CVE-2010-3036

Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:cisco:ciscoworks_common_services:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_common_services:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_common_services:3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_common_services:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_common_services:3.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_common_services:3.3:*:*:*:*:*:*:*
OR cpe:2.3:a:cisco:ciscoworks_lan_management_solution:2.6:update:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.0:december_2007:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:ciscoworks_lan_management_solution:3.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:qos_policy_manager:4.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:qos_policy_manager:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:qos_policy_manager:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:security_manager:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:security_manager:3.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:telepresence_readiness_assessment_manager:1.0:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_operations_manager:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_operations_manager:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_operations_manager:2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:cisco:unified_service_monitor:2.0.1:*:*:*:*:*:*:*

History

21 Nov 2024, 01:17

Type Values Removed Values Added
References () http://osvdb.org/68927 - () http://osvdb.org/68927 -
References () http://secunia.com/advisories/42011 - Vendor Advisory () http://secunia.com/advisories/42011 - Vendor Advisory
References () http://securitytracker.com/id?1024646 - () http://securitytracker.com/id?1024646 -
References () http://www.cisco.com/en/US/products/products_security_advisory09186a0080b51501.shtml - Patch, Vendor Advisory () http://www.cisco.com/en/US/products/products_security_advisory09186a0080b51501.shtml - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/44468 - Patch () http://www.securityfocus.com/bid/44468 - Patch
References () http://www.vupen.com/english/advisories/2010/2793 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/2793 - Vendor Advisory

Information

Published : 2010-10-29 19:00

Updated : 2024-11-21 01:17


NVD link : CVE-2010-3036

Mitre link : CVE-2010-3036

CVE.ORG link : CVE-2010-3036


JSON object : View

Products Affected

cisco

  • ciscoworks_common_services
  • telepresence_readiness_assessment_manager
  • unified_service_monitor
  • unified_operations_manager
  • ciscoworks_lan_management_solution
  • qos_policy_manager
  • security_manager
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer