CVE-2010-0042
published 2010-03-15CVE-2010-0042: ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.52%
83.2th percentile
ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 4.0.4 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
GPL WEB_SERVER Tomcat null byte directory listing attempt
suricata·2010-09-23
CVE-2003-0042 GPL WEB_SERVER Tomcat null byte directory listing attempt
GPL WEB_SERVER Tomcat null byte directory listing attempt
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL WEB_SERVER Tomcat null byte directory listing attempt"; flow:established,to_server; http.uri; content:"|00|.jsp"; reference:bugtraq,2518; reference:bugtraq,6721; reference:cve,2003-0042; classtype:web-application-attack; sid:2102061; rev:9; metadata:created_at 2010_09_23, cve CVE_2003_0042, signature_severity Unknown, updated_at 2024_03_08;)
Suricata
GPL IMAP authenticate overflow attempt
suricata·2010-09-23
CVE-1999-0005 GPL IMAP authenticate overflow attempt
GPL IMAP authenticate overflow attempt
Rule: alert tcp $EXTERNAL_NET any -> $HOME_NET 143 (msg:"GPL IMAP authenticate overflow attempt"; flow:established,to_server; content:"AUTHENTICATE"; nocase; isdataat:100,relative; pcre:"/\sAUTHENTICATE\s[^\n]{100}/smi"; reference:bugtraq,12995; reference:bugtraq,130; reference:cve,1999-0005; reference:cve,1999-0042; reference:nessus,10292; classtype:misc-attack; sid:2101844; rev:12; metadata:created_at 2010_09_23, cve CVE_1999_0005, confidence Medium, signature_severity Major, updated_at 2019_07_26;)
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Mar/msg00000.htmlhttp://secunia.com/advisories/39135http://secunia.com/advisories/42314http://support.apple.com/kb/HT4070http://support.apple.com/kb/HT4077http://support.apple.com/kb/HT4105http://support.apple.com/kb/HT4225http://support.apple.com/kb/HT4456http://www.securityfocus.com/bid/38671http://www.securityfocus.com/bid/38677http://www.securitytracker.com/id?1023706https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2010//Mar/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Jun/msg00003.htmlhttp://lists.apple.com/archives/security-announce/2010/Mar/msg00000.htmlhttp://secunia.com/advisories/39135http://secunia.com/advisories/42314http://support.apple.com/kb/HT4070http://support.apple.com/kb/HT4077http://support.apple.com/kb/HT4105http://support.apple.com/kb/HT4225http://support.apple.com/kb/HT4456http://www.securityfocus.com/bid/38671http://www.securityfocus.com/bid/38677http://www.securitytracker.com/id?1023706https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7561
2010-03-15
Published