CVE-2012-0135
published 2012-04-18CVE-2012-0135: Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows remote authenticated users to cause a denial of service via unknown vectors.
PriorityP411low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.91%
77.6th percentile
Unspecified vulnerability in HP System Management Homepage (SMH) before 7.0 allows remote authenticated users to cause a denial of service via unknown vectors.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | system_management_homepage | <= 6.1.0-103 | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
| hp | system_management_homepage | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0497 OpenJDK: insufficient checking of the graphics rendering object (2D, 7112642)
bugzilla·2012-02-10·CVSS 10.0
CVE-2012-0497 [CRITICAL] CVE-2012-0497 OpenJDK: insufficient checking of the graphics rendering object (2D, 7112642)
CVE-2012-0497 OpenJDK: insufficient checking of the graphics rendering object (2D, 7112642)
It was discovered that Java2D did not properly check graphics rendering objects before passing them to the native renderer. This could lead to Java Virtual Machine (JVM) crash or Java sandbox bypass.
Discussion:
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0135 https://rhn.redhat.com/errata/RHSA-2012-0135.html
---
Patches were applied in following IcedTea versions:
* IcedTea6 1.8.13 (based on OpenJDK6 b18)
* IcedTea6 1.9.13 (based on OpenJDK6 b20)
* IcedTea6 1.10.6 (based on OpenJDK6 b22)
* IcedTea6 1.11.1 (based on OpenJDK6 b24)
* IcedTea 2
Bugzilla
CVE-2012-0503 OpenJDK: unrestricted use of TimeZone.setDefault() (i18n, 7110687)
bugzilla·2012-02-09·CVSS 7.5
CVE-2012-0503 [HIGH] CVE-2012-0503 OpenJDK: unrestricted use of TimeZone.setDefault() (i18n, 7110687)
CVE-2012-0503 OpenJDK: unrestricted use of TimeZone.setDefault() (i18n, 7110687)
It was discovered that the use of TimeZone.setDefault() is not restricted by SecurityManager, allowing untrusted Java application or applet to set new default time zone and hence bypass SecurityManager restrictions.
Discussion:
External Reference:
http://www.oracle.com/technetwork/topics/security/javacpufeb2012-366318.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:0135 https://rhn.redhat.com/errata/RHSA-2012-0135.html
---
Patches were applied in following IcedTea versions:
* IcedTea6 1.8.13 (based on OpenJDK6 b18)
* IcedTea6 1.9.13 (based on OpenJDK6 b20)
* IcedTea6 1.10.6 (based on OpenJDK6 b22)
* IcedTea6 1.11.1 (based on OpenJDK6 b24)
* Iced
2012-04-18
Published