CVE-2012-2010

Severity
6.9MEDIUM
EPSS
0.3%
top 51.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 18
Latest updateMay 17

Description

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages1 packages

NVDhp/openvms8.3, 8.3-1h1, 8.4+2

🔴Vulnerability Details

3
GHSA
GHSA-22fp-492m-4h47: The ACMELOGIN implementation in HP OpenVMS 82022-05-17
GHSA
Cross-site scripting in yui 2.4.02022-05-17
CVEList
CVE-2012-2010: The ACMELOGIN implementation in HP OpenVMS 82012-05-18

💥Exploits & PoCs

10
Exploit-DB
Microsoft Excel - OLE Arbitrary Code Execution2017-09-30
Exploit-DB
Zimbra 2009-2013 - Local File Inclusion2013-12-06
Exploit-DB
Apple iOS 7.0.2 - Sim Lock Screen Display Bypass2013-10-15
Exploit-DB
Konqueror 4.7.3 - Memory Corruption2012-11-01
Exploit-DB
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)2012-10-09

📋Vendor Advisories

1
Red Hat
mysql: over-sized packet denial of service vulnerability2010-05-13

🕵️Threat Intelligence

6
Trendmicro
Backdoor-Variante infiziert Word-Dokumente und PDFs2019-08-26
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities2019-08-22

💬Community

5
Bugzilla
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:01032012-04-20
Bugzilla
CVE-2010-5077 quake3: DDoS via getstatus and rcon requests2012-03-26
Bugzilla
CVE-2012-0789 php: strtotime timezone memory leak2012-01-21
Bugzilla
CVE-2010-3843 ettercap: insecure global settings file [epel-4]2011-05-31
Bugzilla
CVE-2010-2642 evince, t1lib: Heap based buffer overflow in DVI file AFM font parser [epel-5]2011-02-21
CVE-2012-2010 (MEDIUM CVSS 6.9) | The ACMELOGIN implementation in HP | cvebase.io