CVE-2010-0782
published 2010-10-20CVE-2010-0782: IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.68%
48.0th percentile
IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3175 Mozilla miscellaneous memory safety hazards
bugzilla·2010-10-12·CVSS 9.3
CVE-2010-3175 [CRITICAL] CVE-2010-3175 Mozilla miscellaneous memory safety hazards
CVE-2010-3175 Mozilla miscellaneous memory safety hazards
Mozilla developers identified and fixed several memory safety bugs in the
browser engine used in Firefox and other Mozilla-based products. Some of
these bugs showed evidence of memory corruption under certain
circumstances, and we presume that with enough effort at least some of
these could be exploited to run arbitrary code.
Gary Kwong, Martijn Wargers and Siddharth Agarwal reported memory safety
problems that affected Firefox 3.6 only.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-64.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0782 https://rhn.redhat.com/errata/RHSA-2010-0782.html
---
This issue
Bugzilla
CVE-2010-3178 Mozilla cross-site information disclosure via modal calls
bugzilla·2010-10-12·CVSS 5.8
CVE-2010-3178 [MEDIUM] CVE-2010-3178 Mozilla cross-site information disclosure via modal calls
CVE-2010-3178 Mozilla cross-site information disclosure via modal calls
Security researcher Eduardo Vela N reported that if a web page opened a new
window and used a javascript: URL to make a modal call, such as alert(),
then subsequently navigated the page to a different domain, once the modal
call returned the opener of the window could get access to objects in the
navigated window. This is a violation of the same-origin policy and could
be used by an attacker to steal information from another web site.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-69.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0782 https://rhn.redhat.com/errata/RHSA-2010-0782.html
---
T
Bugzilla
CVE-2010-3179 Mozilla buffer overflow and memory corruption using document.write
bugzilla·2010-10-12·CVSS 9.3
CVE-2010-3179 [CRITICAL] CVE-2010-3179 Mozilla buffer overflow and memory corruption using document.write
CVE-2010-3179 Mozilla buffer overflow and memory corruption using document.write
Security researcher Alexander Miller reported that passing an excessively
long string to document.write could cause text rendering routines to end up
in an inconsistent state with sections of stack memory being overwritten
with the string data. An attacker could potentially use this flaw to crash
a victim's browser and run arbitrary code on their computer.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2010/mfsa2010-65.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0782 https://rhn.redhat.com/errata/RHSA-2010-0782.html
---
This issue has been addressed in following products:
Red Hat Enterprise
http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68707http://www-01.ibm.com/support/docview.wss?uid=swg27014224https://exchange.xforce.ibmcloud.com/vulnerabilities/60018http://www-01.ibm.com/support/docview.wss?uid=swg1IZ68707http://www-01.ibm.com/support/docview.wss?uid=swg27014224https://exchange.xforce.ibmcloud.com/vulnerabilities/60018
2010-10-20
Published