CVE-2010-0781
published 2010-09-21CVE-2010-0781: Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to…
PriorityP414medium4CVSS 2.0
AVNACLAuSCNINAP
EPSS
1.72%
75.1th percentile
Unspecified vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.33 allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted URL.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
| ibm | websphere_application_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
GPL FTP CWD overflow attempt
suricata·2010-09-23
CVE-1999-0219 GPL FTP CWD overflow attempt
GPL FTP CWD overflow attempt
Rule: alert ftp $EXTERNAL_NET any -> $HOME_NET any (msg:"GPL FTP CWD overflow attempt"; flow:established,to_server; content:"CWD"; nocase; isdataat:100,relative; pcre:"/^CWD\s[^\n]{100}/smi"; reference:bugtraq,11069; reference:bugtraq,1227; reference:bugtraq,1690; reference:bugtraq,6869; reference:bugtraq,7251; reference:bugtraq,7950; reference:cve,1999-0219; reference:cve,1999-1058; reference:cve,1999-1510; reference:cve,2000-1035; reference:cve,2000-1194; reference:cve,2001-0781; reference:cve,2002-0126; reference:cve,2002-0405; classtype:attempted-admin; sid:2101919; rev:25; metadata:created_at 2010_09_23, cve CVE_1999_0219, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_08;)
No public exploits indexed.
Bugzilla
CVE-2010-3173 NSS: insecure Diffie-Hellman key exchange
bugzilla·2010-10-12·CVSS 7.5
CVE-2010-3173 [HIGH] CVE-2010-3173 NSS: insecure Diffie-Hellman key exchange
CVE-2010-3173 NSS: insecure Diffie-Hellman key exchange
Mozilla cryptographer Nelson Bolyard reported that the SSL implementation
was permitting servers to use 256-bit Diffie-Hellman Ephemeral mode (DHE)
for key exchanges. A DHE key of this length is trivially breakable on
modern hardware so SSL servers operating in this mode were providing very
little effective security for its clients.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-72.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2010:0781 https://rhn.redhat.com/errata/RHSA-2010-0781.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-201
Bugzilla
CVE-2010-3177 Mozilla XSS in gopher parser when parsing hrefs
bugzilla·2010-10-12·CVSS 4.3
CVE-2010-3177 [MEDIUM] CVE-2010-3177 Mozilla XSS in gopher parser when parsing hrefs
CVE-2010-3177 Mozilla XSS in gopher parser when parsing hrefs
Google security researcher Robert Swiecki reported that functions used by
the Gopher parser to convert text to HTML tags could be exploited to turn
text into executable JavaScript. If an attacker could create a file or
directory on a Gopher server with the encoded script as part of its name
the script would then run in a victim's browser within the context of the
site.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-68.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 3
Red Hat Enterprise Linux 4
Via RHSA-2010:0781 https://rhn.redhat.com/errata/RHSA-2010-0781.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux
Bugzilla
CVE-2009-2696 tomcat: missing fix for CVE-2009-0781
bugzilla·2010-07-21·CVSS 4.3
CVE-2009-2696 [MEDIUM] CVE-2009-2696 tomcat: missing fix for CVE-2009-0781
CVE-2009-2696 tomcat: missing fix for CVE-2009-0781
The RHSA-2009:1164 Tomcat security update for Red Hat Enterprise Linux 5
did not, unlike the erratum text stated, provide a fix for CVE-2009-0781, a
cross-site scripting (XSS) flaw in the examples calendar application. A
missing patch is considered a security regression, and requires a new CVE
name. This regression is assigned CVE-2009-2696. It fixes the same issue as
CVE-2009-0781 and is specific to Red Hat Enterprise Linux 5.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2010:0580 https://rhn.redhat.com/errata/RHSA-2010-0580.html
http://secunia.com/advisories/41722http://www-01.ibm.com/support/docview.wss?uid=swg1PM11807http://www-01.ibm.com/support/docview.wss?uid=swg27007951https://exchange.xforce.ibmcloud.com/vulnerabilities/61890http://secunia.com/advisories/41722http://www-01.ibm.com/support/docview.wss?uid=swg1PM11807http://www-01.ibm.com/support/docview.wss?uid=swg27007951https://exchange.xforce.ibmcloud.com/vulnerabilities/61890
2010-09-21
Published