CVE-2012-0388
published 2012-03-29CVE-2012-0388: Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of…
PriorityP432high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.52%
71.9th percentile
Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_cisco7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco IOS Software Zone-Based Firewall Vulnerabilities
vendor_cisco·2012-03-28·CVSS 7.8
CVE-2012-0387 [HIGH] Cisco IOS Software Zone-Based Firewall Vulnerabilities
Cisco IOS Software Zone-Based Firewall Vulnerabilities
Cisco IOS Software contains four vulnerabilities related to Cisco IOS Zone-Based Firewall features. These vulnerabilities are as follows:
Memory Leak Associated with Crafted IP Packets
Memory Leak in HTTP Inspection
Memory Leak in H.323 Inspection
Memory Leak in SIP Inspection
Workarounds that mitigate these vulnerabilities are not available.
Cisco has released software updates that address these vulnerabilities.
This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-zbfw
Note: The March 28, 2012, Cisco IOS Software Security Advisory bundled publication includes nine Cisco Security Advisories. Each advisory lists the Cisco IOS Software
Cisco
Cisco IOS Software Zone-Based Firewall Vulnerabilities
vendor_cisco
CVE-2012-0388 Cisco IOS Software Zone-Based Firewall Vulnerabilities
CVE-2012-0388: Cisco IOS Software Zone-Based Firewall Vulnerabilities
Cisco IOS Software contains four vulnerabilities related to Cisco IOS Zone-Based Firewall features. These vulnerabilities are as follows: Memory Leak Associated with Crafted IP Packets Memory Leak in HTTP Inspection Memory Leak in H.323 Inspection Memory Leak in SIP Inspection
Bug IDs: CSCti46171, CSCto89536, CSCtq36153, CSCti46171, CSCto89536
GHSA
GHSA-wgvw-vfq9-3m2p: Memory leak in the H
ghsa_unreviewed·2022-05-04
CVE-2012-0388 [HIGH] GHSA-wgvw-vfq9-3m2p: Memory leak in the H
Memory leak in the H.323 inspection feature in the Zone-Based Firewall in Cisco IOS 12.4, 15.0, 15.1, and 15.2 allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed transit H.323 traffic, aka Bug ID CSCtq45553.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0456 CVE-2012-0457 Mozilla: SVG issues found with Address Sanitizer (MFSA 2012-14)
bugzilla·2012-03-14·CVSS 5.0
CVE-2012-0456 [MEDIUM] CVE-2012-0456 CVE-2012-0457 Mozilla: SVG issues found with Address Sanitizer (MFSA 2012-14)
CVE-2012-0456 CVE-2012-0457 Mozilla: SVG issues found with Address Sanitizer (MFSA 2012-14)
Security researcher Atte Kettunen from OUSPG found two issues with Firefox's handling of SVG using the Address Sanitizer tool. The first issue, critically rated, is a use-after-free in SVG animation that could potentially lead to arbitrary code execution. The second issue is rated moderate and is an out of bounds read in SVG Filters. This could potentially incorporate data from the user's memory, making it accessible to the page content.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-14.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.htm
Bugzilla
CVE-2012-0458 Mozilla: Escalation of privilege with Javascript: URL as home page (MFSA 2012-16)
bugzilla·2012-03-14·CVSS 6.8
CVE-2012-0458 [MEDIUM] CVE-2012-0458 Mozilla: Escalation of privilege with Javascript: URL as home page (MFSA 2012-16)
CVE-2012-0458 Mozilla: Escalation of privilege with Javascript: URL as home page (MFSA 2012-16)
Security researcher Mariusz Mlynski reported that an attacker able to convince a potential victim to set a new home page by dragging a link to the "home" button can set that user's home page to a javascript: URL. Once this is done the attacker's page can cause repeated crashes of the browser, eventually getting the script URL loaded in the privileged about:sessionrestore context.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-16.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
---
This issue has been addressed in following prod
Bugzilla
CVE-2012-0451 Mozilla: XSS with multiple Content Security Policy headers (MFSA 2012-15)
bugzilla·2012-03-14·CVSS 4.3
CVE-2012-0451 [MEDIUM] CVE-2012-0451 Mozilla: XSS with multiple Content Security Policy headers (MFSA 2012-15)
CVE-2012-0451 Mozilla: XSS with multiple Content Security Policy headers (MFSA 2012-15)
Security Researcher Mike Brooks of Sitewatch reported that if multiple Content Security Policy (CSP) headers are present on a page, they have an additive effect page policy. Using carriage return line feed (CRLF) injection, a new CSP rule can be introduced which allows for cross-site scripting (XSS) on sites with a separate header injection vulnerability.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-15.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Bugzilla
CVE-2012-0460 Mozilla: window.fullScreen writeable by untrusted content (MFSA 2012-18)
bugzilla·2012-03-14·CVSS 6.4
CVE-2012-0460 [MEDIUM] CVE-2012-0460 Mozilla: window.fullScreen writeable by untrusted content (MFSA 2012-18)
CVE-2012-0460 Mozilla: window.fullScreen writeable by untrusted content (MFSA 2012-18)
Mozilla developer Matt Brubeck reported that window.fullScreen is writeable by untrusted content now that the DOM fullscreen API is enabled. Because window.fullScreen does not include mozRequestFullscreen's security protections, it could be used for UI spoofing. This code change makes window.fullScreen read only by untrusted content, forcing the use of the DOM fullscreen API in normal usage.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-18.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
---
This issue has been addressed in following p
Bugzilla
CVE-2012-0461 CVE-2012-0462 CVE-2012-0464 Mozilla: Miscellaneous memory safety hazards (rv:11.0/ rv:10.0.3 / rv:1.9.2.28) (MFSA 2012-19)
bugzilla·2012-03-14·CVSS 7.5
CVE-2012-0461 [HIGH] CVE-2012-0461 CVE-2012-0462 CVE-2012-0464 Mozilla: Miscellaneous memory safety hazards (rv:11.0/ rv:10.0.3 / rv:1.9.2.28) (MFSA 2012-19)
CVE-2012-0461 CVE-2012-0462 CVE-2012-0464 Mozilla: Miscellaneous memory safety hazards (rv:11.0/ rv:10.0.3 / rv:1.9.2.28) (MFSA 2012-19)
Mozilla developers identified and fixed several memory safety bugs in the browser engine used in Firefox and other Mozilla-based products. Some of these bugs showed evidence of memory corruption under certain circumstances, and we presume that with enough effort at least some of these could be exploited to run arbitrary code.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-19.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
---
This issue has been addressed in following products:
Red Hat
Bugzilla
CVE-2012-0455 Mozilla: XSS with Drag and Drop and Javascript: URL (MFSA 2012-13)
bugzilla·2012-03-14·CVSS 4.3
CVE-2012-0455 [MEDIUM] CVE-2012-0455 Mozilla: XSS with Drag and Drop and Javascript: URL (MFSA 2012-13)
CVE-2012-0455 Mozilla: XSS with Drag and Drop and Javascript: URL (MFSA 2012-13)
Firefox prevents the dropping of javascript: links onto a frame to prevent malicious sites from tricking users into performing a cross-site scripting (XSS) attacks on themselves. Security researcher Soroush Dalili reported a way to bypass this protection.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-13.html
Discussion:
*** Bug 772690 has been marked as a duplicate of this bug. ***
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-20
Bugzilla
CVE-2012-0459 Mozilla: Crash when accessing keyframe cssText after dynamic modification (MFSA 2012-17)
bugzilla·2012-03-14·CVSS 7.5
CVE-2012-0459 [HIGH] CVE-2012-0459 Mozilla: Crash when accessing keyframe cssText after dynamic modification (MFSA 2012-17)
CVE-2012-0459 Mozilla: Crash when accessing keyframe cssText after dynamic modification (MFSA 2012-17)
Mozilla community member Daniel Glazman of Disruptive Innovations reported a crash when accessing a keyframe's cssText after dynamic modification. This crash may be potentially exploitable.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-17.html
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0388 https://rhn.redhat.com/errata/RHSA-2012-0388.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0387 https://rhn.redhat.com/errata/RHSA-2012-0387.html
http://secunia.com/advisories/48608http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-zbfwhttp://www.securityfocus.com/bid/52753http://www.securitytracker.com/id?1026861https://exchange.xforce.ibmcloud.com/vulnerabilities/74436http://secunia.com/advisories/48608http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120328-zbfwhttp://www.securityfocus.com/bid/52753http://www.securitytracker.com/id?1026861https://exchange.xforce.ibmcloud.com/vulnerabilities/74436
2012-03-29
Published