CVE-2010-0479
published 2010-04-14CVE-2010-0479: Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted…
PriorityP356critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
23.41%
97.6th percentile
Buffer overflow in Microsoft Office Publisher 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | publisher | — | — |
| microsoft | publisher | — | — |
| microsoft | publisher | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1129 CVE-2010-1130 php: safe_mode / open_basedir security fixes in 5.2.13/5.3.2
bugzilla·2010-03-28·CVSS 7.5
CVE-2010-1129 [HIGH] CVE-2010-1129 CVE-2010-1130 php: safe_mode / open_basedir security fixes in 5.2.13/5.3.2
CVE-2010-1129 CVE-2010-1130 php: safe_mode / open_basedir security fixes in 5.2.13/5.3.2
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1129 to
the following vulnerability:
Name: CVE-2010-1129
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1129
Assigned: 20100326
Reference: CONFIRM: http://www.php.net/ChangeLog-5.php
Reference: CONFIRM: http://www.php.net/releases/5_2_13.php
Reference: BID:38431
Reference: URL: http://www.securityfocus.com/bid/38431
Reference: SECTRACK:1023661
Reference: URL: http://securitytracker.com/id?1023661
Reference: SECUNIA:38708
Reference: URL: http://secunia.com/advisories/38708
Reference: VUPEN:ADV-2010-0479
Reference: URL: http://www.vupen.com/english/advisories/2010/0479
The safe_mode implementation in PHP before 5.2.13 do
Bugzilla
CVE-2010-1128 php: LCG entropy weakness
bugzilla·2010-03-28·CVSS 6.4
CVE-2010-1128 [MEDIUM] CVE-2010-1128 php: LCG entropy weakness
CVE-2010-1128 php: LCG entropy weakness
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1128 to
the following vulnerability:
The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not
provide the expected entropy, which makes it easier for
context-dependent attackers to guess values that were intended to be
unpredictable, as demonstrated by session cookies generated by using
the uniqid function.
References:
http://www.php.net/releases/5_2_13.php
http://www.php.net/ChangeLog-5.php#5.2.13
http://www.securityfocus.com/bid/38430
http://secunia.com/advisories/38708
http://www.vupen.com/english/advisories/2010/0479
Discussion:
Upstream commit:
http://svn.php.net/viewvc?view=revision&revision=293253
More details in:
http://samy.pl/phpwn/
---
This issue has
http://www.us-cert.gov/cas/techalerts/TA10-103A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-023https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7141http://www.us-cert.gov/cas/techalerts/TA10-103A.htmlhttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-023https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7141
2010-04-14
Published