CVE-2011-0311
published 2011-09-02CVE-2011-0311: The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote…
PriorityP413low3.5CVSS 2.0
AVNACMAuSCNINAP
EPSS
1.78%
76.0th percentile
The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | java | <= 1.4.2.13.8 | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | java | — | — |
| ibm | runtimes_for_java_technology | <= 5.0.12.4 | — |
| ibm | runtimes_for_java_technology | <= 6.0.9.0 | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
| ibm | runtimes_for_java_technology | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:N/A:P
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
java-1.4.2-ibm: DoS via class file parser in IBM Java 1.4.2.SR13.FP9
vendor_redhat·2011-06-29·CVSS 3.5
CVE-2011-3387 [LOW] java-1.4.2-ibm: DoS via class file parser in IBM Java 1.4.2.SR13.FP9
java-1.4.2-ibm: DoS via class file parser in IBM Java 1.4.2.SR13.FP9
The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.
Red Hat
IBM JDK Class file parsing denial-of-service
vendor_redhat·2011-01-20·CVSS 3.5
CVE-2011-0311 [LOW] IBM JDK Class file parsing denial-of-service
IBM JDK Class file parsing denial-of-service
The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.
GHSA
GHSA-4f6f-x539-9v2g: The class file parser in IBM Java before 1
ghsa_unreviewed·2022-05-17
CVE-2011-0311 [LOW] CWE-119 GHSA-4f6f-x539-9v2g: The class file parser in IBM Java before 1
The class file parser in IBM Java before 1.4.2 SR13 FP9, as used in IBM Runtimes for Java Technology 5.0.0 before SR13 and 6.0.0 before SR10, allows remote authenticated users to cause a denial of service (JVM segmentation fault, and possibly memory consumption or an infinite loop) via a crafted attribute length field in a class file, which triggers a buffer over-read.
GHSA
GHSA-c76f-h47x-j5r2: The class file parser in IBM Java 1
ghsa_unreviewed·2022-05-17·CVSS 3.5
CVE-2011-3387 [LOW] CWE-20 GHSA-c76f-h47x-j5r2: The class file parser in IBM Java 1
The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-3387 java-1.4.2-ibm: DoS via class file parser in IBM Java 1.4.2.SR13.FP9
bugzilla·2011-09-09·CVSS 3.5
CVE-2011-3387 [LOW] CVE-2011-3387 java-1.4.2-ibm: DoS via class file parser in IBM Java 1.4.2.SR13.FP9
CVE-2011-3387 java-1.4.2-ibm: DoS via class file parser in IBM Java 1.4.2.SR13.FP9
Common Vulnerabilities and Exposures assigned an identifier CVE-2011-3387 to
the following vulnerability:
Name: CVE-2011-3387
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3387
Assigned:
Reference: AIXAPAR:PM42551
Reference: https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551
The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote
authenticated users to cause a denial of service (memory consumption
or an infinite loop) via a crafted attribute length field in a class
file, related to validation of a length field at the wrong time, a
different vulnerability than CVE-2011-0311.
Discussion:
This flaw only affected FP9 and is fixed in FP10, which was made available via:
https://
Bugzilla
CVE-2011-0311 IBM JDK Class file parsing denial-of-service
bugzilla·2011-05-05·CVSS 3.5
CVE-2011-0311 [LOW] CVE-2011-0311 IBM JDK Class file parsing denial-of-service
CVE-2011-0311 IBM JDK Class file parsing denial-of-service
IBM reported a problem with class file parsing in IBM JDK:
IBM Runtimes for Java Technology is vulnerable to a denial of service, caused by an error in the class file parser. A remote authenticated attacker could exploit this vulnerability using a specially-crafted class file containing an invalid attribute length field to cause a segmentation fault. [1]
The issue is fixed with JDK 1.4.2 SR13-FP9 , 5.0 SR12-FP4 and 6 SR9-FP1 [2]
and APAR IZ89602 [3]
[1] http://xforce.iss.net/xforce/xfdb/65189
[2] http://www.ibm.com/developerworks/java/jdk/alerts/
[3] http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602
Discussion:
This issue has been addressed in following products:
Supplementary for Red Hat Enterprise Linux 5
Extras fo
Bugzilla
CVE-2011-0062 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)
bugzilla·2011-02-04·CVSS 10.0
CVE-2011-0062 [CRITICAL] CVE-2011-0062 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)
CVE-2011-0062 Mozilla miscellaneous memory safety hazards (MFSA 2011-01)
Mozilla developers identified and fixed several memory safety bugs
in the browser engine used in Firefox and other Mozilla-based
products. Some of these bugs showed evidence of memory corruption
under certain circumstances, and we presume that with enough effort
at least some of these could be exploited to run arbitrary code.
Igor Bukanov and Gary Kwong reported memory safety problems that
affected Firefox 3.6 only.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-01.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0311 https://rhn.redhat.com/errata/RHSA-2011-0311.html
---
This issue has been addressed in following p
Bugzilla
CVE-2011-0061 Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)
bugzilla·2011-02-04·CVSS 9.3
CVE-2011-0061 [CRITICAL] CVE-2011-0061 Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)
CVE-2011-0061 Mozilla crash caused by corrupted JPEG image (MFSA 2011-09)
Security researcher Jordi Chancel reported that a JPEG image
could be constructed that would be decoded incorrectly,
causing data to be written past the end of a buffer created
to store the image.
An attacker could potentially craft such an image that would
cause malicious code to be stored in memory and then later
executed on a victim's computer.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-09.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0311 https://rhn.redhat.com/errata/RHSA-2011-0311.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 5
Red Ha
Bugzilla
CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)
bugzilla·2011-02-04·CVSS 9.3
CVE-2010-1585 [CRITICAL] CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)
CVE-2010-1585 Mozilla ParanoidFragmentSink allows javascript: URLs in chrome documents (MFSA 2011-08)
Mozilla security developer Roberto Suggi Liverani reported
that ParanoidFragmentSink, a class used to sanitize potentially
unsafe HTML for display, allows javascript: URLs and other
inline JavaScript when the embedding document is a chrome document.
While there are no unsafe uses of this class in any released products,
extension code could have potentially used it in an unsafe manner.
Discussion:
This is now public:
http://www.mozilla.org/security/announce/2011/mfsa2011-08.html
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2011:0311 https://rhn.redhat.com/errata/RHSA-2011-0311.html
---
This issue has been addressed in following prod
http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00010.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89620http://www.redhat.com/support/errata/RHSA-2011-1159.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1265.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/65189https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00010.htmlhttp://www-01.ibm.com/support/docview.wss?uid=swg1IZ89602http://www-01.ibm.com/support/docview.wss?uid=swg1IZ89620http://www.redhat.com/support/errata/RHSA-2011-1159.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1265.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/65189https://www-304.ibm.com/support/docview.wss?uid=isg1PM42551
2011-09-02
Published