CVE-2018-0122
published 2018-02-08CVE-2018-0122: A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local…
PriorityP423medium4.4CVSS 3.1
AVLACLPRHUINSUCNIHAN
EPSS
0.38%
29.7th percentile
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the attacker would need to authenticate to an affected system by using valid administrator credentials. Cisco Bug IDs: CSCvf93335.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | staros | — | — |
| cisco | staros_for_cisco_asr_5000_series_aggregation_services_routers_file_overwrite | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv2.06.6MEDIUMAV:L/AC:L/Au:N/C:N/I:C/A:C
vendor_cisco4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrq7-hq3r-99cx: A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, l
ghsa_unreviewed·2022-05-13
CVE-2018-0122 [MEDIUM] CWE-78 GHSA-vrq7-hq3r-99cx: A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, l
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the attacker would need to authenticate to an affected system by using valid administrator credentials. Cisco Bug IDs:
Cisco
Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
vendor_cisco·2018-02-08·CVSS 4.4
CVE-2018-0122 [MEDIUM] CWE-20 Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system.
The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the attacker would
Cisco
Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
vendor_cisco·CVSS 3.0
CVE-2018-0122 Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
CVE-2018-0122: Cisco StarOS for Cisco ASR 5000 Series Aggregation Services Routers File Overwrite Vulnerability
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the at
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-5098 Mozilla: Use-after-free while manipulating form input elements (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5098 [CRITICAL] CVE-2018-5098 Mozilla: Use-after-free while manipulating form input elements (MFSA 2018-03)
CVE-2018-5098 Mozilla: Use-after-free while manipulating form input elements (MFSA 2018-03)
A use-after-free vulnerability can occur when manipulating form input elements, focus, and selections through script. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5098
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:
Bugzilla
CVE-2018-5104 Mozilla: Use-after-free during font face manipulation (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5104 [CRITICAL] CVE-2018-5104 Mozilla: Use-after-free during font face manipulation (MFSA 2018-03)
CVE-2018-5104 Mozilla: Use-after-free during font face manipulation (MFSA 2018-03)
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5104
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5099 Mozilla: Use-after-free with widget listener (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5099 [CRITICAL] CVE-2018-5099 Mozilla: Use-after-free with widget listener (MFSA 2018-03)
CVE-2018-5099 Mozilla: Use-after-free with widget listener (MFSA 2018-03)
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5099
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 http
Bugzilla
CVE-2018-5117 Mozilla: URL spoofing with right-to-left text aligned left-to-right (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 5.3
CVE-2018-5117 [MEDIUM] CVE-2018-5117 Mozilla: URL spoofing with right-to-left text aligned left-to-right (MFSA 2018-03)
CVE-2018-5117 Mozilla: URL spoofing with right-to-left text aligned left-to-right (MFSA 2018-03)
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5117
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Xisigr
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has
Bugzilla
CVE-2018-5103 Mozilla: Use-after-free during mouse event handling (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5103 [CRITICAL] CVE-2018-5103 Mozilla: Use-after-free during mouse event handling (MFSA 2018-03)
CVE-2018-5103 Mozilla: Use-after-free during mouse event handling (MFSA 2018-03)
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5103
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5097 Mozilla: Use-after-free when source document is manipulated during XSLT (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5097 [CRITICAL] CVE-2018-5097 Mozilla: Use-after-free when source document is manipulated during XSLT (MFSA 2018-03)
CVE-2018-5097 Mozilla: Use-after-free when source document is manipulated during XSLT (MFSA 2018-03)
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5097
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linu
Bugzilla
CVE-2018-5096 Mozilla: Use-after-free while editing form elements (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5096 [CRITICAL] CVE-2018-5096 Mozilla: Use-after-free while editing form elements (MFSA 2018-03)
CVE-2018-5096 Mozilla: Use-after-free while editing form elements (MFSA 2018-03)
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5096
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5091 Mozilla: Use-after-free with DTMF timers (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5091 [CRITICAL] CVE-2018-5091 Mozilla: Use-after-free with DTMF timers (MFSA 2018-03)
CVE-2018-5091 Mozilla: Use-after-free with DTMF timers (MFSA 2018-03)
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5091
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Looben Yang
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
Bugzilla
CVE-2018-5102 Mozilla: Use-after-free in HTML media elements (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5102 [CRITICAL] CVE-2018-5102 Mozilla: Use-after-free in HTML media elements (MFSA 2018-03)
CVE-2018-5102 Mozilla: Use-after-free in HTML media elements (MFSA 2018-03)
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5102
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Nils
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat Enterprise Linux 7
Via RHSA-2018:0262 https://access.redhat.com/errata/RHSA-2018:0262
Bugzilla
CVE-2018-5095 Mozilla: Integer overflow in Skia library during edge builder allocation (MFSA 2018-03)
bugzilla·2018-01-23·CVSS 9.8
CVE-2018-5095 [CRITICAL] CVE-2018-5095 Mozilla: Integer overflow in Skia library during edge builder allocation (MFSA 2018-03)
CVE-2018-5095 Mozilla: Integer overflow in Skia library during edge builder allocation (MFSA 2018-03)
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-03/#CVE-2018-5095
Discussion:
Acknowledgments:
Name: the Mozilla project
Upstream: Anonymous
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 6
Via RHSA-2018:0122 https://access.redhat.com/errata/RHSA-2018:0122
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Red Hat E
http://www.securityfocus.com/bid/103028http://www.securitytracker.com/id/1040340https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-asrhttp://www.securityfocus.com/bid/103028http://www.securitytracker.com/id/1040340https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180207-asr
2018-02-08
Published