CVE-2010-3596
published 2011-01-19CVE-2010-3596: Unspecified vulnerability in the mod_ssl component in Oracle Secure Backup 10.3.0.2 allows remote attackers to affect integrity and availability via unknown…
PriorityP429medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
1.49%
71.3th percentile
Unspecified vulnerability in the mod_ssl component in Oracle Secure Backup 10.3.0.2 allows remote attackers to affect integrity and availability via unknown vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | secure_backup | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
bugzilla·2010-01-11·CVSS 7.5
CVE-2010-0277 [HIGH] CVE-2010-0277 pidgin MSN protocol plugin memory corruption
CVE-2010-0277 pidgin MSN protocol plugin memory corruption
slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and
Adium 1.3.8 allows remote attackers to cause a denial of service
(memory corruption) or possibly have unspecified other impact via
unknown vectors, a different issue than CVE-2010-0013.
Reference: URL:http://www.openwall.com/lists/oss-security/2010/01/07/2
Reference: MISC:http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
Discussion:
http://pidgin.im/news/security/?id=43
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Via RHSA-2010:0115 https://rhn.redhat.com/errata/RHSA-2010-0115.html
---
pidgin-2.6.6-1.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.
Bugzilla
CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
bugzilla·2010-01-05·CVSS 7.5
CVE-2010-0013 [HIGH] CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
CVE-2010-0013 pidgin/libpurple: MSN custom smiley request directory traversal file disclosure
On 26C3, Fabian Yamaguchi presented a directory traversal flaw in libpurple MSN protocol implementation. The flaw can be used by the remote attacker to download arbitrary file readable by the user running instant messenger using libpurple (such as pidgin) from the victim's computer via MSN emoticon / smiley download request. More details in Fabian's presentation:
http://events.ccc.de/congress/2009/Fahrplan/events/3596.en.html
http://events.ccc.de/congress/2009/Fahrplan/attachments/1483_26c3_ipv4_fuckups.pdf
(slides 10-22)
Upstream fix:
http://d.pidgin.im/viewmtn/revision/info/c64a1adc8bda2b4aeaae1f273541afbc4f71b810
which depends on the other two commits:
http://d.pidgin.im/viewmtn/revision/in
http://secunia.com/advisories/42918http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlhttp://www.securityfocus.com/bid/45850http://www.securitytracker.com/id?1024974http://www.vupen.com/english/advisories/2011/0142http://secunia.com/advisories/42918http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.htmlhttp://www.securityfocus.com/bid/45850http://www.securitytracker.com/id?1024974http://www.vupen.com/english/advisories/2011/0142
2011-01-19
Published