CVE-2010-0504
published 2010-03-30CVE-2010-0504: Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.14%
86.6th percentile
Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x_server | <= 10.6.2 | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
| apple | mac_os_x_server | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apple Mac OS X up to 10.6.2 memory corruption (HT4077 / Nessus ID 45372)
vuldb·2026-05-04·CVSS 7.5
CVE-2010-0504 [HIGH] Apple Mac OS X up to 10.6.2 memory corruption (HT4077 / Nessus ID 45372)
A vulnerability was found in Apple Mac OS X up to 10.6.2. It has been classified as critical. Affected by this issue is some unknown functionality. Performing a manipulation results in memory corruption.
This vulnerability is cataloged as CVE-2010-0504. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
GHSA-g5p3-8rp5-m2r4: Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10
ghsa_unreviewed·2022-05-02
CVE-2010-0504 [HIGH] CWE-119 GHSA-g5p3-8rp5-m2r4: Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10
Multiple stack-based buffer overflows in iChat Server in Apple Mac OS X Server before 10.6.3 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.
Red Hat
kernel: untangle the do_mremap()
vendor_redhat·2009-12-07·CVSS 4.6
CVE-2010-0291 [MEDIUM] kernel: untangle the do_mremap()
kernel: untangle the do_mremap()
The Linux kernel before 2.6.32.4 allows local users to gain privileges or cause a denial of service (panic) by calling the (1) mmap or (2) mremap function, aka the "do_mremap() mess" or "mremap/mmap mess."
Statement: The risks associated with fixing this bug are greater than the important severity security risk. We therefore currently have no plans to fix this flaw in Red Hat Enterprise Linux 3 and 4. This issue was addressed in Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2010-0504.html and https://rhn.redhat.com/errata/RHSA-2010-0161.html.
No detection rules found.
Exploit-DB
vam shop 1.6 - Multiple Vulnerabilities
exploitdb·2011-01-11
CVE-2011-0504 vam shop 1.6 - Multiple Vulnerabilities
vam shop 1.6 - Multiple Vulnerabilities
---
Vulnerability ID: HTB22780
Reference: http://www.htbridge.ch/advisory/xsrf_csrf_in_vam_shop.html
Product: VaM Shop
Vendor: Vamsoft ( http://vamshop.ru/ )
Vulnerable Version: 1.6 and Probably Prior Versions
Vendor Notification: 28 December 2010
Vulnerability Type: CSRF (Cross-Site Request Forgery)
Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response
Risk level: Low
Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
Vulnerability Details:
The vulnerability exists due to failure in the "admin/accounting.php" script to properly verify the source of HTTP request.
Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication crede
Exploit-DB
Microsoft Windows - (Authenticated) User Code Execution (Metasploit)
exploitdb·2010-12-02
CVE-1999-0504 Microsoft Windows - (Authenticated) User Code Execution (Metasploit)
Microsoft Windows - (Authenticated) User Code Execution (Metasploit)
---
##
# $Id: psexec.rb 11204 2010-12-02 17:29:26Z todb $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
=begin
Windows XP systems that are not part of a domain default to treating all
network logons as if they were Guest. This prevents SMB relay attacks from
gaining administrative access to these systems. This setting can be found
under:
Local Security Settings >
Local Policies >
Security Options >
Network Access: Sharing and security model for local accounts
=end
require 'msf/core'
class Metasploit3 'Mi
Bugzilla
CVE-2010-1088 kernel: fix LOOKUP_FOLLOW on automount "symlinks"
bugzilla·2010-02-24·CVSS 5.4
CVE-2010-1088 [MEDIUM] CVE-2010-1088 kernel: fix LOOKUP_FOLLOW on automount "symlinks"
CVE-2010-1088 kernel: fix LOOKUP_FOLLOW on automount "symlinks"
Description of problem:
Make sure that automount "symlinks" are followed regardless of LOOKUP_FOLLOW; it should have no effect on them.
Upstream commit:
http://git.kernel.org/linus/ac278a9c505092dd82077a2446af8f9fc0d9c095
For this vulnerability to work, you need the support for O_NOFOLLOW (predates 2.6.12), openat (2.6.16 onwards) and use by NFS of 'trapdoor mounts' (2.6.18 onwards).
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0504 https://rhn.redhat.com/errata/RHSA-2010-0504.html
---
This issue has been addressed in following products:
MRG for RHEL-5
Via RHSA-2010:0631 https://rhn.redhat.com/errata/RHSA-2010-0631.html
Bugzilla
CVE-2010-1087 kernel: NFS: Fix an Oops when truncating a file
bugzilla·2010-02-22·CVSS 7.8
CVE-2010-1087 [HIGH] CVE-2010-1087 kernel: NFS: Fix an Oops when truncating a file
CVE-2010-1087 kernel: NFS: Fix an Oops when truncating a file
Description of problem:
The VM/VFS does not allow mapping->a_ops->invalidatepage() to fail. Unfortunately, nfs_wb_page_cancel() may fail if a fatal signal occurs. Since the NFS code assumes that the page stays mapped for as long as the writeback is active, we can end up Oopsing (among other things).
The only safe fix here is to convert nfs_wait_on_request(), so as to make it uninterruptible (as is already the case with wait_on_page_writeback()).
Upstream commit:
http://git.kernel.org/linus/9f557cd8073104b39528794d44e129331ded649f
Discussion:
*** Bug 570093 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0504 https://rhn.red
2010-03-30
Published