CVE-2009-1673
published 2009-05-18CVE-2009-1673: The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.
PriorityP411medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.39%
30.8th percentile
The kernel in Sun Solaris 9 allows local users to cause a denial of service (panic) by calling fstat with a first argument of AT_FDCWD.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | solaris | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3984 Mozilla SSL spoofing with document.location and empty SSL response page
bugzilla·2009-12-11·CVSS 6.8
CVE-2009-3984 [MEDIUM] CVE-2009-3984 Mozilla SSL spoofing with document.location and empty SSL response page
CVE-2009-3984 Mozilla SSL spoofing with document.location and empty SSL response page
Security researcher Jonathan Morgan reported that when a page loaded over an insecure protocol, such as http: or file:, sets its document.location to a https: URL which responds with a 204 status and empty response body, the insecure page will receive SSL indicators near the location bar, but will not have its page content modified in any way. This could lead to a user believing they were on a secure page when in fact they were not.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2009:1673 https://rhn.redhat.com/errata/RHSA-2009-1673.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux
Bugzilla
CVE-2009-3983 Mozilla NTLM reflection vulnerability
bugzilla·2009-12-11·CVSS 6.8
CVE-2009-3983 [MEDIUM] CVE-2009-3983 Mozilla NTLM reflection vulnerability
CVE-2009-3983 Mozilla NTLM reflection vulnerability
Security researcher Takehiro Takahashi of the IBM X-Force reported that Mozilla's NTLM implementation was vulnerable to reflection attacks in which NTLM credentials from one application could be forwarded to another arbitary application via the browser. If an attacker could get a user to visit a web page he controlled he could force NTLM authenticated requests to be forwarded to another application on behalf of the user.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2009:1673 https://rhn.redhat.com/errata/RHSA-2009-1673.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2009:1
http://osvdb.org/54464http://secunia.com/advisories/35103http://secunia.com/advisories/35119http://sunsolve.sun.com/search/document.do?assetkey=1-21-122300-40-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-257988-1http://support.avaya.com/elmodocs2/security/ASA-2009-188.htmhttp://www.securityfocus.com/bid/34979http://www.securitytracker.com/id?1022232http://www.vupen.com/english/advisories/2009/1315http://www.vupen.com/english/advisories/2009/1388https://exchange.xforce.ibmcloud.com/vulnerabilities/50557https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6256http://osvdb.org/54464http://secunia.com/advisories/35103http://secunia.com/advisories/35119http://sunsolve.sun.com/search/document.do?assetkey=1-21-122300-40-1http://sunsolve.sun.com/search/document.do?assetkey=1-66-257988-1http://support.avaya.com/elmodocs2/security/ASA-2009-188.htmhttp://www.securityfocus.com/bid/34979http://www.securitytracker.com/id?1022232http://www.vupen.com/english/advisories/2009/1315http://www.vupen.com/english/advisories/2009/1388https://exchange.xforce.ibmcloud.com/vulnerabilities/50557https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6256
2009-05-18
Published