CVE-2012-1350
published 2012-08-06CVE-2012-1350: Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281…
PriorityP335high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
1.89%
77.4th percentile
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
Affected
304 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | aironet_ap340 | — | — |
| cisco | aironet_ap350 | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
| cisco | ios | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4g7m-fgrx-qqc3: Cisco IOS 12
ghsa_unreviewed·2022-05-17
CVE-2012-1350 [HIGH] GHSA-4g7m-fgrx-qqc3: Cisco IOS 12
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
Red Hat
kernel: gro: only reset frag0 when skb can be pulled
vendor_redhat·2011-07-27·CVSS 5.7
CVE-2011-2723 [MEDIUM] kernel: gro: only reset frag0 when skb can be pulled
kernel: gro: only reset frag0 when skb can be pulled
The skb_gro_header_slow function in include/linux/netdevice.h in the Linux kernel before 2.6.39.4, when Generic Receive Offload (GRO) is enabled, resets certain fields in incorrect situations, which allows remote attackers to cause a denial of service (system crash) via crafted network traffic.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not backport the upstream commit a5b1cf28 that introduced this issue. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1386.html, https://rhn.redhat.com/errata/RHSA-2011-1350.html, and https://rhn.redhat.com/errata/RHSA-2012-0010.html.
Package: kern
Red Hat
kernel: perf: Fix software event overflow
vendor_redhat·2011-07-22·CVSS 5.5
CVE-2011-2918 [MEDIUM] kernel: perf: Fix software event overflow
kernel: perf: Fix software event overflow
The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.
Statement: This issue did not affect Red Hat Enterprise Linux 4 and 5 as they did not include support for perf. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2012-0333.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Red Hat
kernel: af_packet: infoleak
vendor_redhat·2011-06-07·CVSS 5.5
CVE-2011-2898 [MEDIUM] kernel: af_packet: infoleak
kernel: af_packet: infoleak
net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit 393e52e3 that introduced this flaw. This has been addressed in Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2012-0010.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2918 kernel: perf: Fix software event overflow
bugzilla·2011-08-15·CVSS 5.5
CVE-2011-2918 [MEDIUM] CVE-2011-2918 kernel: perf: Fix software event overflow
CVE-2011-2918 kernel: perf: Fix software event overflow
Under certain circumstances software event overflows go wrong and deadlock. Avoid trying to delete a timer from the timer callback.
Upstream fix:
a8b0ca17b80e92faab46ee7179ba9e99ccb61233
References:
https://lkml.org/lkml/2011/7/27/337
https://lkml.org/lkml/2011/7/28/284
Discussion:
Statement:
This issue did not affect Red Hat Enterprise Linux 4 and 5 as they did not include support for perf. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2012-0333.html.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:1350 https://rhn.redhat.com/errata/RHSA-2011-1350.h
Bugzilla
CVE-2011-2898 kernel: af_packet: infoleak
bugzilla·2011-08-04·CVSS 5.5
CVE-2011-2898 [MEDIUM] CVE-2011-2898 kernel: af_packet: infoleak
CVE-2011-2898 kernel: af_packet: infoleak
In 2.6.27, commit 393e52e33c6c2 (packet: deliver VLAN TCI to userspace) added a small information leak.
Add padding field and make sure its zeroed before copy to user.
Upstream commit:
http://git.kernel.org/linus/13fcb7bd322164c67926ffe272846d4860196dc6
introduced by commit 393e52e33c6c2 (v2.6.27-rc1)
Discussion:
Statement:
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 and 5 as they did not backport the upstream commit 393e52e3 that introduced this flaw. This has been addressed in Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2012-0010.html.
---
This issue has been addressed in following
Unit42
Threat Brief: Microsoft DNS Server Wormable Vulnerability CVE-2020-1350
blogs_unit42·2020-07-21·CVSS 10.0
CVE-2020-1350 [CRITICAL] Threat Brief: Microsoft DNS Server Wormable Vulnerability CVE-2020-1350
## Executive Summary
In July 2020, Microsoft released a security update, CVE-2020-1350 | Windows DNS Server Remote Code Execution Vulnerability, for a new remote code execution (RCE) vulnerability.
This vulnerability exists within the Microsoft Windows Domain Name System (DNS) Server due to the improper handling of certain types of requests, specifically over port 53/TCP. Exploitation of this vulnerability is possible by creating an integer overflow, potentially leading to remote code execution.
This vulnerability only affects Windows DNS and the following builds of the Microsoft Windows operating system (OS):
- Windows Server 2008/2008 R2
- Windows Server 2012/2012 R2
- Windows Server 2016
- Windows Server 2019
- Windows Server version 1803/1903/1909/2004 (Server Core installation)
#
2012-08-06
Published