CVE-2010-0500
published 2010-03-30CVE-2010-0500: Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.74%
75.3th percentile
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.6.2 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x_server | <= 10.6.2 | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple Mac OS X up to 10.6.2 input validation (HT4077 / Nessus ID 45372)
vuldb·2026-05-04·CVSS 7.8
CVE-2010-0500 [HIGH] Apple Mac OS X up to 10.6.2 input validation (HT4077 / Nessus ID 45372)
A vulnerability, which was classified as problematic, has been found in Apple Mac OS X up to 10.6.2. This affects an unknown function. The manipulation leads to improper input validation.
This vulnerability is referenced as CVE-2010-0500. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
GHSA-vfq8-637p-vg8j: Event Monitor in Apple Mac OS X before 10
ghsa_unreviewed·2022-05-02
CVE-2010-0500 [HIGH] CWE-20 GHSA-vfq8-637p-vg8j: Event Monitor in Apple Mac OS X before 10
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue."
No detection rules found.
Bugzilla
CVE-2010-1202 Mozilla Crashes with evidence of memory corruption
bugzilla·2010-05-10·CVSS 9.3
CVE-2010-1202 [CRITICAL] CVE-2010-1202 Mozilla Crashes with evidence of memory corruption
CVE-2010-1202 Mozilla Crashes with evidence of memory corruption
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Bob Clary, Igor Bukanov, Gary Kwong and Andreas Gal reported crashes in the
JavaScript engine that affected Firefox 3.6 and Firefox 3.5.
Discussion:
This issue is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-26.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2010:0500 https://rhn.redhat.com/errata/RHSA-2010-0500.html
---
Th
Bugzilla
CVE-2010-1203 Mozilla Crashes with evidence of memory corruption
bugzilla·2010-05-10·CVSS 9.3
CVE-2010-1203 [CRITICAL] CVE-2010-1203 Mozilla Crashes with evidence of memory corruption
CVE-2010-1203 Mozilla Crashes with evidence of memory corruption
Mozilla developers identified and fixed several stability bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these crashes showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Gary Kwong and David Anderson reported crashes in the JavaScript engine
that affected Firefox 3.6 only.
Discussion:
This issue is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-26.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Via RHSA-2010:0500 https://rhn.redhat.com/errata/RHSA-2010-0500.html
---
This issue has been addressed in fo
Bugzilla
CVE-2009-0499,0500,0501,0502 moodle: multiple issues [F10]
bugzilla·2009-02-10·CVSS 6.4
CVE-2009-0499 [MEDIUM] CVE-2009-0499,0500,0501,0502 moodle: multiple issues [F10]
CVE-2009-0499,0500,0501,0502 moodle: multiple issues [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=484917,
---
Correct bodhi update submission URL is:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&bugs=484917,CVE-2009-0499,CVE-2009-0500,CVE-2009-0501,CVE-2009-0502
---
Built and bodhi'd.
---
Stable, not closed by bodhi
2010-03-30
Published