CVE-2012-0623
published 2012-03-08CVE-2012-0623: WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.76%
88.7th percentile
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | < 5.1 | 5.1 |
| apple | itunes | < 10.6 | 10.6 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m8fm-gg8w-rfmg: WebKit, as used in Apple iOS before 5
ghsa_unreviewed·2022-05-14
CVE-2012-0623 [HIGH] CWE-119 GHSA-m8fm-gg8w-rfmg: WebKit, as used in Apple iOS before 5
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-03-07-1 and APPLE-SA-2012-03-07-2.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0601 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0619 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0616 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0605 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0620 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, and CVE-2013-0623.
Red Hat
acroread: multiple code execution flaws (APSB13-02)
vendor_redhat·2013-01-08·CVSS 10.0
CVE-2013-0623 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, and CVE-2013-0620.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
bugzilla·2013-05-03·CVSS 5.0
CVE-2013-2051 [MEDIUM] CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
CVE-2013-2051 tomcat: DIGEST authentication vulnerable to replay attacks
It was found that the fix for CVE-2012-5887 shipped for tomcat 6 on Red Hat Enterprise Linux 6 (RHSA-2013:0623) was incomplete. The fix only allowed DIGEST authentication to succeed when a stale nonce was provided, rather than when a stale nonce was NOT provided. As a result, DIGEST authentication did not function. However, a man-in-the-middle attacker could record a DIGEST authentication exchange, wait until the associated nonce is marked as stale on the server, then successfully replay this request.
Discussion:
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0869 https://rhn.redhat.com/errata/RHSA-2013-0869.html
Bugzilla
acroread: multiple code execution flaws (APSB13-02)
bugzilla·2013-01-09·CVSS 10.0
CVE-2012-1530 [CRITICAL] acroread: multiple code execution flaws (APSB13-02)
acroread: multiple code execution flaws (APSB13-02)
Adobe security bulletin APSB13-02 describes multiple security flaws that could cause Adobe Acrobat Reader to crash and potentially allow an attacker to take control of the affected system:
These updates resolve memory corruption vulnerabilities that could lead to code execution (CVE-2012-1530, CVE-2013-0601, CVE-2013-0605, CVE-2013-0616, CVE-2013-0619, CVE-2013-0620, CVE-2013-0623).
These updates resolve a use-after-free vulnerability that could lead to code execution (CVE-2013-0602).
These updates resolve heap overflow vulnerabilities that could lead to code execution (CVE-2013-0603, CVE-2013-0604).
These updates resolve stack overflow vulnerabilities that could lead to code execution (CVE-2013-0610, CVE-2013-0626).
These updates r
http://lists.apple.com/archives/security-announce/2012/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Mar/msg00003.htmlhttp://secunia.com/advisories/48274http://secunia.com/advisories/48288http://secunia.com/advisories/48377http://www.securityfocus.com/bid/52365http://www.securitytracker.com/id?1026774https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17431http://lists.apple.com/archives/security-announce/2012/Mar/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2012/Mar/msg00001.htmlhttp://lists.apple.com/archives/security-announce/2012/Mar/msg00003.htmlhttp://secunia.com/advisories/48274http://secunia.com/advisories/48288http://secunia.com/advisories/48377http://www.securityfocus.com/bid/52365http://www.securitytracker.com/id?1026774https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17431
2012-03-08
Published