CVE-2010-0924
published 2010-03-03CVE-2010-0924: cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of…
PriorityP415medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.16%
63.9th percentile
cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | — | — |
| apple | safari | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4q7x-c564-25jq: cfnetwork
ghsa_unreviewed·2022-05-02
CVE-2010-0924 [MEDIUM] GHSA-4q7x-c564-25jq: cfnetwork
cfnetwork.dll 1.450.5.0 in CFNetwork, as used by safari.exe 531.21.10 in Apple Safari 4.0.3 and 4.0.4 on Windows, allows remote attackers to cause a denial of service (application crash) via a long string in the BACKGROUND attribute of a BODY element.
Red Hat
Wireshark: Heap-based buffer overflow in LDSS dissector
vendor_redhat·2010-11-18·CVSS 7.5
CVE-2010-4300 [HIGH] CWE-122 Wireshark: Heap-based buffer overflow in LDSS dissector
Wireshark: Heap-based buffer overflow in LDSS dissector
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.
Statement: This issue did not affect the versions of wireshark as shipped with Red Hat Enterprise Linux 4 and 5 as they did not include support for the Local Download Sharing Service (LDSS) protocol.
This issue was addressed in Red Hat Enterprise Linux 6 via
https://rhn.redhat.com/errata/RHSA-2010-0924.html.
Package: wireshark (Red Hat Enterprise Linux 4) - Not affected
Package: wireshar
Red Hat
wireshark: stack overflow in BER dissector
vendor_redhat·2010-09-13·CVSS 5.0
CVE-2010-3445 [MEDIUM] wireshark: stack overflow in BER dissector
wireshark: stack overflow in BER dissector
Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update to wireshark in Red Hat Enterprise Linux 4 and 5 may address this flaw.
This issue was addressed in Red Hat Enterprise Linux 6 via https://rhn.redhat.com/errata/RHSA-2010-0924.html.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2010-03-03
Published