CVE-2013-1029
published 2013-09-16CVE-2013-1029: The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect…
PriorityP417medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.53%
42.0th percentile
The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect, extraneous code in the IGMP parser.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.8.4 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-6092 activemq: Multiple XSS flaws in web demos
bugzilla·2013-04-24·CVSS 4.3
CVE-2012-6092 [MEDIUM] CVE-2012-6092 activemq: Multiple XSS flaws in web demos
CVE-2012-6092 activemq: Multiple XSS flaws in web demos
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublish or Market Data Publisher), or vectors involving (2) debug logs or (3) subscribe messages in webapp/websocket/chat.js. NOTE: AMQ-4124 is covered by CVE-2012-6551.
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6092
Discussion:
This issue has been addressed in following products:
Fuse MQ Enterprise 7.1.0
Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
Bugzilla
CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp
bugzilla·2013-04-24·CVSS 5.0
CVE-2012-6551 [MEDIUM] CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp
CVE-2012-6551 activemq: DoS by resource consumption via HTTP requests to sample webapp
The default configuration of Apache ActiveMQ before 5.8.0 enables a sample web application, which allows remote attackers to cause a denial of service (broker resource consumption) via HTTP requests.
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6551
Discussion:
This issue has been addressed in following products:
Fuse MQ Enterprise 7.1.0
Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
Bugzilla
CVE-2013-1879 ActiveMQ: XSS vulnerability in scheduled.jsp
bugzilla·2013-03-21·CVSS 4.3
CVE-2013-1879 [MEDIUM] CVE-2013-1879 ActiveMQ: XSS vulnerability in scheduled.jsp
CVE-2013-1879 ActiveMQ: XSS vulnerability in scheduled.jsp
Dejan Bosanac reports:
If a string such as:
* * * * *alert(1)
is entered into cron of a message, JS code will be executed on the scheduled.jsp page.
External references:
https://issues.apache.org/jira/browse/AMQ-4397
Discussion:
Created activemq tracking bugs for this issue
Affects: fedora-18 [bug 924448]
---
This issue has been addressed in following products:
Fuse MQ Enterprise 7.1.0
Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
Bugzilla
CVE-2013-1880 ActiveMQ: XSS vulnerability in portfolioPublish demo application
bugzilla·2013-03-21·CVSS 4.3
CVE-2013-1880 [MEDIUM] CVE-2013-1880 ActiveMQ: XSS vulnerability in portfolioPublish demo application
CVE-2013-1880 ActiveMQ: XSS vulnerability in portfolioPublish demo application
Portfolio publisher servlet doesn't sanitize input. For example he following url in Firefox
http://localhost:8161/demo/portfolioPublish?count=1&refresh=%27%3E%3Cscript%3Ealert%28%27XSS%27%29;%3C/script%3E&stocks=IBMW&stocks=BEAS&stocks=MSFT&stocks=SUNW
will trigger JS code.
External references:
https://issues.apache.org/jira/browse/AMQ-4398
Discussion:
Created activemq tracking bugs for this issue
Affects: fedora-18 [bug 924448]
---
This issue has been addressed in following products:
Fuse MQ Enterprise 7.1.0
Via RHSA-2013:1029 https://rhn.redhat.com/errata/RHSA-2013-1029.html
2013-09-16
Published