Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-0255

EPSS 49.26% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-0255

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft IE URLMON嗅探跨域信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Internet Explorer是Windows操作系统中默认捆绑的web浏览器。 在加载本地文件时Internet Explorer的HTML渲染引擎仅检查其MIME类型来判断是否匹配为可处理的文件。对于由于重新定向引用而处理为HTML的未知类型,如果内容源没有明确地设置类型,就会默认将其类型确定为text/html;对于没有明确设置内容类型的非html文件,URLMON会根据重新定向所示默认处理为text/html类型。因此,Internet Explorer会加载非html的本地文件并渲染为HTM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-0255

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0255

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-02-04 · 17 CVEs total

CVE-2010-0555Microsoft IE URLMON嗅探跨域信息泄露漏洞
CVE-2010-0548Xerox WorkCentre 多个产品Network控制器 和Web服务器 多个未明漏洞
CVE-2010-0549Xerox WorkCentre 6400 System Software和Net Controller Network控制器未明漏洞
CVE-2010-0550Geopp Geo++ GNCASTER 'admin.htm'HTTP Digest认证授权问题漏洞
CVE-2010-0551Geopp Geo++ GNCASTER HTTP认证信息泄露漏洞
CVE-2010-0552Geopp Geo++ GNCASTER URI拒绝服务攻击和任意代码执行漏洞
CVE-2010-0553Geopp Geo++ GNCASTER 拒绝服务攻击和任意代码执行漏洞
CVE-2010-0554Geopp Geo++ GNCASTER HTTP认证执行机制 绕过认证
CVE-2009-2750IBM WebSphere Service Registry and Repository 配置属性不充分安全漏洞
CVE-2009-4016IRCD-Hybrid和ircd-ratbox LINKS命令整数下溢漏洞
CVE-2010-0300ircd-ratbox HELP命令拒绝服务漏洞
CVE-2010-0301maildrop 'main.C' 权限提升漏洞
CVE-2010-0303Hybserv2 :help命令远程拒绝服务漏洞
CVE-2010-0441Asterisk T.38 FaxMaxDatagram字段远程拒绝服务漏洞
CVE-2010-0443HP OpenVMS 系统RMS服务器未明漏洞
CVE-2010-0547Samba “client/mount.cifs.c” 远程拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2010-0255

No comments yet


Leave a comment