=swg27006876http://www-01.ibm.com/support/docview.wss?uid=swg27007033http://www-01.ibm.com/support/docview.wss?uid=swg27007951http://www-01.ibm.com/support/docview.wss?uid=swg27008517http://www-1.ibm.com/support/docview.wss?uid=swg1PK66154http://www.securityfocus.com/bid/33700https://exchange.xforce.ibmcloud.com/vulnerabilities/48526
2009-02-10
Published