3 results (0.002 seconds)

CVSS: 9.8EPSS: 1%CPEs: 9EXPL: 0

Multiple buffer overflows in mDNSResponder before 625.41.2 allow remote attackers to read or write to out-of-bounds memory locations via vectors involving the (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import, or (4) CopyNSEC3ResourceRecord function. Múltiples desbordamientos de buffer en mDNSResponder en versiones anteriores a 625.41.2 permiten a atacantes remotos leer o escribir en posiciones de memoria fuera de los límites a través de vectores implicando la función (1) GetValueForIPv4Addr, (2) GetValueForMACAddr, (3) rfc3110_import o (4) CopyNSEC3ResourceRecord. • http://www.kb.cert.org/vuls/id/143335 http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html http://www.securityfocus.com/bid/91323 http://www.securitytracker.com/id/1036181 https://support.apple.com/HT206846 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.8EPSS: 1%CPEs: 9EXPL: 0

The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors. La función handle_regservice_request en mDNSResponder en versiones anteriores a 625.41.2 permite a atacantes remotos ejecutar código arbitrario o provocar una denegación de servicio (referencia a puntero NULL) a través de vectores no especificados. • http://www.kb.cert.org/vuls/id/143335 http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html http://www.securitytracker.com/id/1036181 https://support.apple.com/HT206846 •

CVSS: 5.0EPSS: 1%CPEs: 3EXPL: 3

The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate _presence._tcp mDNS queries. La funcionalidad Bonjour en el mDNSResponder, iChat 3.1.6 y InstantMessage framework 428 en el Apple Mac OS X 10.4.8 no chequea entradas duplicadas cuando se añaden contactos disponibles recién descubiertos, lo que permite a atacantes remotos provocar una denegación de servicio (interrumpir la comunicación) mediante una avalancha de consultas duplicate _presence._tcp mDNS. • https://www.exploit-db.com/exploits/3230 http://projects.info-pull.com/moab/MOAB-29-01-2007.html http://www.osvdb.org/32698 http://www.osvdb.org/32699 http://www.securityfocus.com/bid/22304 •