U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2010-3332

Change History

Modified Analysis by NIST 11/23/2020 2:50:12 PM

Action Type Old Value New Value
Changed CPE Configuration
AND
     OR
          *cpe:2.3:a:microsoft:.net_framework:1.0:sp3:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:3.5:*:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:4.0:*:*:*:*:*:*:*
     OR
          cpe:2.3:a:microsoft:iis:*:*:*:*:*:*:*:*
AND
     OR
          *cpe:2.3:a:microsoft:.net_framework:1.1:sp1:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:2.0:sp1:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:2.0:sp2:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:3.5:-:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:3.5:sp1:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:3.5.1:*:*:*:*:*:*:*
          *cpe:2.3:a:microsoft:.net_framework:4.0:-:*:*:*:*:*:*
     OR
          cpe:2.3:a:microsoft:internet_information_services:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:L/Au:N/C:P/I:P/A:N)
Removed CVSS V2
NIST (AV:N/AC:L/Au:N/C:P/I:N/A:N)

								
						
Added CWE

								
							
							
						
NIST CWE-209
Removed CWE
NIST CWE-310

								
						
Changed Reference Type
http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx No Types Assigned
http://blogs.technet.com/b/srd/archive/2010/09/17/understanding-the-asp-net-vulnerability.aspx Vendor Advisory
Changed Reference Type
http://isc.sans.edu/diary.html?storyid=9568 No Types Assigned
http://isc.sans.edu/diary.html?storyid=9568 Third Party Advisory
Changed Reference Type
http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/ No Types Assigned
http://pentonizer.com/general-programming/aspnet-poet-vulnerability-what-else-can-i-do/ Third Party Advisory
Changed Reference Type
http://secunia.com/advisories/41409 Vendor Advisory
http://secunia.com/advisories/41409 Third Party Advisory
Changed Reference Type
http://securitytracker.com/id?1024459 No Types Assigned
http://securitytracker.com/id?1024459 Third Party Advisory, VDB Entry
Changed Reference Type
http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310 No Types Assigned
http://threatpost.com/en_us/blogs/new-crypto-attack-affects-millions-aspnet-apps-091310 Third Party Advisory
Changed Reference Type
http://twitter.com/thaidn/statuses/24832350146 No Types Assigned
http://twitter.com/thaidn/statuses/24832350146 Broken Link
Changed Reference Type
http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx No Types Assigned
http://weblogs.asp.net/scottgu/archive/2010/09/18/important-asp-net-security-vulnerability.aspx Mitigation, Third Party Advisory
Changed Reference Type
http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx No Types Assigned
http://www.dotnetnuke.com/Community/Blogs/tabid/825/EntryId/2799/Oracle-Padding-Vulnerability-in-ASP-NET.aspx Third Party Advisory
Changed Reference Type
http://www.ekoparty.org/juliano-rizzo-2010.php No Types Assigned
http://www.ekoparty.org/juliano-rizzo-2010.php Broken Link
Changed Reference Type
http://www.microsoft.com/technet/security/advisory/2416728.mspx No Types Assigned
http://www.microsoft.com/technet/security/advisory/2416728.mspx Broken Link
Changed Reference Type
http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle No Types Assigned
http://www.mono-project.com/Vulnerabilities#ASP.NET_Padding_Oracle Exploit, Third Party Advisory
Changed Reference Type
http://www.securityfocus.com/bid/43316 No Types Assigned
http://www.securityfocus.com/bid/43316 Third Party Advisory, VDB Entry
Changed Reference Type
http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security No Types Assigned
http://www.theinquirer.net/inquirer/news/1732956/security-researchers-destroy-microsoft-aspnet-security Third Party Advisory
Changed Reference Type
http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html Exploit
http://www.troyhunt.com/2010/09/fear-uncertainty-and-and-padding-oracle.html Exploit, Third Party Advisory
Changed Reference Type
http://www.vupen.com/english/advisories/2010/2429 Vendor Advisory
http://www.vupen.com/english/advisories/2010/2429 Third Party Advisory
Changed Reference Type
http://www.vupen.com/english/advisories/2010/2751 Vendor Advisory
http://www.vupen.com/english/advisories/2010/2751 Third Party Advisory
Changed Reference Type
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070 No Types Assigned
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-070 Patch, Vendor Advisory
Changed Reference Type
https://exchange.xforce.ibmcloud.com/vulnerabilities/61898 No Types Assigned
https://exchange.xforce.ibmcloud.com/vulnerabilities/61898 Third Party Advisory, VDB Entry
Changed Reference Type
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365 No Types Assigned
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12365 Third Party Advisory