Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-0425

Опубликовано: 05 мар. 2010
Источник: nvd
CVSS2: 10
EPSS Критический

Описание

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:z\/os:*:*
Версия от 6.1 (включая) до 6.1.0.31 (исключая)
Конфигурация 2

Одновременно

Одно из

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Версия от 2.0.37 (включая) до 2.0.64 (исключая)
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Версия от 2.2.0 (включая) до 2.2.15 (исключая)
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
Версия от 2.3.0 (включая) до 2.3.7 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

Одно из

cpe:2.3:a:ibm:http_server:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.19:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.23:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.29:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.31:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.33:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.35:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.0.2.39:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.17:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.19:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.23:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:http_server:6.1.0.29:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:a:oracle:http_server:10.1.3.5.0:*:*:*:*:*:*:*
Конфигурация 5
cpe:2.3:a:broadcom:vmware_ace_management_server:*:*:*:*:*:*:*:*
Версия до 2.7.2 (исключая)

EPSS

Процентиль: 100%
0.94248
Критический

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
больше 16 лет назад

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

debian
больше 16 лет назад

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server ...

github
больше 4 лет назад

modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

suse-cvrf
почти 9 лет назад

Security update for apache2

EPSS

Процентиль: 100%
0.94248
Критический

10 Critical

CVSS2

Дефекты

NVD-CWE-noinfo