CVE-2010-0189
published 2010-02-23CVE-2010-0189: A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly…
PriorityP346critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.18%
91.5th percentile
A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | download_manager | <= 1.6.2.60 | — |
| nos_microsystems | getplus_download_manager | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt
suricata·2010-09-23
CVE-2006-0189 GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt
GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 5060 (msg:"GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt"; content:"|3B|branch|3D|"; content:"a|3D|"; pcre:"/^a\x3D[^\n]{1000,}/smi"; reference:bugtraq,16213; reference:cve,2006-0189; classtype:misc-attack; sid:2100223; rev:2; metadata:created_at 2010_09_23, cve CVE_2006_0189, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
No public exploits indexed.
No writeups or analysis indexed.
http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspxhttp://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.htmlhttp://blogs.zdnet.com/security/?p=5505http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856http://secunia.com/advisories/38729http://securitytracker.com/id?1023651http://www.adobe.com/support/security/bulletins/apsb10-08.htmlhttp://www.akitasecurity.nl/advisory.php?id=AK20090401http://www.osvdb.org/62547http://www.securityfocus.com/bid/38313http://www.vupen.com/english/advisories/2010/0459https://exchange.xforce.ibmcloud.com/vulnerabilities/56370https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7182http://aviv.raffon.net/2010/02/18/SkeletonsInAdobesSecurityCloset.aspxhttp://blogs.adobe.com/psirt/2010/02/adobe_download_manager_issue.htmlhttp://blogs.zdnet.com/security/?p=5505http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856http://secunia.com/advisories/38729http://securitytracker.com/id?1023651http://www.adobe.com/support/security/bulletins/apsb10-08.htmlhttp://www.akitasecurity.nl/advisory.php?id=AK20090401http://www.osvdb.org/62547http://www.securityfocus.com/bid/38313http://www.vupen.com/english/advisories/2010/0459https://exchange.xforce.ibmcloud.com/vulnerabilities/56370https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7182
2010-02-23
Published