CVE-2012-0710
published 2012-03-20CVE-2012-0710: IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.73%
84.4th percentile
IBM DB2 9.1 before FP11, 9.5 before FP9, 9.7 before FP5, and 9.8 before FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Distributed Relational Database Architecture (DRDA) request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-1946 Mozilla: Use-after-free while replacing/inserting a node in a document (MFSA 2012-38)
bugzilla·2012-06-03·CVSS 9.3
CVE-2012-1946 [CRITICAL] CVE-2012-1946 Mozilla: Use-after-free while replacing/inserting a node in a document (MFSA 2012-38)
CVE-2012-1946 Mozilla: Use-after-free while replacing/inserting a node in a document (MFSA 2012-38)
Security researcher Arthur Gerkis used the Address Sanitizer tool to find a use-after-free while replacing/inserting a node in a document. This use-after-free could possibly allow for remote code execution.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-38.html
Discussion:
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges security researcher Arthur Gerkis as the original
reporter.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0710 https://rhn.redhat.com/errata/RHSA-2012-0710.html
---
This issue has been addressed in follo
Bugzilla
CVE-2012-1944 Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
bugzilla·2012-06-03·CVSS 4.3
CVE-2012-1944 [MEDIUM] CVE-2012-1944 Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
CVE-2012-1944 Mozilla: Content Security Policy inline-script bypass (MFSA 2012-36)
Security researcher Adam Barth found that inline event handlers, such as onclick, were no longer blocked by Content Security Policy's (CSP) inline-script blocking feature. Web applications relying on this feature of CSP to protect against cross-site scripting (XSS) were not fully protected.
Reference:
http://www.mozilla.org/security/announce/2012/mfsa2012-36.html
http://www.w3.org/TR/CSP/
Discussion:
Acknowledgements:
Red Hat would like to thank the Mozilla project for reporting this issue.
Upstream acknowledges security researcher Adam Barth as the original
reporter.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2012:0710 htt
http://www-01.ibm.com/support/docview.wss?uid=swg1IC76781http://www-01.ibm.com/support/docview.wss?uid=swg1IC76899http://www-01.ibm.com/support/docview.wss?uid=swg1IC76901http://www-01.ibm.com/support/docview.wss?uid=swg1IC76902http://www-01.ibm.com/support/docview.wss?uid=swg21588090http://www.securityfocus.com/bid/78282https://exchange.xforce.ibmcloud.com/vulnerabilities/73494https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15078http://www-01.ibm.com/support/docview.wss?uid=swg1IC76781http://www-01.ibm.com/support/docview.wss?uid=swg1IC76899http://www-01.ibm.com/support/docview.wss?uid=swg1IC76901http://www-01.ibm.com/support/docview.wss?uid=swg1IC76902http://www-01.ibm.com/support/docview.wss?uid=swg21588090http://www.securityfocus.com/bid/78282https://exchange.xforce.ibmcloud.com/vulnerabilities/73494https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15078
2012-03-20
Published