CVE-2010-2408
published 2010-10-14CVE-2010-2408: Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
0.98%
58.6th percentile
Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
| oracle | e-business_suite | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mr7x-3456-7m2m: Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11
ghsa_unreviewed·2022-05-17
CVE-2010-2408 [MEDIUM] GHSA-mr7x-3456-7m2m: Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11
Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.
Red Hat
w3m: doesn't handle NULL in Common Name properly
vendor_redhat·2010-06-14·CVSS 5.9
CVE-2010-2074 [MEDIUM] w3m: doesn't handle NULL in Common Name properly
w3m: doesn't handle NULL in Common Name properly
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: w3m (Red Hat Enterprise Linux 6) - Not affected
Red Hat
libESMTP: Multiple certificate validation flaws
vendor_redhat·2010-03-03·CVSS 5.9
CVE-2010-1192 [MEDIUM] libESMTP: Multiple certificate validation flaws
libESMTP: Multiple certificate validation flaws
libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Package: libesmtp (Red Hat Enterprise Linux 6) - Affected
Red Hat
OpenLDAP: Doesn't properly handle NULL character in subject Common Name
vendor_redhat·2009-08-10·CVSS 5.9
CVE-2009-3767 [MEDIUM] OpenLDAP: Doesn't properly handle NULL character in subject Common Name
OpenLDAP: Doesn't properly handle NULL character in subject Common Name
libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
Statement: This issue was addressed in the openldap packages as shipped with Red Hat Enterprise Linux 5 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0198.html and https://rhn.redhat.com/errata/RHSA-2010-0543.html respectively.
The Red Hat Security Response Team has rated this issue as having moderate security imp
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-3170 [MEDIUM] CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
CVE-2010-3170 firefox/nss: doesn't handle IP-based wildcards in X509 certificates safely
Richard Moore and Simon Ward reported flaws in the way browsers such
as Firefox handled wildcard characters in the Common Name field of
a certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Firefox, the attacker could
use the certificate during the man-in-the-middle attack and potentially
confuse Firefox into accepting it by mistake. Different vulnerability than
CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335731
Discussion:
This will be fixed in NSS 3.12.8
---
Mozilla has assigned CVE-2010-3170 identifier to this issue.
Mozilla upstream bug:
[3]
Bugzilla
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
bugzilla·2010-09-03·CVSS 5.9
CVE-2010-5076 [MEDIUM] CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
CVE-2010-5076 Qt: QSslSocket incorrect handling of IP wildcards in certificate Common Name
Richard Moore and Simon Ward reported flaw in the way Qt software toolkit
handled wildcard characters in the Common Name field of a x509v3 digital
certificate. If an attacker is able to get a carefully-crafted certificate,
signed by a Certificate Authority trusted by Konqueror / Arora web browsers,
the attacker could use the certificate during the man-in-the-middle attack
and potentially confuse Konqueror / Arora into accepting it by mistake.
Different vulnerability than CVE-2009-2408.
References:
[1] http://www.westpoint.ltd.uk/advisories/wp-10-0001.txt
[2] http://bugs.gentoo.org/show_bug.cgi?id=335730
Discussion:
Upstream commit addressing this issue:
http://qt.gitorious.org/qt/qt/commit/846f1b
2010-10-14
Published