CVE-2010-0580
published 2010-03-25CVE-2010-0580: Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message…
critical10CVSS 3.1
AVNACLAuNCCICAC
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
GHSA
GHSA-crxg-42h5-fw55: Unspecified vulnerability in the SIP implementation in Cisco IOS 12
ghsa_unreviewed·2022-05-02
CVE-2010-0580 [HIGH] GHSA-crxg-42h5-fw55: Unspecified vulnerability in the SIP implementation in Cisco IOS 12
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco·2010-03-24·CVSS 10.0
CVE-2010-0579 [CRITICAL] CWE-399 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP)
implementation in Cisco IOS® Software that could
allow an unauthenticated, remote attacker to cause a reload of an affected
device when SIP operation is enabled. Remote code execution may also be
possible.
Cisco has released software updates that address these vulnerabilities. For devices that must run SIP there are no workarounds;
however, mitigations are available to limit exposure of the
vulnerabilities.
This advisory is posted at
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20100324-sip.
Note: The March 24, 2010, Cisco IOS Software Security Advisory bundled
publication includes seven Securit
Cisco
Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
vendor_cisco
CVE-2010-0580 Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
CVE-2010-0580: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities
Multiple vulnerabilities exist in the Session Initiation Protocol (SIP) implementation in Cisco IOS ® Software that could allow an unauthenticated, remote attacker to cause a reload of an affected device when SIP operation is enabled. Remote code execution may also be possible. Cisco has released software updates that address these vulnerabilities. For devices that must run SIP there are no
CWE: CWE-399, CWE-94, CWE-399, CWE-94
Bug IDs: CSCsz48680, CSCsz89904, CSCtb93416, CSCsz48680, CSCsz89904
No detection rules found.
No public exploits indexed.
arXiv
Formal Black-Box Analysis of Routing Protocol Implementations
arxiv_fulltext·2017-09-23
Formal Black-Box Analysis of Routing Protocol Implementations
Formal Black-Box Analysis of Routing Protocol Implementations
Adi Sosnovich Orna Grumberg
Computer Science Department
Technion -- Israel Institute of Technology
Gabi Nakibly
Rafael -- Advanced Defense Systems Ltd.
empty
## Abstract
The Internet infrastructure relies entirely on open standards for its routing protocols. However, the overwhelming majority of routers on the Internet are proprietary and closed-source. Hence, there is no straightforward way to analyze them. Specifically, one cannot easily and systematically identify deviations of a router's routing functionality from the routing protocol's standard. Such deviations (either deliberate or inadvertent) are particularly important to identify since they present non-standard functionalities which have not been openly and rigo
Bugzilla
CVE-2009-2696 tomcat: missing fix for CVE-2009-0781
bugzilla·2010-07-21·CVSS 4.3
CVE-2009-2696 [MEDIUM] CVE-2009-2696 tomcat: missing fix for CVE-2009-0781
CVE-2009-2696 tomcat: missing fix for CVE-2009-0781
The RHSA-2009:1164 Tomcat security update for Red Hat Enterprise Linux 5
did not, unlike the erratum text stated, provide a fix for CVE-2009-0781, a
cross-site scripting (XSS) flaw in the examples calendar application. A
missing patch is considered a security regression, and requires a new CVE
name. This regression is assigned CVE-2009-2696. It fixes the same issue as
CVE-2009-0781 and is specific to Red Hat Enterprise Linux 5.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0580 https://rhn.redhat.com/errata/RHSA-2010-0580.html
http://secunia.com/advisories/39068http://securitytracker.com/id?1023744http://tools.cisco.com/security/center/viewAlert.x?alertId=20064http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtmlhttp://secunia.com/advisories/39068http://securitytracker.com/id?1023744http://tools.cisco.com/security/center/viewAlert.x?alertId=20064http://www.cisco.com/en/US/products/products_security_advisory09186a0080b20f32.shtml
2010-03-25
Published