CVE-2011-0788
published 2011-06-14CVE-2011-0788: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote…
PriorityP340high7.6CVSS 2.0
AVNACHAuNCCICAC
EPSS
2.35%
81.7th percentile
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0786.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sun | jdk | <= 1.6.0 | — |
| sun | jdk | — | — |
| sun | jre | <= 1.6.0 | — |
| sun | jre | — | — |
CVSS provenance
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6xh6-rm7h-pf2m: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows r
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2011-0788 [HIGH] GHSA-6xh6-rm7h-pf2m: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows r
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0786.
GHSA
GHSA-j7q5-68q4-2hh8: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows r
ghsa_unreviewed·2022-05-17·CVSS 7.6
CVE-2011-0786 [HIGH] GHSA-j7q5-68q4-2hh8: Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows r
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0788.
Red Hat
JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
vendor_redhat·2011-06-07·CVSS 7.6
CVE-2011-0788 [HIGH] JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0786.
Red Hat
JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
vendor_redhat·2011-06-07·CVSS 7.6
CVE-2011-0786 [HIGH] JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, when running on Windows, allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Deployment, a different vulnerability than CVE-2011-0788.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0788 php: crash when unserializing serialized PDORow object
bugzilla·2012-01-21·CVSS 5.0
CVE-2012-0788 [MEDIUM] CVE-2012-0788 php: crash when unserializing serialized PDORow object
CVE-2012-0788 php: crash when unserializing serialized PDORow object
https://bugs.php.net/bug.php?id=55776
[2011-09-24 19:21 UTC] grinyad at mail dot ru
Description:
fetch(PDO::FETCH_LAZY);
session_start();
$_SESSION['PDORow'] = $result;
?>
Is crashing on next request after saving PDORow to session on session_start()
[2011-09-24 19:24 UTC] [email protected]
What do you mean by "crashing"? Is the actual PHP process crashing, or
are you just getting an error message because PDO statements aren't
serialisable (which is expected)?
[2011-09-25 08:56 UTC] grinyad at mail dot ru
Is a Apache crash. It gives a CGI/FastCGI Send/Don't Send window.
http://img171.imageshack.us/img171/3953/57126366.jpg
After few minutes is crashing apache server:
http://img840.imageshack.us/img840/2981/212310
Bugzilla
CVE-2011-0786 CVE-2011-0788 CVE-2011-0817 CVE-2011-0866 Oracle JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
bugzilla·2011-06-08·CVSS 7.6
CVE-2011-0786 [HIGH] CVE-2011-0786 CVE-2011-0788 CVE-2011-0817 CVE-2011-0866 Oracle JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
CVE-2011-0786 CVE-2011-0788 CVE-2011-0817 CVE-2011-0866 Oracle JDK: unspecified vulnerabilities fixed in 6u26 (Deployment, JRE)
Update 26 of Oracle/Sun Java fixes multiple unspecified vulnerabilities in the Deployment and JRE components. Upstream has CVSSv2 scored these issues as:
CVE-2011-0786 Deployment 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
CVE-2011-0788 Deployment 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
CVE-2011-0817 Deployment 10/AV:N/AC:L/Au:N/C:C/I:C/A:C
CVE-2011-0866 JRE 7.6/AV:N/AC:H/Au:N/C:C/I:C/A:C
http://www.oracle.com/technetwork/topics/security/javacpujune2011-313339.html
Upstream advisory lists these issues as only affecting JRE/JDK versions running on Windows platform. Versions for Linux should not be affected.
Discussion:
ZDI has published an advisory for CVE-2011-0817:
Oracle Java
Bugzilla
CVE-2009-0788 rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
bugzilla·2009-03-20·CVSS 6.4
CVE-2009-0788 [MEDIUM] CVE-2009-0788 rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
CVE-2009-0788 rhn_satellite: Incorrect mod_rewrite rules (information disclosure, abuse as distributed DoS tool)
A flaw was found in the way RHN Satellite rewrote certain URLs.
An unauthenticated user could use a specially-crafted HTTP
request to obtain sensitive information about the host system
RHN Satellite was running on. They could also use RHN Satellite
as a distributed denial of service tool, forcing it to connect
to an arbitrary service at an arbitrary IP address via a
specially-crafted HTTP request.
Discussion:
The preliminary embargo date for this issue has been set up to
Monday, 9-th of May, 2011.
---
(In reply to comment #25)
The preliminary embargo date for this issue has been moved to
earlier date, Monday, 11-th of April, 2011.
---
This issue has been addressed in foll
http://lists.opensuse.org/opensuse-security-announce/2011-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00009.htmlhttp://marc.info/?l=bugtraq&m=132439520301822&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://secunia.com/advisories/44930http://www.ibm.com/developerworks/java/jdk/alerts/http://www.oracle.com/technetwork/topics/security/javacpujune2011-313339.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14140https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14568http://lists.opensuse.org/opensuse-security-announce/2011-06/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00009.htmlhttp://marc.info/?l=bugtraq&m=132439520301822&w=2http://marc.info/?l=bugtraq&m=134254866602253&w=2http://marc.info/?l=bugtraq&m=134254957702612&w=2http://secunia.com/advisories/44930http://www.ibm.com/developerworks/java/jdk/alerts/http://www.oracle.com/technetwork/topics/security/javacpujune2011-313339.htmlhttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14140https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14568
2011-06-14
Published