CVE-2019-2006
published 2019-06-19CVE-2019-2006: In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in…
PriorityP344critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
0.72%
49.6th percentile
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-116665972
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
php: link function accepts filenames with embedded null byte and treats them as terminating at that byte on Windows
vendor_redhat·2019-11-23·CVSS 5.0
CVE-2019-11044 [MEDIUM] CWE-170 php: link function accepts filenames with embedded null byte and treats them as terminating at that byte on Windows
php: link function accepts filenames with embedded null byte and treats them as terminating at that byte on Windows
In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
A flaw was discovered in the link function in PHP. When compiled on Windows, it does not correctly handle paths containing NULL bytes. An attacker could abuse this flaw to bypass application checks on file paths.
Statement: This issue did not affect the versions of php as shipped with Red Hat Enterprise Linux 5, 6, 7, and 8 as the flaw only affects Windows builds. See CVE-2006-72
Red Hat
axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
vendor_redhat·2019-04-09·CVSS 7.5
CVE-2019-0227 [HIGH] CWE-547 axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Package: axis (Red Hat Enterprise Linux 5) - Will not fix
Package: axis (Red Hat Enterprise Linux 6) - Will not fix
Android
CVE-2019-2006: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2006
Severity: HIGH
Type: EoP
Affected AOSP versions: 9
References: A-116665972
vendor_android·2019-03-01·CVSS 9.8
CVE-2019-2006 [CRITICAL] CVE-2019-2006: Android Security Bulletin 2019-03-01
CVE: CVE-2019-2006
Severity: HIGH
Type: EoP
Affected AOSP versions: 9
References: A-116665972
Android Security Bulletin 2019-03-01
CVE: CVE-2019-2006
Severity: HIGH
Type: EoP
Affected AOSP versions: 9
References: A-116665972
GHSA
GHSA-pj99-xr7h-24mx: In serviceDied of HalDeathHandlerHidl
ghsa_unreviewed·2022-05-24
CVE-2019-2006 [CRITICAL] CWE-416 GHSA-pj99-xr7h-24mx: In serviceDied of HalDeathHandlerHidl
In serviceDied of HalDeathHandlerHidl.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege in the audio server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9Android ID: A-116665972
GHSA
Server Side Request Forgery in Apache Axis
ghsa·2019-05-14
CVE-2019-0227 [HIGH] CWE-918 Server Side Request Forgery in Apache Axis
Server Side Request Forgery in Apache Axis
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Suricata
ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Inbound)
suricata·2019-12-16
CVE-2006-4000 ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Inbound)
ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Inbound)
Rule: alert http $EXTERNAL_NET any -> any any (msg:"ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Inbound)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/preview_email.cgi?file=/mail/mlog/|7c|"; startswith; fast_pattern; content:"http"; distance:0; reference:url,unit42.paloaltonetworks.com/mirai-variant-echobot-resurfaces-with-13-previously-unexploited-vulnerabilities/; reference:cve,2006-4000; classtype:attempted-admin; sid:2029173; rev:3; metadata:affected_product Linux, attack_target IoT, created_at 2019_12_16, cve CVE_2006_4000, deployment Perimeter, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_13;)
Suricata
ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Outbound)
suricata·2019-12-16
CVE-2006-4000 ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Outbound)
ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Outbound)
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT Barracuda Spam Firewall 3.3.x RCE 2006-4000 (Outbound)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/preview_email.cgi?file=/mail/mlog/|7c|"; startswith; fast_pattern; content:"http"; distance:0; reference:url,unit42.paloaltonetworks.com/mirai-variant-echobot-resurfaces-with-13-previously-unexploited-vulnerabilities/; reference:cve,2006-4000; classtype:attempted-admin; sid:2029172; rev:3; metadata:affected_product Linux, attack_target IoT, created_at 2019_12_16, cve CVE_2006_4000, deployment Perimeter, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_04_13;)
Suricata
GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt
suricata·2010-09-23
CVE-2006-0189 GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt
GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 5060 (msg:"GPL VOIP EXPLOIT SIP UDP Softphone overflow attempt"; content:"|3B|branch|3D|"; content:"a|3D|"; pcre:"/^a\x3D[^\n]{1000,}/smi"; reference:bugtraq,16213; reference:cve,2006-0189; classtype:misc-attack; sid:2100223; rev:2; metadata:created_at 2010_09_23, cve CVE_2006_0189, confidence Medium, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_07_26;)
Suricata
GPL SNMP SNMP trap Format String detected
suricata·2010-09-23
CVE-2006-0250 GPL SNMP SNMP trap Format String detected
GPL SNMP SNMP trap Format String detected
Rule: alert udp $EXTERNAL_NET any -> $HOME_NET 162 (msg:"GPL SNMP SNMP trap Format String detected"; content:"%s"; fast_pattern; reference:bugtraq,16267; reference:cve,2006-0250; reference:url,www.osvdb.org/displayvuln.php?osvdb_id=22493; classtype:attempted-recon; sid:2100227; rev:5; metadata:created_at 2010_09_23, cve CVE_2006_0250, signature_severity Informational, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2019_10_08;)
Exploit-DB
Netartmedia PHP Mall 4.1 - SQL Injection
exploitdb·2019-03-19
Netartmedia PHP Mall 4.1 - SQL Injection
Netartmedia PHP Mall 4.1 - SQL Injection
---
# Exploit Title: Netartmedia PHP Mall 4.1 - Multiple SQL Injection
# Date: 19.03.2019
# Exploit Author: Ahmet Ümit BAYRAM
# Vendor Homepage: https://www.netartmedia.net/mall/
# Demo Site: https://www.phpscriptdemos.com/mall/
# Version: 4.1
# Tested on: Kali Linux
# CVE: N/A
# Description: PHP Mall is one of the first multi-stores and multi-vendors
php scripts (offered since 2006) and successfully used on many websites
today.
----- PoC 1 : SQLi (time-based blind) -----
# Request: http://localhost/[PATH]/index.php
# Parameter: id (GET)
# Payload: id=1 AND SLEEP(5)&item=&lang=en&mod=details
----- PoC 2 : SQLi (time-based blind) ----
# Request: http://localhost/[PATH]/loginaction.php
# Parameter: Email (POST)
# Payload: Email=0'XOR(if(now()=sysd
Exploit-DB
Apple Mac OSX Safari 2.0.3 (417.9.2) - 'ROWSPAN' Denial of Service (PoC)
exploitdb·2006-04-24
CVE-2006-2019 Apple Mac OSX Safari 2.0.3 (417.9.2) - 'ROWSPAN' Denial of Service (PoC)
Apple Mac OSX Safari 2.0.3 (417.9.2) - 'ROWSPAN' Denial of Service (PoC)
---
# milw0rm.com [2006-04-24]
No writeups or analysis indexed.
2019-06-19
Published