CVE-2011-0079
published 2011-05-07CVE-2011-0079: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x before 4.0.1 allow remote attackers to cause a denial of service (memory…
PriorityP339critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.60%
93.1th percentile
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x before 4.0.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to gfx/layers/d3d10/ReadbackManagerD3D10.cpp and unknown other vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_ubuntu10.0CRITICAL
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h7f2-gppj-23p5: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4
ghsa_unreviewed·2022-05-17
CVE-2011-0079 [HIGH] GHSA-h7f2-gppj-23p5: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x before 4.0.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to gfx/layers/d3d10/ReadbackManagerD3D10.cpp and unknown other vectors.
Red Hat
OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
vendor_redhat·2012-01-18·CVSS 4.3
CVE-2012-0079 [MEDIUM] OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in continuing to
Red Hat
OpenSSO: unspecified vulnerability in the authentication component
vendor_redhat·2011-10-18·CVSS 4.3
CVE-2011-3517 [MEDIUM] OpenSSO: unspecified vulnerability in the authentication component
OpenSSO: unspecified vulnerability in the authentication component
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 8.0 allows remote attackers to affect availability via unknown vectors related to Authentication.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in continui
Red Hat
OpenSSO: unspecified vulnerability in the authentication component
vendor_redhat·2011-10-18·CVSS 4.3
CVE-2011-3506 [MEDIUM] OpenSSO: unspecified vulnerability in the authentication component
OpenSSO: unspecified vulnerability in the authentication component
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Sun Products Suite 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Authentication.
Statement: Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quickstart has been removed in JBoss Enterprise SOA Platform 5.3.0 to address these flaws. Users interested in con
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2011-04-30·CVSS 10.0
CVE-2011-0079 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple firefox vulnerabilities
Boris Zbarsky, Gary Kwong, Jesse Ruderman, Michael Wu, and Ted Mielczarek
discovered multiple memory vulnerabilities. An attacker could exploit these
to possibly run arbitrary code as the user running Firefox. (CVE-2011-0079)
It was discovered that there was a vulnerability in the memory handling of
certain types of content. An attacker could exploit this to possibly run
arbitrary code as the user running Firefox. (CVE-2011-0081)
It was discovered that Firefox incorrectly handled certain JavaScript
requests. An attacker could exploit this to possibly run arbitrary code as
the user running Firefox. (CVE-2011-0069)
Ian Beer discovered a vulnerability in the memory handling of a certain
types of documents. An attack
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
bugzilla·2012-01-23·CVSS 4.3
CVE-2012-0079 [MEDIUM] CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
CVE-2012-0079 OpenSSO: Unspecified vulnerability allows remote attackers to affect integrity via unknown vectors
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-0079 to the following vulnerability:
Unspecified vulnerability in Oracle OpenSSO 7.1 and 8.0 allows remote attackers to affect integrity via unknown vectors related to Administration.
References:
[1] http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0079
Discussion:
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application i
Bugzilla
CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
bugzilla·2011-10-26·CVSS 4.3
CVE-2011-3517 [MEDIUM] CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
CVE-2011-3517 Oracle OpenSSO: unspecified vulnerability in the authentication component
Oracle OpenSSO 8.0 exposes an unspecified vulnerability in the authentication component, allowing a remote attacker to perform a denial of service (CVE-2011-3517).
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
---
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso qui
Bugzilla
CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
bugzilla·2011-10-26·CVSS 4.3
CVE-2011-3506 [MEDIUM] CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
CVE-2011-3506 Oracle OpenSSO: unspecified vulnerability in the authentication component
Oracle OpenSSO 7.1 and 8.0 expose an unspecified vulnerability in the authentication component, allowing attackers to manipulate certain data (CVE-2011-3506).
Discussion:
External References:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
---
Statement:
Oracle OpenSSO is provided as part of the opensso quickstart example application shipped with JBoss Enterprise SOA Platform 5. The CVE-2011-3506, CVE-2011-3517, and CVE-2012-0079 flaws are not exposed unless the opensso quickstart example application is deployed, or you have created and deployed a custom application that is packaged with a copy of Oracle OpenSSO as provided by the opensso quickstart.
The opensso quicksta
Bugzilla
CVE-2011-0445 wireshark: DoS via crafted packets to ASN.1 BER dissector (upstream bug #5537)
bugzilla·2011-01-13·CVSS 5.0
CVE-2011-0445 [MEDIUM] CVE-2011-0445 wireshark: DoS via crafted packets to ASN.1 BER dissector (upstream bug #5537)
CVE-2011-0445 wireshark: DoS via crafted packets to ASN.1 BER dissector (upstream bug #5537)
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0445 to
the following vulnerability:
Name: CVE-2011-0445
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0445
Assigned: 20110112
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2011-02.html
Reference: CONFIRM: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5537
Reference: VUPEN:ADV-2011-0079
Reference: URL: http://www.vupen.com/english/advisories/2011/0079
The ASN.1 BER dissector in Wireshark 1.4.0 through 1.4.2 allows remote
attackers to cause a denial of service (assertion failure) via crafted
packets, as demonstrated by fuzz-2010-12-30-28473.pcap.
Discussion:
Created wireshark tracking bugs
Bugzilla
CVE-2011-0444 wireshark: buffer overflow in MAC-LTE disector (upstream bug #5530)
bugzilla·2011-01-13·CVSS 10.0
CVE-2011-0444 [CRITICAL] CVE-2011-0444 wireshark: buffer overflow in MAC-LTE disector (upstream bug #5530)
CVE-2011-0444 wireshark: buffer overflow in MAC-LTE disector (upstream bug #5530)
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0444 to
the following vulnerability:
Name: CVE-2011-0444
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0444
Assigned: 20110112
Reference: MISC: https://bugs.wireshark.org/bugzilla/attachment.cgi?id=5676
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2011-01.html
Reference: CONFIRM: http://www.wireshark.org/security/wnpa-sec-2011-02.html
Reference: CONFIRM: https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=5530
Reference: VUPEN:ADV-2011-0079
Reference: URL: http://www.vupen.com/english/advisories/2011/0079
Buffer overflow in the MAC-LTE dissector
(epan/dissectors/packet-mac-lte.c) in Wireshark 1.2.0 through
http://www.mozilla.org/security/announce/2011/mfsa2011-12.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=601102https://bugzilla.mozilla.org/show_bug.cgi?id=639343https://bugzilla.mozilla.org/show_bug.cgi?id=639728https://bugzilla.mozilla.org/show_bug.cgi?id=639885https://bugzilla.mozilla.org/show_bug.cgi?id=641388https://bugzilla.mozilla.org/show_bug.cgi?id=642717https://bugzilla.mozilla.org/show_bug.cgi?id=643649https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14232http://www.mozilla.org/security/announce/2011/mfsa2011-12.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=601102https://bugzilla.mozilla.org/show_bug.cgi?id=639343https://bugzilla.mozilla.org/show_bug.cgi?id=639728https://bugzilla.mozilla.org/show_bug.cgi?id=639885https://bugzilla.mozilla.org/show_bug.cgi?id=641388https://bugzilla.mozilla.org/show_bug.cgi?id=642717https://bugzilla.mozilla.org/show_bug.cgi?id=643649https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14232
2011-05-07
Published