CVE-2010-0019
published 2010-08-11CVE-2010-0019: Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to…
PriorityP350critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
14.37%
96.2th percentile
Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | silverlight | <= 3.0.40818.0 | — |
| microsoft | silverlight | <= 3.0.50106.0 | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
| microsoft | silverlight | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7xgr-cxmr-5q3f: Microsoft Silverlight 3 before 3
ghsa_unreviewed·2022-05-02
CVE-2010-0019 [HIGH] CWE-94 GHSA-7xgr-cxmr-5q3f: Microsoft Silverlight 3 before 3
Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."
Red Hat
Server: Multiple memory leaks in the normalization functionality
vendor_redhat·2010-12-16·CVSS 5.0
CVE-2010-4746 [MEDIUM] CWE-401 Server: Multiple memory leaks in the normalization functionality
Server: Multiple memory leaks in the normalization functionality
Multiple memory leaks in the normalization functionality in 389 Directory Server before 1.2.7.5 allow remote attackers to cause a denial of service (memory consumption) via "badly behaved applications," related to (1) Slapi_Attr mishandling in the DN normalization code and (2) pointer mishandling in the syntax normalization code, a different issue than CVE-2011-0019.
Statement: Not vulnerable. This issue did not affect Red Hat Directory Server 8 packages.
Package: Directory Server (Red Hat Directory Server 8) - Affected
Red Hat
kernel: ipv6_hop_jumbo remote system crash
vendor_redhat·2007-09-07·CVSS 7.8
CVE-2007-4567 [HIGH] CWE-228 kernel: ipv6_hop_jumbo remote system crash
kernel: ipv6_hop_jumbo remote system crash
The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.22 does not properly validate the hop-by-hop IPv6 extended header, which allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted IPv6 packet.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 3, 4 and Red Hat Enterprise MRG. Shipped kernels do not include upstream commit a11d206d that introduced the problem.
This upstream commit was backported in Red Hat Enterprise Linux 5 via RHBA-2008:0314. It was reported and addressed in Red Hat Enterprise Linux 5 via RHSA-2010:0019.
No detection rules found.
No public exploits indexed.
Zscaler
Zscaler Provides Advanced Protection for Massive MS Patch
blogs_zscaler
Zscaler Provides Advanced Protection for Massive MS Patch
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Zscaler
Zscaler found Multiple Security Vulnerabilities | 08-10-2010
blogs_zscaler
Zscaler found Multiple Security Vulnerabilities | 08-10-2010
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality
bugzilla·2011-02-24·CVSS 5.0
CVE-2010-4746 [MEDIUM] CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality
CVE-2010-4746 Directory Server: Multiple memory leaks in the normalization functionality
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-4746 to
the following vulnerability:
Multiple memory leaks in the normalization functionality in 389
Directory Server before 1.2.7.5 allow remote attackers to cause a
denial of service (memory consumption) via "badly behaved
applications," related to (1) Slapi_Attr mishandling in the DN
normalization code and (2) pointer mishandling in the syntax
normalization code, a different issue than CVE-2011-0019.
References:
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4746
[2] http://directory.fedoraproject.org/wiki/Release_Notes
[3] https://bugzilla.redhat.com/show_bug.cgi?id=663597
Discussion:
Nathan, Rich, did this affect
Bugzilla
CVE-2009-4538 kernel: e1000e frame fragment issue
bugzilla·2009-12-29·CVSS 10.0
CVE-2009-4538 [CRITICAL] CVE-2009-4538 kernel: e1000e frame fragment issue
CVE-2009-4538 kernel: e1000e frame fragment issue
Description of problem:
Similar to the second issue that Fab mentioned in his presentation at 26c3, this affects the e1000e driver. See https://bugzilla.redhat.com/show_bug.cgi?id=550907#c0 issue #2 for the description, and this https://bugzilla.redhat.com/show_bug.cgi?id=550907#c4. This bug is filed to make sure we fix this too.
http://www.securityfocus.com/bid/37523
Discussion:
A quick heads up to all the release owners on this bug, the patch I posted upstream for bz 550915 (specifically the e1000 bits) will apply pretty cleanly to e1000e here.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0019 https://rhn.redhat.com/errata/RHSA-2010-0019.html
---
This issue has been addressed
2010-08-11
Published