CVE-2009-2872
published 2009-09-28CVE-2009-2872: Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service…
medium6.8CVSS 3.1
AVNACLAuSCNINAC
Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776.
Affected
289 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-mh9m-75gc-gjxq: Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2009-2872 [MEDIUM] GHSA-mh9m-75gc-gjxq: Cisco IOS 12
Cisco IOS 12.0 through 12.4, when IP-based tunnels and the Cisco Express Forwarding feature are enabled, allows remote attackers to cause a denial of service (device reload) via a malformed packet that is not properly handled during switching from one tunnel to a second tunnel, aka Bug IDs CSCsh97579 and CSCsq31776.
Cisco
Cisco IOS Software Tunnels Vulnerability
vendor_cisco·2009-09-23·CVSS 7.1
CVE-2009-2872 [HIGH] CWE-399 Cisco IOS Software Tunnels Vulnerability
Cisco IOS Software Tunnels Vulnerability
Cisco devices running affected versions of Cisco IOS Software are
vulnerable to a denial of service (DoS) attack if configured for IP tunnels and
Cisco Express Forwarding.
Cisco has released software updates that address this vulnerability.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-tunnels.
Note: The September 23, 2009, Cisco IOS Security Advisory bundled
publication includes eleven Security Advisories. Ten of the advisories address
vulnerabilities in Cisco IOS Software, and one advisory addresses a
vulnerability in Cisco Unified Communications Manager. Each advisory lists the
releases that correct the vulnerability or vulnerabilities detailed in the
advisory.
Indi
Cisco
Cisco IOS Software Tunnels Vulnerability
vendor_cisco
CVE-2009-2872 Cisco IOS Software Tunnels Vulnerability
CVE-2009-2872: Cisco IOS Software Tunnels Vulnerability
Cisco devices running affected versions of Cisco IOS Software are vulnerable to a denial of service (DoS) attack if configured for IP tunnels and Cisco Express Forwarding. Cisco has released software updates that address this vulnerability. This advisory is posted at https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20090923-tunnels . Note: The September 23, 2009, Cisco IOS Security Advisory bundled publication includes eleven Security Advisories. Ten of the advisories address vulnerabilities in Cisco IOS Software, and one advisory addresses a vulnerability in Cisco Unified Communications Manager. Each advisory lists the releases that correct the vulnerability or vulnerabilities detailed in the adv
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3554 JBoss EAP Twiddle logs the JMX password
bugzilla·2009-11-20·CVSS 2.1
CVE-2009-3554 [LOW] CVE-2009-3554 JBoss EAP Twiddle logs the JMX password
CVE-2009-3554 JBoss EAP Twiddle logs the JMX password
From https://jira.jboss.org/jira/browse/JBPAPP-2872
Twiddle logs all command line arguments, including the JMX password to twiddle.log. This log is publicly readable and is created in the current directory.
Discussion:
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 4
Via RHSA-2009:1636 https://rhn.redhat.com/errata/RHSA-2009-1636.html
---
This issue has been addressed in following products:
JBEAP 4.2.0 for RHEL 4
Via RHSA-2009:1637 https://rhn.redhat.com/errata/RHSA-2009-1637.html
---
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 5
Via RHSA-2009:1649 https://rhn.redhat.com/errata/RHSA-2009-1649.html
---
This issue has been addressed in following products:
JBEAP 4.2.
Bugzilla
CVE-2008-4681 wireshark: DoS (app crash or abort) in Bluetooth RFCOMM dissector via unknown packets
bugzilla·2008-10-23·CVSS 4.3
CVE-2008-4681 [MEDIUM] CVE-2008-4681 wireshark: DoS (app crash or abort) in Bluetooth RFCOMM dissector via unknown packets
CVE-2008-4681 wireshark: DoS (app crash or abort) in Bluetooth RFCOMM dissector via unknown packets
Common Vulnerabilities and Exposures assigned an identifier CVE-2008-4681 to
the following vulnerability:
Unspecified vulnerability in the Bluetooth RFCOMM dissector in
Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a
denial of service (application crash or abort) via unknown packets.
Affected Wireshark versions: 0.99.7 through 1.0.3
References:
http://www.wireshark.org/security/wnpa-sec-2008-06.html
http://www.securityfocus.com/bid/31838
http://www.frsirt.com/english/advisories/2008/2872
http://securitytracker.com/id?1021069
http://secunia.com/advisories/32355
Discussion:
This issue was addressed in:
Red Hat Enterprise Linux:
http://rhn.redhat.com/errata/RHSA-2009-0
http://osvdb.org/58333http://tools.cisco.com/security/center/viewAlert.x?alertId=18893http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080af8113.htmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080af8115.shtmlhttp://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep09.htmlhttp://www.securitytracker.com/id?1022930http://www.vupen.com/english/advisories/2009/2759http://osvdb.org/58333http://tools.cisco.com/security/center/viewAlert.x?alertId=18893http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080af8113.htmlhttp://www.cisco.com/en/US/products/products_security_advisory09186a0080af8115.shtmlhttp://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep09.htmlhttp://www.securitytracker.com/id?1022930http://www.vupen.com/english/advisories/2009/2759
2009-09-28
Published