CVE-2011-0310
published 2011-01-13CVE-2011-0310: Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.01%
85.9th percentile
Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
| ibm | websphere_mq | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j497-52cv-pcp6: Buffer overflow in IBM WebSphere MQ 7
ghsa_unreviewed·2022-05-17
CVE-2011-0310 [MEDIUM] CWE-119 GHSA-j497-52cv-pcp6: Buffer overflow in IBM WebSphere MQ 7
Buffer overflow in IBM WebSphere MQ 7.0 before 7.0.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted header field in a message.
Red Hat
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
vendor_redhat·2011-04-19·CVSS 3.3
CVE-2011-1749 [LOW] nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
nfs-utils: mount.nfs fails to anticipate RLIMIT_FSIZE
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089.
Statement: This issue did not affect the versions of nfs-utils as shipped with Red Hat Enterprise Linux 4 as it did not include include mount.nfs. It was addressed in Red Hat Enterprise Linux 5 and 6 via RHSA-2012:0310 and RHSA-2011:1534 respectively.
Package: nfs-utils (Red Hat Enterprise Linux 4) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-0057 Mozilla use-after-free error using Web Workers (MFSA 2011-06)
bugzilla·2011-02-04·CVSS 10.0
CVE-2011-0057 [CRITICAL] CVE-2011-0057 Mozilla use-after-free error using Web Workers (MFSA 2011-06)
CVE-2011-0057 Mozilla use-after-free error using Web Workers (MFSA 2011-06)
Daniel Kozlowski reported that a JavaScript Worker could be
used to keep a reference to an object that could be freed during
garbage collection. Subsequent calls through this deleted
reference could cause attacker-controlled memory to be executed
on a victim's computer.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-06.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:0310 https://rhn.redhat.com/errata/RHSA-2011-0310.html
Bugzilla
CVE-2011-0054 Mozilla Buffer overflow in JavaScript upvarMap (MFSA 2011-04)
bugzilla·2011-02-04·CVSS 10.0
CVE-2011-0054 [CRITICAL] CVE-2011-0054 Mozilla Buffer overflow in JavaScript upvarMap (MFSA 2011-04)
CVE-2011-0054 Mozilla Buffer overflow in JavaScript upvarMap (MFSA 2011-04)
Security researcher Christian Holler reported that the JavaScript engine's
internal memory mapping of non-local JS variables contained a buffer
overflow which could potentially be used by an attacker to run arbitrary
code on a victim's computer.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-04.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Hat Enterprise Linux 6
Via RHSA-2011:0310 https://rhn.redhat.com/errata/RHSA-2011-0310.html
http://osvdb.org/70476http://secunia.com/advisories/42958http://www-01.ibm.com/support/docview.wss?uid=swg27014224http://www.securityfocus.com/bid/45923http://www.vupen.com/english/advisories/2011/0128https://exchange.xforce.ibmcloud.com/vulnerabilities/64628https://www-304.ibm.com/support/docview.wss?uid=swg1SE45551http://osvdb.org/70476http://secunia.com/advisories/42958http://www-01.ibm.com/support/docview.wss?uid=swg27014224http://www.securityfocus.com/bid/45923http://www.vupen.com/english/advisories/2011/0128https://exchange.xforce.ibmcloud.com/vulnerabilities/64628https://www-304.ibm.com/support/docview.wss?uid=swg1SE45551
2011-01-13
Published