CVE-2009-1011

4 documents4 sources
Severity
4.4MEDIUM
EPSS
0.2%
top 60.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 15
Latest updateMay 2

Description

Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.

CVSS vector

AV:L/AC:M/C:P/I:P/A:PExploitability: 3.4 | Impact: 6.4

Affected Packages1 packages

NVDoracle/application_server8.2.2, 8.3.0+1

🔴Vulnerability Details

2
GHSA
GHSA-57pg-rh9v-f46h: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 82022-05-02
CVEList
CVE-2009-1011: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 82009-04-15

💥Exploits & PoCs

1
Exploit-DB
phpShop 0.8.1 - Multiple Vulnerabilities2009-12-05
CVE-2009-1011 (MEDIUM CVSS 4.4) | Unspecified vulnerability in the Ou | cvebase.io