CVE-2012-0100
published 2012-01-18CVE-2012-0100: Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors…
PriorityP418medium6.8CVSS 2.0
AVLACLAuSCCICAC
EPSS
0.35%
27.5th percentile
Unspecified vulnerability in Oracle Solaris 9, 10, and 11 Express allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Kerberos.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | sunos | — | — |
| sun | sunos | — | — |
| sun | sunos | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
exploitdb·2017-03-15
CVE-2017-0100 Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
---
/*
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1021
Windows: COM Session Moniker EoP
Platform: Tested on Windows 10 14393, Server 2012 R2
Class: Elevation of Privilege
Summary:
When activating an object using the session moniker the DCOM activator doesn’t check if the current user has permission allowing a user to start an arbitrary process in another logged on user’s session.
Description:
The COM session moniker allows a user to specify the interactive session that’s to be used when a DCOM object is registered with an AppID with RunAs of “Interactive User”. As switching sessions is not something a normal user can do you’d assume that this would be only accessible to administrators (or a
Exploit-DB
NetSarang Xlpd Printer Daemon 4 - Denial of Service
exploitdb·2012-02-02
CVE-2012-1009 NetSarang Xlpd Printer Daemon 4 - Denial of Service
NetSarang Xlpd Printer Daemon 4 - Denial of Service
---
##############################################################################
#
# Title : NetSarang Xlpd Printer Daemon Denial of Service Vulnerability
# Author : Prabhu S Angadi SecPod Technologies (www.secpod.com)
# Vendor : http://www.netsarang.com
# Advisory : http://secpod.org/blog/?p=457
# http://secpod.org/advisories/SecPod_Exploit_NetSarang_Xlpd_Printer_Daemon_DoS_Vuln.txt
# http://secpod.org/exploits/SecPod_Exploit_NetSarang_Xlpd_Printer_Daemon_DoS.py
# Software : NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186
# Date : 01/02/2012
#
##############################################################################
SecPod ID: 1033 14/12/2011 Issue Discovered
20/01/2012 Vendor Notified
No Response
01/
No writeups or analysis indexed.
http://osvdb.org/78421http://secunia.com/advisories/48308http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/72496http://osvdb.org/78421http://secunia.com/advisories/48308http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/72496
2012-01-18
Published