CVE-2012-2010
published 2012-05-18CVE-2012-2010: The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.39%
31.3th percentile
The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | openvms | — | — |
| hp | openvms | — | — |
| hp | openvms | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
ghsa4.3MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-22fp-492m-4h47: The ACMELOGIN implementation in HP OpenVMS 8
ghsa_unreviewed·2022-05-17
CVE-2012-2010 [MEDIUM] GHSA-22fp-492m-4h47: The ACMELOGIN implementation in HP OpenVMS 8
The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM system service is enabled, allows local users to gain privileges via unspecified vectors.
GHSA
Cross-site scripting in yui 2.4.0
ghsa·2022-05-17·CVSS 4.3
CVE-2012-5881 [MEDIUM] CWE-79 Cross-site scripting in yui 2.4.0
Cross-site scripting in yui 2.4.0
Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.4.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to charts.swf, a similar issue to CVE-2010-4207.
Red Hat
mysql: over-sized packet denial of service vulnerability
vendor_redhat·2010-05-13·CVSS 5.0
CVE-2010-1849 [MEDIUM] mysql: over-sized packet denial of service vulnerability
mysql: over-sized packet denial of service vulnerability
The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.
Statement: This issue was fixed in mysql packages shipped with Red Hat Enterprise Linux 5 via RHSA-2012:0127. The mysql packages in Red Hat Enterprise Linux 6 include this fix since the initial release of the product.
Package: mysql (Red Hat Enterprise Linux 4) - Will not fix
Package: mysql (Red Hat Enterprise Linux 6) - Affected
No detection rules found.
Exploit-DB
Microsoft Excel - OLE Arbitrary Code Execution
exploitdb·2017-09-30
CVE-2017-0199 Microsoft Excel - OLE Arbitrary Code Execution
Microsoft Excel - OLE Arbitrary Code Execution
---
Title: MS Office Excel (all versions) Arbitrary Code Execution Vulnerability
Date: September 30th, 2017.
Author: Eduardo Braun Prado
Vendor Homepage: http://www.microsoft.com/
Software Link: https://products.office.com/
Version: 2007,2010,2013,2016 32/64 bits (x86 and x64)
Tested on: Windows 10/8.1/8.0/7/Server 2012/Server 2008/Vista (X86 and x64)
CVE: 2017-0199
Description:
MS Excel contains a remote code execution vulnerability upon processing OLE objects. Although this is a different issue from the
MS Word HTA execution vulnerability, it has been patched together, 'silently'. By performing some tests from the Word HTA PoC posted
on exploit-db[dot]com, it´s possible to exploit it through Excel too, however the target would ne
Exploit-DB
Zimbra 2009-2013 - Local File Inclusion
exploitdb·2013-12-06
CVE-2013-7091 Zimbra 2009-2013 - Local File Inclusion
Zimbra 2009-2013 - Local File Inclusion
---
# Exploit Title: Zimbra 0day exploit / Privilegie escalation via LFI
# Date: 06 Dec 2013
# Exploit Author: rubina119
# Contact Email : rubina119[at]gmail.com
# Vendor Homepage: http://www.zimbra.com/
# Version: 2009, 2010, 2011, 2012 and early 2013 versions are afected,
# Tested on: Centos(x), Ubuntu.
# CVE : No CVE, no patch just 0Day
# State : Critical
# Exploit-DB Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30085.zip (zimbraexploit_rubina119.zip)
---------------Description-----------------
This script exploits a Local File Inclusion in
/res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz
which allows us to see localconfig.xml
that contains LDAP root credentials wich allo
Exploit-DB
Apple iOS 7.0.2 - Sim Lock Screen Display Bypass
exploitdb·2013-10-15
CVE-2013-5147 Apple iOS 7.0.2 - Sim Lock Screen Display Bypass
Apple iOS 7.0.2 - Sim Lock Screen Display Bypass
---
Document Title:
Apple iOS 7.2 - Sim Lock Screen Display Bypass Vulnerability
References (Source):
http://www.vulnerability-lab.com/get_content.php?id=1105
Video: http://www.vulnerability-lab.com/get_content.php?id=1104
Release Date:
2013-10-04
Vulnerability Laboratory ID (VL-ID):
1105
Common Vulnerability Scoring System:
6.1
Product & Service Introduction:
iOS (previously iPhone OS) is a mobile operating system developed and distributed by Apple Inc. Originally unveiled in 2007
for the iPhone, it has been extended to support other Apple devices such as the iPod Touch (September 2007), iPad (January 2010),
iPad Mini (November 2012) and second-generation Apple TV (September 2010). Unlike Microsoft`s Windows Phone and Google`s
Exploit-DB
Konqueror 4.7.3 - Memory Corruption
exploitdb·2012-11-01·CVSS 9.3
CVE-2012-4515 [CRITICAL] Konqueror 4.7.3 - Memory Corruption
Konqueror 4.7.3 - Memory Corruption
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Nth Dimension Security Advisory (NDSA20121010)
Date: 10th October 2012
Author: Tim Brown
URL: /
Product: Konqueror 4.7.3
Vendor: KDE
Risk: Medium
Summary
The Konqueror web browser is vulnerable to a number of memory corruption
vulnerabilities.
This advisory comes in 4 related parts:
1) The Konqueror web browser is vulnerable to type confusion leading to memory
disclosure. The root cause of this is the same as CVE-2010-0046 reported by
Chris Rohlf which affected WebKit.
2) The Konqueror web browser is vulnerable to an out of bounds memory access
when accessing the canvas. In this case the vulnerability was identified whilst
playing with bug #43813 from Google's Chrome repository.
3) The Konquero
Exploit-DB
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
exploitdb·2012-10-09
CVE-2010-0188 Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
Apple iOS Mobile Mail - LibTIFF Buffer Overflow (Metasploit)
---
##
# $Id: mobilemail_libtiff.rb 15950 2012-10-09 18:31:08Z rapid7 $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
class Metasploit3 'Apple iOS MobileMail LibTIFF Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow in the version of
libtiff shipped with firmware versions 1.00, 1.01, 1.02, and
1.1.1 of the Apple iPhone. iPhones which have not had the BSD
tools installed will need to use a special payload.
},
'License' => MSF_LICENSE,
'Author' => ['hdm', 'kf'],
'Version' => '$Revision: 1595
Exploit-DB
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
exploitdb·2012-10-09
CVE-2010-0188 Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
Apple iOS Mobile Safari - LibTIFF Buffer Overflow (Metasploit)
---
##
# $Id: safari_libtiff.rb 15950 2012-10-09 18:31:08Z rapid7 $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# web site for more information on licensing and terms of use.
# http://metasploit.com/
##
require 'msf/core'
class Metasploit3 'Apple iOS MobileSafari LibTIFF Buffer Overflow',
'Description' => %q{
This module exploits a buffer overflow in the version of
libtiff shipped with firmware versions 1.00, 1.01, 1.02, and
1.1.1 of the Apple iPhone. iPhones which have not had the BSD
tools installed will need to use a special payload.
},
'License' => MSF_LICENSE,
'Author' => ['hdm', 'kf'],
'Version' => '$Revision: 1595
Exploit-DB
Joomla! Component RokModule 1.1 - 'module' Blind SQL Injection
exploitdb·2012-09-10
CVE-2010-1480 Joomla! Component RokModule 1.1 - 'module' Blind SQL Injection
Joomla! Component RokModule 1.1 - 'module' Blind SQL Injection
---
Titulo: Joomla Component RokModule Blind SQLi [module] Vulnerability
Nombre del Componente: Com_rokmodule
Empresa: http://www.rockettheme.com/
Testeado: Linux Backtrack
Autor: Yarolinux Para WebSecurityDev
Twitter: @Yarolinux
Fecha: 09/09/2012
Bueno la Injeccion Va de la siguiente manera:
http://localhost/index.php?option=com_rokmodule&tmpl=component&type=raw&module=[sqli]
http://localhost/web/index.php?option=com_rokmodule&tmpl=component&type=raw&module=[sqli]or[BlindSQLi]
Ok! Eso es todo Difrutenlo!
Estamos trabajando en un laboratorio testeandolo en Joomla 1.7, Muy
pronto resultados :D
Greetz: Dylan Irzi & WebSecurityDev
Exploit-DB
Reserve Logic 1.2 Booking CMS - Multiple Vulnerabilities
exploitdb·2012-07-12
CVE-2010-4980 Reserve Logic 1.2 Booking CMS - Multiple Vulnerabilities
Reserve Logic 1.2 Booking CMS - Multiple Vulnerabilities
---
Title:
Reserve Logic v1.2 Booking CMS - Multiple Vulnerabilities
Date:
2012-06-18
References:
http://www.vulnerability-lab.com/get_content.php?id=617
VL-ID:
617
Common Vulnerability Scoring System:
8.5
Introduction:
iScripts ReserveLogic offers an online web based reservation system for the hospitality industry for service providers.
This turn-key reservation system allows you to start online reservation and customer management in minutes.
Flexible Reservation Software. iScripts ReserveLogic is designed to simplify the task of online booking. It provides
users a unique, intuitive and easy to use interface that improves the way people use the web today. Through personalization
and rich features, iScripts ReserveLogic e
Exploit-DB
Artiphp CMS 5.5.0 - Database Backup Disclosure
exploitdb·2012-05-16
CVE-2012-2905 Artiphp CMS 5.5.0 - Database Backup Disclosure
Artiphp CMS 5.5.0 - Database Backup Disclosure
---
\n\n\n";
die();
}
$godina_array = array('2012','2011','2010');
$mesec_array = array('12','11','10','09',
'08','07','06','05',
'04','03','02','01');
$dn_array = array('31','30','29','28','27','26',
'25','24','23','22','21','20',
'19','18','17','16','15','14',
'13','12','11','10','09','08',
'07','06','05','04','03','02',
'01');
$backup_array = array('full','structure','partial');
$host = $argv[1];
$port = intval($argv[2]);
$path = "/artiphp/artzone/artpublic/database/"; // change per need.
$alert1 = "\033[0;31m";
$alert2 = "\033[0;37m";
foreach($godina_array as $godina)
{
print "\n\n\x20[*] Checking year: ".$godina."\n\n Scanning: ";
sleep(2);
foreach($mesec_array as $mesec)
{
foreach($dn_array as $dn)
{
print "~";
foreach($backup_a
Exploit-DB
FlatnuX CMS - Traversal Arbitrary File Access
exploitdb·2012-04-01
CVE-2012-4878 FlatnuX CMS - Traversal Arbitrary File Access
FlatnuX CMS - Traversal Arbitrary File Access
---
source: https://www.securityfocus.com/bid/52846/info
Flatnux is prone to multiple security vulnerabilities:
1. An HTML-injection vulnerability
2. A cross-site request-forgery vulnerability
3. A directory-traversal vulnerability
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, obtain sensitive information, or control how the site is rendered to the user. Other attacks are also possible.
The following versions are vulnerable:
Flatnux 2011-08.09.2
Flatnux 2011-2012-01.03.3
Flatnux 2011-minimal-2012-01.03.3
Fncommerce 2010-08-09-no-db
Fncommerce 2010-08-09-no-sample-data
Fncommerce 2010-0
Trendmicro
Backdoor-Variante infiziert Word-Dokumente und PDFs
blogs_trendmicro·2019-08-26·CVSS 7.3
[HIGH] Backdoor-Variante infiziert Word-Dokumente und PDFs
Malware
## Backdoor-Variante infiziert Word-Dokumente und PDFs
Sicherheitsforscher stießen auf Asruex in einer PDF-Datei und stellten fest, dass eine Variante der Malware auch als Infector fungieren kann, insbesondere durch die Ausnutzung alter Schwachstellen.
By: Trend Micro Aug 26, 2019 Read time: ( words)
Save to Folio
Originalbeitrag von Ian Mercado and Mhica Romero
Asruex wurde 2015 zum ersten Mal gesichtet und ist bekannt für seine Backdoor-Funktionen und die Verbindung zur Spyware DarkHotel. Nun stießen die Sicherheitsforscher auf Asruex in einer PDF-Datei und stellten fest, dass eine Variante der Malware auch als Infector fungieren kann, insbesondere durch die Ausnutzung alter Schwachstellen wie CVE-2012-0158 und CVE-2010-2883, die Code in Word- bzw. PDF-Dateien injizieren.
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Ciberamenazas
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyber Threats
# Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero
Aug 22, 2019
Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883, which inject code in Word and PDF files respectively. The use of old, patched vulnerabilities c
Trendmicro
Asruex Backdoor Infects Files Via Old Vulnerabilities
blogs_trendmicro·2019-08-22·CVSS 7.3
[HIGH] Asruex Backdoor Infects Files Via Old Vulnerabilities
Cyberbedrohungen
## Asruex Backdoor Infects Files Via Old Vulnerabilities
Asruex has been known for its backdoor capabilities. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities.
By: Ian Mercado, Mhica Romero Aug 22, 2019 Read time: ( words)
Save to Folio
Since it first emerged in 2015, Asruex has been known for its backdoor capabilities and connection to the spyware DarkHotel. However, when we encountered Asruex in a PDF file, we found that a variant of the malware can also act as an infector particularly through the use of old vulnerabilities CVE-2012-0158 and CVE-2010-2883 , which inject code in Word and PDF files respectively. The use of old, patched vulnerabiliti
Talos
Phishing Games
blogs_talos·2012-07-30·CVSS 7.8
CVE-2010-3333 [HIGH] Phishing Games
It's no surprise that, as the 2012 London Olympic games approach, cybercriminals are using the event as bait for a variety of scams. Sure, there are plenty of 419 scams revolving around the games - but we'll assume that none of the readers of this blog are dumb enough to fall an online lottery scam or the like. I'll focus today on a pair of different phish we've seen with more dirty tricks - one with an attached RTF file exploiting CVE-2010-3333, and one with a fairly standard link off to an exploit kit.
The email with the attached RTF has come in from several different sources, and all of them were classic "please read the attached file to do the thing we think you're interested in" sorts of phish. For those foolish enough to be opening random documents from strangers out of their email,
Bugzilla
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
bugzilla·2012-04-20·CVSS 5.0
CVE-2012-2124 [MEDIUM] CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
CVE-2012-2124 squirrelmail: CVE-2010-2813 not fixed in RHSA-2012:0103
A Red Hat Security Advisory RHSA-2012:0103 for squirrelmail packages shipped in Red Hat Enterprise Linux 4 and 5 claim to have fixed CVE-2010-2813 issue ("CVE-2010-2813 SquirrelMail: DoS (disk space consumption) by random IMAP login attempts with 8-bit characters in the password", bug #618096). However, the patch for this issue was not applied correctly and hence the issue was not fixed as stated in the advisory.
Discussion:
CVE assignment notification:
http://www.openwall.com/lists/oss-security/2012/04/20/22
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2013:0126 https://rhn.redhat.com/errata/RHSA-2013-0126.html
Bugzilla
CVE-2010-5077 quake3: DDoS via getstatus and rcon requests
bugzilla·2012-03-26·CVSS 7.8
CVE-2010-5077 [HIGH] CVE-2010-5077 quake3: DDoS via getstatus and rcon requests
CVE-2010-5077 quake3: DDoS via getstatus and rcon requests
A distributed denial of service flaw was found in the way Quake3 Arena / OpenArena servers used to handle 'getstatus' and 'rcon' (remote command) connectionless requests. A remote attacker could use this flaw to perform distributed denial of service attack against the target server IP gameserver by spoofing certain packets.
References:
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=665656
[2] http://openarena.ws/board/index.php?topic=4391.0
[3] http://www.ioquake.org/forums/viewtopic.php?f=12&t=1694
[4] http://www.urbanterror.info/forums/topic/27825-drdos/
[5] http://lists.ioquake.org/pipermail/ioquake3-ioquake.org/2012-January/004778.html
Relevant upstream patch:
[6] http://icculus.org/pipermail/quake3-commits/2010-Januar
Bugzilla
CVE-2012-0789 php: strtotime timezone memory leak
bugzilla·2012-01-21·CVSS 5.0
CVE-2012-0789 [MEDIUM] CVE-2012-0789 php: strtotime timezone memory leak
CVE-2012-0789 php: strtotime timezone memory leak
https://bugs.php.net/bug.php?id=53502
[2010-12-08 21:04 UTC] jsheridan at tenable dot com
Description:
strtotime calls with a timezone embedded function correctly but continually use up
memory. In a daemon program this becomes quickly fatal.
Test script:
Expected result:
Memory usage should remain stable.
Discussion:
Duping against bug 169857.
*** This bug has been marked as a duplicate of bug 169857 ***
---
Statement:
(none)
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2012:1047 https://rhn.redhat.com/errata/RHSA-2012-1047.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2012:1046 https://rhn.redhat.com/errata/RHSA-2012-104
Bugzilla
CVE-2010-2642 evince, t1lib: Heap based buffer overflow in DVI file AFM font parser [epel-5]
bugzilla·2011-02-21·CVSS 7.6
CVE-2010-2642 [HIGH] CVE-2010-2642 evince, t1lib: Heap based buffer overflow in DVI file AFM font parser [epel-5]
CVE-2010-2642 evince, t1lib: Heap based buffer overflow in DVI file AFM font parser [epel-5]
epel-5 tracking bug for t1lib: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
t1lib-5.1.1-9.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/FEDORA-EPEL-2012-0069/t1lib-5.1.1-9.el5
---
t1lib-5.1.1-9.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
http://osvdb.org/82015http://www.securityfocus.com/bid/53613http://www.securitytracker.com/id?1027074https://exchange.xforce.ibmcloud.com/vulnerabilities/75729https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03333494http://osvdb.org/82015http://www.securityfocus.com/bid/53613http://www.securitytracker.com/id?1027074https://exchange.xforce.ibmcloud.com/vulnerabilities/75729https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03333494
2012-05-18
Published